Skip to documentation
Browse 13 guides

User guide

Connections, plans, and billing

Connect external accounts inside the organization that owns the data. Use the narrowest permissions the provider supports, store secrets only in Tailwin’s credential fields or t…

Updated September 28, 2026

On this page
  1. Connection principles
  2. Common connection order
  3. DataForSEO account setup
  4. Plans, billing, and limits
  5. Safe credential rotation
  6. Chat model preferences

Connection principles

Connect external accounts inside the organization that owns the data. Use the narrowest permissions the provider supports, store secrets only in Tailwin’s credential fields or the deployment secret manager, and remove a connection when authorization ends.

The Connections and Reports screens expose different categories: publishing and platform connections support workflows, while report sources normalize metrics for dashboards. A provider can appear in both for different purposes.

Common connection order

  1. Google OAuth for sign-in and supported Google services.
  2. Search Console and Bing for no-marginal-cost measured search data.
  3. AI engine credentials or the configured routing provider for Signal.
  4. Crawler tracker for first-party bot evidence.
  5. CMS or social destinations for publishing.
  6. Analytics, ads, call, CRM, email, commerce, and local sources for Reports.
  7. DataForSEO only where direct SERP, Labs, backlink, or Maps data is needed.
  8. Visitor identification vendors only after privacy review.
  9. Stripe and Press rails only after an operator is ready to test financial actions.

DataForSEO account setup

DataForSEO uses HTTP Basic authentication with the API login and API password issued in the vendor dashboard. The application reads them as deployment secrets; it does not use the interactive account password unless the vendor explicitly made it the API password.

After any password reset, update both values in the deployment secret manager, restart the web and worker services, run a free account/ledger check, then perform one deliberately bounded keyword canary. Never paste the credential into documentation, source code, tickets, or screenshots.

Tailwin operators maintain a separate private DataForSEO runbook for endpoint, recovery, and cost-control details.

Safe site activation

Creating a DataForSEO source does not buy data. Tailwin stores it with scheduling disabled. The site activation card can then call the vendor’s uncharged account endpoint to verify the platform credentials. The source reads credentials valid · paid checks off until an operator deliberately selects metered sync in Reports and confirms the warning.

That first metered sync also enables future scheduled syncs for the source. Search Console uses the same staged interface, but its explicit property validation has no per-call vendor charge.

Plans, billing, and limits

The code-defined monthly prices are Starter $49, Growth $149, and Agency $399. The active entitlement record is authoritative for an organization.

PlanSitesQueries per siteIncluded locationsScan cadenceAI enginesContent creditsSeatsWhite label
Free1101Weekly201No
Starter1251Weekly322No
Growth11003Daily585No
Agency110010Daily5255Yes

Additional location prices are defined in the application and displayed at checkout. Always confirm the current pricing page before quoting a customer.

When billing is not configured, checkout, the customer portal and location purchases report that billing is unavailable. No paid plan or additional location is granted. Checkout and portal buttons display the error so you can retry after configuration is restored. A production purchase is not proven until checkout, webhook processing, entitlement update, receipt, and customer portal are all verified.

Safe credential rotation

  1. Create the replacement at the provider.
  2. Update the correct environment or encrypted source record.
  3. Restart only the services that read it, usually web and worker.
  4. Run a read-only or free verification when the provider offers one.
  5. Run one bounded real workflow.
  6. Confirm source status, worker logs, and downstream data.
  7. Revoke the old credential.
  8. Record the rotation time and outcome without recording the value.

Chat model preferences

Workspace managers can open Settings to save their preferred chat model, language, locale, market, tone, output format, depth and target site. Preferences are personal to the current workspace. Organization defaults apply to users who have not saved their own preferences. Saving settings does not run a model or spend AI budget.

The model list shows configuration availability, supported capabilities and reviewed token prices. A configured model may still require a live account check. Platform administrators enable models; agencies can narrow the list for their client workspaces. Client preferences cannot override agency restrictions. If a saved model becomes unavailable, choose another allowed model before saving.

Live Tailwin data is a preference for using workspace evidence in supported chat tools; it does not automatically browse or fetch information. JSON-LD output means JSON-LD with setup notes, and generated content still requires review. New chat surfaces use the shared settings as they become available.

Chat calls count toward the workspace AI budget. Mock replies are clearly labelled and cost nothing. Interrupted requests can temporarily retain their reserved budget until the charge is reconciled. Provider-reported charges and costs calculated from reviewed prices are retained separately in the accounting record.