Configuration Guide
Almost everything is configurable from the admin panel — no code edits. This guide follows the sections you see under Admin → Settings.
Recommended setup order
- Branding & Support — brand name, logo, favicon, support email
- Appearance — colours and homepage look
- API Providers — connect TikTok data (see API Providers)
- Bot Protection — Cloudflare Turnstile keys
- SEO & Analytics — GA4, Search Console verification
- SMTP — outbound email for the contact form and newsletter
- Monetization — ad slots
- Affiliates / Social — partner cards and social profiles
- Custom Pages — About, Contact, legal pages, and their menu placement
Settings sections
Branding & Support
- Site brand name, tagline, and logo text
- Logo and favicon — uploaded directly (stored under
storage/app/public/branding) - Support email, contact email, and support URL — used by the contact form and footer
Appearance
- Colour and surface presets applied to the public site
- Upload-based branding only (manual logo/favicon URL fields are intentionally removed for safer defaults and a simpler buyer experience)
Homepage Appearance
- How-it-works card count (1–9)
- Feature card count (1–9)
- Show/hide the “Explore tools” section
Menu & Layout
- Show custom pages in the header / footer
- Maximum header pages (1–10) and footer pages (1–20)
Footer Content
- Footer copyright, navigation heading
- Newsletter block heading, text, placeholder, and button label
- Footer legal heading and text
API Providers
- Provider mode (RapidAPI, TikWM, TikAPI, Custom, Apify)
- Base URL, host, keys (primary/secondary), auth header/scheme, host header
- Timeout, retries, retry delay
- Per-type caching (profile / posts / video)
- Rate limits (search / download / stream / image)
- Test Connection action
See the API Providers Guide for full details.
Bot Protection (Cloudflare Turnstile)
- Enabled / Disabled master switch
- Site key and secret key
- Visibility (visible/hidden)
- Per-location toggles: admin login, search, contact, newsletter
SEO & Analytics
- GA4 Measurement ID (
G-XXXXXXXXXX) - Google Search Console verification string
sitemap.xmlandrobots.txtare served dynamically (no cron or static files needed)
Monetization (Ads)
- Global head script slot
- Top banner
- Profile slot
- Article top/bottom (with desktop/mobile variants)
- Homepage slots: hero, mid, pre-FAQ, footer (desktop/mobile variants)
Ad script slots are sanitized: inline event handlers, javascript: URLs, and server-side tags
(<?, <%) are rejected.
Affiliates
- iProyal and Hostinger partner URLs
- Top and bottom affiliate card: image, title, subtitle, button text
Social Profiles
- TikTok, X, YouTube, Facebook, Instagram URLs
SMTP Mail
- Host, port, encryption (SSL/TLS), username, password
- From address and from name
- Test SMTP and Send test email actions
Note
If SMTP is not configured, the public contact form still works — it fails gracefully with a friendly message instead of throwing an error.
Custom pages and menus
Use Admin → Custom Pages to create pages such as About, Contact, Support, Changelog, refund policy, or niche landing pages. Each page supports:
- slug (
/p/{slug}) - SEO title and description
- excerpt and rich content
- published/draft state
- menu placement toggles (
show_in_header,show_in_footer) - menu sort order
Published pages with the header/footer toggles on render automatically in the public menu.
Settings validation model
- Only allowlisted keys are accepted by the backend.
- URL fields require valid absolute URLs.
- Branding is upload-only (not freely editable URLs).
- GA4 ID must match
G-XXXXXXXXXXformat. - Mail port must be an integer
1–65535. - Ad script fields are sanitized (see Monetization above).
- Custom page content is sanitized before saving:
<script>blocks, inline event handlers, andjavascript:payloads are removed.
Branding uploads
- Admin → Settings → Appearance supports direct uploads for logo and favicon.
- Files are stored in
storage/app/public/brandingand referenced as/storage/branding/.... - Replacing or removing an upload deletes the old file automatically.
- If your host blocks the
public/storagesymlink, TokGrab serves these through a safe/storage/...fallback route, so images still display.
.env baseline
You normally do not need to edit .env. On first load TokGrab creates it automatically, and
the installer writes your database settings for you.
The only value worth setting manually after install is:
APP_URL— your live URL (e.g.https://your-domain.com)
.env.example documents optional advanced values. Never share your real .env — it may contain
secrets. Some values (the update feed endpoint, add-on store links) are intentionally baked
into config rather than exposed to buyers.