Skip to content

Configuration Guide

Almost everything is configurable from the admin panel — no code edits. This guide follows the sections you see under Admin → Settings.


  1. Branding & Support — brand name, logo, favicon, support email
  2. Appearance — colours and homepage look
  3. API Providers — connect TikTok data (see API Providers)
  4. Bot Protection — Cloudflare Turnstile keys
  5. SEO & Analytics — GA4, Search Console verification
  6. SMTP — outbound email for the contact form and newsletter
  7. Monetization — ad slots
  8. Affiliates / Social — partner cards and social profiles
  9. Custom Pages — About, Contact, legal pages, and their menu placement

Settings sections

Branding & Support

  • Site brand name, tagline, and logo text
  • Logo and favicon — uploaded directly (stored under storage/app/public/branding)
  • Support email, contact email, and support URL — used by the contact form and footer

Appearance

  • Colour and surface presets applied to the public site
  • Upload-based branding only (manual logo/favicon URL fields are intentionally removed for safer defaults and a simpler buyer experience)

Homepage Appearance

  • How-it-works card count (1–9)
  • Feature card count (1–9)
  • Show/hide the “Explore tools” section
  • Show custom pages in the header / footer
  • Maximum header pages (1–10) and footer pages (1–20)
  • Footer copyright, navigation heading
  • Newsletter block heading, text, placeholder, and button label
  • Footer legal heading and text

API Providers

  • Provider mode (RapidAPI, TikWM, TikAPI, Custom, Apify)
  • Base URL, host, keys (primary/secondary), auth header/scheme, host header
  • Timeout, retries, retry delay
  • Per-type caching (profile / posts / video)
  • Rate limits (search / download / stream / image)
  • Test Connection action

See the API Providers Guide for full details.

Bot Protection (Cloudflare Turnstile)

  • Enabled / Disabled master switch
  • Site key and secret key
  • Visibility (visible/hidden)
  • Per-location toggles: admin login, search, contact, newsletter

SEO & Analytics

  • GA4 Measurement ID (G-XXXXXXXXXX)
  • Google Search Console verification string
  • sitemap.xml and robots.txt are served dynamically (no cron or static files needed)

Monetization (Ads)

  • Global head script slot
  • Top banner
  • Profile slot
  • Article top/bottom (with desktop/mobile variants)
  • Homepage slots: hero, mid, pre-FAQ, footer (desktop/mobile variants)

Ad script slots are sanitized: inline event handlers, javascript: URLs, and server-side tags (<?, <%) are rejected.

Affiliates

  • iProyal and Hostinger partner URLs
  • Top and bottom affiliate card: image, title, subtitle, button text

Social Profiles

  • TikTok, X, YouTube, Facebook, Instagram URLs

SMTP Mail

  • Host, port, encryption (SSL/TLS), username, password
  • From address and from name
  • Test SMTP and Send test email actions

Note

If SMTP is not configured, the public contact form still works — it fails gracefully with a friendly message instead of throwing an error.


Custom pages and menus

Use Admin → Custom Pages to create pages such as About, Contact, Support, Changelog, refund policy, or niche landing pages. Each page supports:

  • slug (/p/{slug})
  • SEO title and description
  • excerpt and rich content
  • published/draft state
  • menu placement toggles (show_in_header, show_in_footer)
  • menu sort order

Published pages with the header/footer toggles on render automatically in the public menu.


Settings validation model

  • Only allowlisted keys are accepted by the backend.
  • URL fields require valid absolute URLs.
  • Branding is upload-only (not freely editable URLs).
  • GA4 ID must match G-XXXXXXXXXX format.
  • Mail port must be an integer 1–65535.
  • Ad script fields are sanitized (see Monetization above).
  • Custom page content is sanitized before saving: <script> blocks, inline event handlers, and javascript: payloads are removed.

Branding uploads

  • Admin → Settings → Appearance supports direct uploads for logo and favicon.
  • Files are stored in storage/app/public/branding and referenced as /storage/branding/....
  • Replacing or removing an upload deletes the old file automatically.
  • If your host blocks the public/storage symlink, TokGrab serves these through a safe /storage/... fallback route, so images still display.

.env baseline

You normally do not need to edit .env. On first load TokGrab creates it automatically, and the installer writes your database settings for you.

The only value worth setting manually after install is:

  • APP_URL — your live URL (e.g. https://your-domain.com)

.env.example documents optional advanced values. Never share your real .env — it may contain secrets. Some values (the update feed endpoint, add-on store links) are intentionally baked into config rather than exposed to buyers.