Atlas / MCP servers / mikusnuz / Meta Ads

Meta AdsSAFE

mcp/mikusnuz/meta-ads-5

MCP server for Meta Marketing API v25.0 — 135 tools for Facebook & Instagram ad campaign management

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
134 68r · 51w · 15d
Transport
stdio
License
MIT
Stars
83
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@mikusnuz/meta-ads-mcp) [](https://opensource.org/licenses/MIT)

MCP server for the Meta Marketing API v26.0 — 135 tools for managing Facebook & Instagram ad campaigns, audiences, creatives, insights, catalogs, and more.

When to Use

Use this MCP when you need to:

  • "Create a new Facebook ad campaign" — use create_campaign, create_adset, create_ad, and create_creative to build a full funnel
  • "Check how my ads are performing today" — use get_account_insights or get_campaign_insights with today's date range
  • "Pause all campaigns with ROAS below 2" — use list_campaigns + get_campaign_insights to find underperformers, then update_campaign to pause
  • "Set up A/B test between two ad creatives" — use create_experiment to run a controlled test between ad sets
  • "Create a lookalike audience from my customers" — use create_custom_audience, add_users_to_audience, then create_lookalike_audience
  • "Upload ad images and create a carousel ad" — use upload_image for each image, then create_creative with carousel format
  • "Get a detailed performance report for last 30 days" — use create_async_report for large date ranges, then get_async_report to retrieve
  • "Search the Facebook Ad Library for competitor ads" — use search_ad_library to find public ad data
  • "Set up automated rules to pause underperforming ads" — use create_rule with conditions like CPA > threshold
  • "Manage my product catalog for dynamic ads" — use create_catalog, create_feed, and upload_feed to set up dynamic product ads

Installation

{
"mcpServers": {
"meta-ads": {
"command": "npx",
"args": ["-y", "@mikusnuz/meta-ads-mcp"],
"env": {
"META_ADS_ACCESS_TOKEN": "your-access-token",
"META_AD
Read from source at commit 94ad503999a7OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add meta-ads-mcp --env META_ADS_ACCESS_TOKEN=${META_ADS_ACCESS_TOKEN} --env META_APP_SECRET=${META_APP_SECRET} -- npx -y @mikusnuz/[email protected]
03

Exposed tools (134)

68 read · 51 write · 15 destructive. Blast radius: 15 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_business_userwriteAdd a user to the configured business by email. Requires META_BUSINESS_ID env var.
add_to_block_listwriteAdd publisher URLs to an existing block list.
add_users_to_audiencewriteAdd users to a custom audience. Payload must be a JSON string containing hashed user data with a schema array defining the data types (e.g. EMAIL, PHONE, FN, LN).
batch_productsdestructiveBatch create, update, or delete products in a catalog. Supports up to 5,000 items per request. Update operations support upsert.
copy_adwriteCopy an existing ad. Creates a duplicate within the same or different ad set.
copy_adsetwriteCopy an existing ad set. Creates a duplicate within the same or different campaign.
copy_campaignreadCopy an existing campaign. Creates a duplicate with optional name override. Copies structure including ad sets and ads.
create_adwriteCreate a new ad. Requires name, adset_id, and creative (JSON object_story_spec). Defaults to PAUSED status.
create_adsetwriteCreate a new ad set. Requires name, campaign_id, budget, optimization_goal, billing_event, and targeting. Defaults to PAUSED status.
create_async_reportwriteCreate an async insight report for large data queries. Returns a report_run_id to poll with get_async_report.
create_block_listwriteCreate a new publisher block list for the ad account.
create_budget_schedulewriteCreate a budget schedule on a campaign or ad set.
create_campaignwriteCreate a new ad campaign. Defaults to PAUSED status. Requires name and objective. Budget can be set at campaign or ad set level.
create_canvaswriteCreate a new Instant Experience (Canvas) on a Facebook Page. Requires page_id and body_elements JSON array defining the canvas layout.
create_catalogwriteCreate a new product catalog for the ad account.
create_creativewrite
create_custom_audiencewriteCreate a new custom audience. Subtype determines the audience source (CUSTOM, WEBSITE, APP, OFFLINE_CONVERSION, LOOKALIKE, ENGAGEMENT, etc.).
create_dynamic_creativewriteCreate a dynamic creative with asset_feed_spec. Meta automatically combines different images, videos, titles, bodies, and CTAs to find the best performing combinations.
create_experimentwriteCreate a new A/B test experiment (ad study).
create_feedwriteCreate a new product feed for a catalog.
create_lead_formwriteCreate a new lead generation form on a Facebook Page. Requires pages_manage_ads permission.
create_lookalike_audiencewriteCreate a lookalike audience based on an existing custom audience. Ratio (1-10) determines how closely the new audience resembles the source.
create_offline_event_setwriteCreate a new offline conversion data set.
create_product_setwriteCreate a new product set within a catalog.
create_rf_predictionwriteCreate a new reach & frequency prediction. Provide targeting spec as JSON string, budget in cents, and scheduling info.
create_rulewriteCreate a new automated rule for the ad account.
create_system_userwriteCreate a new system user in the configured business. Requires META_BUSINESS_ID env var.
debug_tokenreadDebug an access token to inspect its properties, permissions, expiration, and validity. Requires META_APP_ID and META_APP_SECRET.
delete_addestructiveDelete an ad. This action is irreversible.
delete_adsetdestructiveDelete an ad set. This action is irreversible.
delete_audiencedestructiveDelete a custom audience. This action is irreversible.
delete_block_listdestructiveDelete a publisher block list. This action is irreversible.
delete_budget_scheduledestructiveDelete a budget schedule. This action is irreversible.
delete_campaigndestructiveDelete a campaign. This action is irreversible.
delete_canvasdestructiveDelete an Instant Experience (Canvas). This action is irreversible.
delete_imagedestructiveDelete an ad image by hash. This action is irreversible.
delete_rf_predictiondestructiveDelete a reach & frequency prediction. This action is irreversible.
delete_ruledestructiveDelete an automated rule.
delete_videodestructiveDelete an ad video. This action is irreversible.
exchange_tokenreadExchange a short-lived access token for a long-lived token. Requires META_APP_ID and META_APP_SECRET to be configured.
generate_previewreadGenerate an ad preview without needing an existing ad. Provide creative spec directly to see how it would look.
get_account_activitiesreadGet activity log for the ad account. Shows changes made to campaigns, ad sets, ads, etc.
get_account_insightsreadGet performance insights for the ad account. Returns metrics like impressions, clicks, spend, reach, etc.
get_adreadGet details of a specific ad by ID.
get_ad_accountreadGet details of the configured ad account including status, balance, currency, timezone, and spend info.
get_ad_insightsreadGet performance insights for a specific ad.
get_ad_previewreadGet a preview of an ad in a specific format. Returns HTML iframe for rendering.
get_adsetwriteGet details of a specific ad set by ID.
get_adset_adswriteGet all ads belonging to a specific ad set.
get_adset_insightswriteGet performance insights for a specific ad set.
get_adset_leadswriteGet leads generated by a specific ad set. Requires leads_retrieval permission.
get_adset_targeting_sentencewriteGet human-readable targeting description for an ad set. Converts targeting spec into readable sentences.
get_async_reportreadCheck status and retrieve results of an async insight report.
get_audiencereadGet details of a specific custom audience by ID.
get_audience_healthreadGet health status and delivery readiness of a custom audience. Shows match rate, size, and operation status.
get_batch_statusreadCheck the status of a catalog batch operation.
get_businessreadGet details of a specific business by ID.
get_campaignreadGet details of a specific campaign by ID.
get_campaign_adsreadGet all ads belonging to a specific campaign.
get_campaign_adsetsreadGet all ad sets belonging to a specific campaign.
get_campaign_insightsreadGet performance insights for a specific campaign.
get_campaign_leadsreadGet leads generated by a specific campaign. Requires leads_retrieval permission.
get_canvasreadGet details of a specific Instant Experience (Canvas) by ID.
get_catalogreadGet details of a specific product catalog.
get_creativereadGet details of a specific ad creative by ID.
get_delivery_estimateread
get_experimentreadGet details of a specific experiment (ad study).
get_experiment_resultsreadGet results/cells of an experiment (ad study).
get_feed_uploadswriteGet upload history for a product feed.
get_form_leadsreadGet leads submitted through a lead generation form.
get_imagereadGet details of a specific ad image by ID.
get_leadreadGet details of a specific lead by ID.
get_lead_formreadGet details of a specific lead generation form.
get_productreadGet details of a specific product.
get_product_setwriteGet details of a specific product set.
get_reach_estimatereadGet estimated audience reach for a given targeting specification. Useful for planning campaigns before creating them.
get_rf_predictionreadGet details of a specific reach & frequency prediction by ID.
get_rulereadGet details of a specific automated rule.
get_saved_audiencereadGet details of a specific saved audience by ID.
get_targeting_suggestionsreadGet targeting suggestions based on existing targeting criteria. Meta suggests related interests, behaviors, and demographics.
get_videoreadGet details of a specific ad video by ID.
list_account_usersreadList users who have access to the ad account with their roles and permissions.
list_ad_accountsreadList all ad accounts accessible by the current user. Returns paginated results.
list_adswriteList ads in the ad account. Optionally filter by campaign, ad set, or status.
list_adsetsreadList ad sets in the ad account. Optionally filter by campaign or status.
list_block_listsreadList publisher block lists for the ad account. Returns paginated results.
list_budget_scheduleswriteList budget schedules attached to a campaign or ad set. Returns paginated results.
list_business_ad_accountsreadList ad accounts owned by the configured business. Requires META_BUSINESS_ID env var.
list_business_instagram_accountsreadList Instagram accounts owned by the configured business. Requires META_BUSINESS_ID env var.
list_business_pagesreadList Facebook Pages owned by the configured business. Requires META_BUSINESS_ID env var.
list_business_usersreadList users of the configured business. Requires META_BUSINESS_ID env var.
list_businessesreadList all businesses accessible by the current user. Returns paginated results.
list_campaignsreadList campaigns in the ad account. Supports filtering by status and objective. Returns paginated results.
list_canvasesreadList Instant Experience (Canvas) creatives in the ad account.
list_catalogsreadList product catalogs for the ad account.
list_creativesreadList ad creatives in the ad account.
list_custom_audiencesreadList custom audiences in the ad account.
list_experimentsreadList A/B test experiments (ad studies) for the ad account.
list_feedsreadList product feeds for a catalog.
list_imagesreadList ad images uploaded to the ad account.
list_lead_formsreadList lead generation forms for a Facebook Page.
list_offline_event_setsreadList offline conversion data sets for the ad account.
list_product_setsreadList product sets within a catalog.
list_productsreadList products within a catalog.
list_rf_predictionsreadList reach & frequency predictions for the ad account. Returns paginated results.
list_rulesreadList automated rules for the ad account.
list_saved_audiencesreadList saved audiences in the ad account. Saved audiences are reusable targeting presets.
list_system_usersreadList system users of the configured business. Requires META_BUSINESS_ID env var.
list_videosreadList ad videos uploaded to the ad account.
refresh_tokenreadExtend a valid long-lived user access token through Meta
remove_business_userdestructiveRemove a user from the configured business. Requires META_BUSINESS_ID env var.
remove_from_block_listdestructiveRemove publisher URLs from an existing block list.
remove_users_from_audiencedestructiveRemove users from a custom audience. Payload format is the same as add_users_to_audience.
search_ad_libraryreadSearch the Meta Ad Library for ads. Allows searching by keywords, countries, and ad type. Useful for competitive research and transparency.
search_locationsreadSearch for geographic locations (countries, regions, cities, zip codes) for ad targeting.
search_targetingreadSearch for targeting options (interests, behaviors, demographics, etc.) by keyword. Use this to find valid targeting IDs for ad set targeting specs.
search_targeting_mapreadMap targeting IDs to their full details (names, types, paths). Useful for resolving IDs obtained from other endpoints.
send_conversion_eventwriteSend a server-side conversion event via the Conversions API (pixel).
send_offline_eventwriteSend an offline conversion event to an offline event set.
update_adwriteUpdate an existing ad. Only provided fields will be modified.
update_ad_accountwriteUpdate the configured ad account settings. Only provided fields will be modified.
update_adsetwriteUpdate an existing ad set. Only provided fields will be modified.
update_audiencewriteUpdate an existing custom audience. Only provided fields will be modified.
update_budget_schedulewriteUpdate an existing budget schedule. Only provided fields will be modified.
update_campaignwriteUpdate an existing campaign. Only provided fields will be modified.
update_catalogwriteUpdate an existing product catalog.
update_creativewriteUpdate an existing ad creative. Only name and url_tags can be modified after creation.
update_experimentwriteUpdate an existing experiment (ad study).
update_productwriteUpdate an existing product in a catalog.
update_product_setwriteUpdate an existing product set.
update_rulewriteUpdate an existing automated rule.
upload_feedwriteUpload/trigger a feed file upload for a product feed.
upload_imagewriteUpload an ad image from a public URL or a local file. Returns image hash for use in ad creatives. Note: fetching from a URL requires the app to have Meta
upload_videowriteUpload an ad video from a public URL or a local file. Returns video ID for use in ad creatives.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
batch_products, delete_ad, delete_adset, delete_audience, delete_block_list, delete_budget_schedule, delete_campaign, delete_canvas, delete_image, delete_rf_prediction, delete_rule, delete_video, remo
Why it matters. 15 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, zod, @types/node, tsx, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 94ad503999a7full audit observations/trust-audit/mcp-server/mikusnuz__meta-ads-5.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0794ad503999a7SAFEB89first audit
06

Questions

What is the Meta Ads MCP server?

MCP server for Meta Marketing API v25.0 — 135 tools for Facebook & Instagram ad campaign management

What tools does Meta Ads expose?

134 in total: 68 read-only, 51 that write, and 15 that can delete or overwrite (batch_products, delete_ad, delete_adset, delete_audience, delete_block_list). Every one is listed on this page with its risk.

Is Meta Ads safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 15 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Meta Ads need?

It reads META_ADS_ACCESS_TOKEN and META_APP_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Meta Ads run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @mikusnuz/meta-ads-mcp at 1.4.1.

How current is this page?

The grade is for one exact copy of the source (94ad503999a7), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement