Meta AdsSAFE
MCP server for Meta Marketing API v25.0 — 135 tools for Facebook & Instagram ad campaign management
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@mikusnuz/meta-ads-mcp) [](https://opensource.org/licenses/MIT)
MCP server for the Meta Marketing API v26.0 — 135 tools for managing Facebook & Instagram ad campaigns, audiences, creatives, insights, catalogs, and more.
When to Use
Use this MCP when you need to:
- "Create a new Facebook ad campaign" — use
create_campaign,create_adset,create_ad, andcreate_creativeto build a full funnel - "Check how my ads are performing today" — use
get_account_insightsorget_campaign_insightswith today's date range - "Pause all campaigns with ROAS below 2" — use
list_campaigns+get_campaign_insightsto find underperformers, thenupdate_campaignto pause - "Set up A/B test between two ad creatives" — use
create_experimentto run a controlled test between ad sets - "Create a lookalike audience from my customers" — use
create_custom_audience,add_users_to_audience, thencreate_lookalike_audience - "Upload ad images and create a carousel ad" — use
upload_imagefor each image, thencreate_creativewith carousel format - "Get a detailed performance report for last 30 days" — use
create_async_reportfor large date ranges, thenget_async_reportto retrieve - "Search the Facebook Ad Library for competitor ads" — use
search_ad_libraryto find public ad data - "Set up automated rules to pause underperforming ads" — use
create_rulewith conditions like CPA > threshold - "Manage my product catalog for dynamic ads" — use
create_catalog,create_feed, andupload_feedto set up dynamic product ads
Installation
{
"mcpServers": {
"meta-ads": {
"command": "npx",
"args": ["-y", "@mikusnuz/meta-ads-mcp"],
"env": {
"META_ADS_ACCESS_TOKEN": "your-access-token",
"META_AD94ad503999a7OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add meta-ads-mcp --env META_ADS_ACCESS_TOKEN=${META_ADS_ACCESS_TOKEN} --env META_APP_SECRET=${META_APP_SECRET} -- npx -y @mikusnuz/[email protected]Exposed tools (134)
68 read · 51 write · 15 destructive. Blast radius: 15 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_business_user | write | Add a user to the configured business by email. Requires META_BUSINESS_ID env var. |
add_to_block_list | write | Add publisher URLs to an existing block list. |
add_users_to_audience | write | Add users to a custom audience. Payload must be a JSON string containing hashed user data with a schema array defining the data types (e.g. EMAIL, PHONE, FN, LN). |
batch_products | destructive | Batch create, update, or delete products in a catalog. Supports up to 5,000 items per request. Update operations support upsert. |
copy_ad | write | Copy an existing ad. Creates a duplicate within the same or different ad set. |
copy_adset | write | Copy an existing ad set. Creates a duplicate within the same or different campaign. |
copy_campaign | read | Copy an existing campaign. Creates a duplicate with optional name override. Copies structure including ad sets and ads. |
create_ad | write | Create a new ad. Requires name, adset_id, and creative (JSON object_story_spec). Defaults to PAUSED status. |
create_adset | write | Create a new ad set. Requires name, campaign_id, budget, optimization_goal, billing_event, and targeting. Defaults to PAUSED status. |
create_async_report | write | Create an async insight report for large data queries. Returns a report_run_id to poll with get_async_report. |
create_block_list | write | Create a new publisher block list for the ad account. |
create_budget_schedule | write | Create a budget schedule on a campaign or ad set. |
create_campaign | write | Create a new ad campaign. Defaults to PAUSED status. Requires name and objective. Budget can be set at campaign or ad set level. |
create_canvas | write | Create a new Instant Experience (Canvas) on a Facebook Page. Requires page_id and body_elements JSON array defining the canvas layout. |
create_catalog | write | Create a new product catalog for the ad account. |
create_creative | write | |
create_custom_audience | write | Create a new custom audience. Subtype determines the audience source (CUSTOM, WEBSITE, APP, OFFLINE_CONVERSION, LOOKALIKE, ENGAGEMENT, etc.). |
create_dynamic_creative | write | Create a dynamic creative with asset_feed_spec. Meta automatically combines different images, videos, titles, bodies, and CTAs to find the best performing combinations. |
create_experiment | write | Create a new A/B test experiment (ad study). |
create_feed | write | Create a new product feed for a catalog. |
create_lead_form | write | Create a new lead generation form on a Facebook Page. Requires pages_manage_ads permission. |
create_lookalike_audience | write | Create a lookalike audience based on an existing custom audience. Ratio (1-10) determines how closely the new audience resembles the source. |
create_offline_event_set | write | Create a new offline conversion data set. |
create_product_set | write | Create a new product set within a catalog. |
create_rf_prediction | write | Create a new reach & frequency prediction. Provide targeting spec as JSON string, budget in cents, and scheduling info. |
create_rule | write | Create a new automated rule for the ad account. |
create_system_user | write | Create a new system user in the configured business. Requires META_BUSINESS_ID env var. |
debug_token | read | Debug an access token to inspect its properties, permissions, expiration, and validity. Requires META_APP_ID and META_APP_SECRET. |
delete_ad | destructive | Delete an ad. This action is irreversible. |
delete_adset | destructive | Delete an ad set. This action is irreversible. |
delete_audience | destructive | Delete a custom audience. This action is irreversible. |
delete_block_list | destructive | Delete a publisher block list. This action is irreversible. |
delete_budget_schedule | destructive | Delete a budget schedule. This action is irreversible. |
delete_campaign | destructive | Delete a campaign. This action is irreversible. |
delete_canvas | destructive | Delete an Instant Experience (Canvas). This action is irreversible. |
delete_image | destructive | Delete an ad image by hash. This action is irreversible. |
delete_rf_prediction | destructive | Delete a reach & frequency prediction. This action is irreversible. |
delete_rule | destructive | Delete an automated rule. |
delete_video | destructive | Delete an ad video. This action is irreversible. |
exchange_token | read | Exchange a short-lived access token for a long-lived token. Requires META_APP_ID and META_APP_SECRET to be configured. |
generate_preview | read | Generate an ad preview without needing an existing ad. Provide creative spec directly to see how it would look. |
get_account_activities | read | Get activity log for the ad account. Shows changes made to campaigns, ad sets, ads, etc. |
get_account_insights | read | Get performance insights for the ad account. Returns metrics like impressions, clicks, spend, reach, etc. |
get_ad | read | Get details of a specific ad by ID. |
get_ad_account | read | Get details of the configured ad account including status, balance, currency, timezone, and spend info. |
get_ad_insights | read | Get performance insights for a specific ad. |
get_ad_preview | read | Get a preview of an ad in a specific format. Returns HTML iframe for rendering. |
get_adset | write | Get details of a specific ad set by ID. |
get_adset_ads | write | Get all ads belonging to a specific ad set. |
get_adset_insights | write | Get performance insights for a specific ad set. |
get_adset_leads | write | Get leads generated by a specific ad set. Requires leads_retrieval permission. |
get_adset_targeting_sentence | write | Get human-readable targeting description for an ad set. Converts targeting spec into readable sentences. |
get_async_report | read | Check status and retrieve results of an async insight report. |
get_audience | read | Get details of a specific custom audience by ID. |
get_audience_health | read | Get health status and delivery readiness of a custom audience. Shows match rate, size, and operation status. |
get_batch_status | read | Check the status of a catalog batch operation. |
get_business | read | Get details of a specific business by ID. |
get_campaign | read | Get details of a specific campaign by ID. |
get_campaign_ads | read | Get all ads belonging to a specific campaign. |
get_campaign_adsets | read | Get all ad sets belonging to a specific campaign. |
get_campaign_insights | read | Get performance insights for a specific campaign. |
get_campaign_leads | read | Get leads generated by a specific campaign. Requires leads_retrieval permission. |
get_canvas | read | Get details of a specific Instant Experience (Canvas) by ID. |
get_catalog | read | Get details of a specific product catalog. |
get_creative | read | Get details of a specific ad creative by ID. |
get_delivery_estimate | read | |
get_experiment | read | Get details of a specific experiment (ad study). |
get_experiment_results | read | Get results/cells of an experiment (ad study). |
get_feed_uploads | write | Get upload history for a product feed. |
get_form_leads | read | Get leads submitted through a lead generation form. |
get_image | read | Get details of a specific ad image by ID. |
get_lead | read | Get details of a specific lead by ID. |
get_lead_form | read | Get details of a specific lead generation form. |
get_product | read | Get details of a specific product. |
get_product_set | write | Get details of a specific product set. |
get_reach_estimate | read | Get estimated audience reach for a given targeting specification. Useful for planning campaigns before creating them. |
get_rf_prediction | read | Get details of a specific reach & frequency prediction by ID. |
get_rule | read | Get details of a specific automated rule. |
get_saved_audience | read | Get details of a specific saved audience by ID. |
get_targeting_suggestions | read | Get targeting suggestions based on existing targeting criteria. Meta suggests related interests, behaviors, and demographics. |
get_video | read | Get details of a specific ad video by ID. |
list_account_users | read | List users who have access to the ad account with their roles and permissions. |
list_ad_accounts | read | List all ad accounts accessible by the current user. Returns paginated results. |
list_ads | write | List ads in the ad account. Optionally filter by campaign, ad set, or status. |
list_adsets | read | List ad sets in the ad account. Optionally filter by campaign or status. |
list_block_lists | read | List publisher block lists for the ad account. Returns paginated results. |
list_budget_schedules | write | List budget schedules attached to a campaign or ad set. Returns paginated results. |
list_business_ad_accounts | read | List ad accounts owned by the configured business. Requires META_BUSINESS_ID env var. |
list_business_instagram_accounts | read | List Instagram accounts owned by the configured business. Requires META_BUSINESS_ID env var. |
list_business_pages | read | List Facebook Pages owned by the configured business. Requires META_BUSINESS_ID env var. |
list_business_users | read | List users of the configured business. Requires META_BUSINESS_ID env var. |
list_businesses | read | List all businesses accessible by the current user. Returns paginated results. |
list_campaigns | read | List campaigns in the ad account. Supports filtering by status and objective. Returns paginated results. |
list_canvases | read | List Instant Experience (Canvas) creatives in the ad account. |
list_catalogs | read | List product catalogs for the ad account. |
list_creatives | read | List ad creatives in the ad account. |
list_custom_audiences | read | List custom audiences in the ad account. |
list_experiments | read | List A/B test experiments (ad studies) for the ad account. |
list_feeds | read | List product feeds for a catalog. |
list_images | read | List ad images uploaded to the ad account. |
list_lead_forms | read | List lead generation forms for a Facebook Page. |
list_offline_event_sets | read | List offline conversion data sets for the ad account. |
list_product_sets | read | List product sets within a catalog. |
list_products | read | List products within a catalog. |
list_rf_predictions | read | List reach & frequency predictions for the ad account. Returns paginated results. |
list_rules | read | List automated rules for the ad account. |
list_saved_audiences | read | List saved audiences in the ad account. Saved audiences are reusable targeting presets. |
list_system_users | read | List system users of the configured business. Requires META_BUSINESS_ID env var. |
list_videos | read | List ad videos uploaded to the ad account. |
refresh_token | read | Extend a valid long-lived user access token through Meta |
remove_business_user | destructive | Remove a user from the configured business. Requires META_BUSINESS_ID env var. |
remove_from_block_list | destructive | Remove publisher URLs from an existing block list. |
remove_users_from_audience | destructive | Remove users from a custom audience. Payload format is the same as add_users_to_audience. |
search_ad_library | read | Search the Meta Ad Library for ads. Allows searching by keywords, countries, and ad type. Useful for competitive research and transparency. |
search_locations | read | Search for geographic locations (countries, regions, cities, zip codes) for ad targeting. |
search_targeting | read | Search for targeting options (interests, behaviors, demographics, etc.) by keyword. Use this to find valid targeting IDs for ad set targeting specs. |
search_targeting_map | read | Map targeting IDs to their full details (names, types, paths). Useful for resolving IDs obtained from other endpoints. |
send_conversion_event | write | Send a server-side conversion event via the Conversions API (pixel). |
send_offline_event | write | Send an offline conversion event to an offline event set. |
update_ad | write | Update an existing ad. Only provided fields will be modified. |
update_ad_account | write | Update the configured ad account settings. Only provided fields will be modified. |
update_adset | write | Update an existing ad set. Only provided fields will be modified. |
update_audience | write | Update an existing custom audience. Only provided fields will be modified. |
update_budget_schedule | write | Update an existing budget schedule. Only provided fields will be modified. |
update_campaign | write | Update an existing campaign. Only provided fields will be modified. |
update_catalog | write | Update an existing product catalog. |
update_creative | write | Update an existing ad creative. Only name and url_tags can be modified after creation. |
update_experiment | write | Update an existing experiment (ad study). |
update_product | write | Update an existing product in a catalog. |
update_product_set | write | Update an existing product set. |
update_rule | write | Update an existing automated rule. |
upload_feed | write | Upload/trigger a feed file upload for a product feed. |
upload_image | write | Upload an ad image from a public URL or a local file. Returns image hash for use in ad creatives. Note: fetching from a URL requires the app to have Meta |
upload_video | write | Upload an ad video from a public URL or a local file. Returns video ID for use in ad creatives. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
batch_products, delete_ad, delete_adset, delete_audience, delete_block_list, delete_budget_schedule, delete_campaign, delete_canvas, delete_image, delete_rf_prediction, delete_rule, delete_video, remo
@modelcontextprotocol/sdk, zod, @types/node, tsx, typescript
Gates applied: no_behavioural_pass.
94ad503999a7full audit observations/trust-audit/mcp-server/mikusnuz__meta-ads-5.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 94ad503999a7 | SAFE | B | 89 | first audit |
Questions
What is the Meta Ads MCP server?
MCP server for Meta Marketing API v25.0 — 135 tools for Facebook & Instagram ad campaign management
What tools does Meta Ads expose?
134 in total: 68 read-only, 51 that write, and 15 that can delete or overwrite (batch_products, delete_ad, delete_adset, delete_audience, delete_block_list). Every one is listed on this page with its risk.
Is Meta Ads safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 15 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Meta Ads need?
It reads META_ADS_ACCESS_TOKEN and META_APP_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Meta Ads run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @mikusnuz/meta-ads-mcp at 1.4.1.
How current is this page?
The grade is for one exact copy of the source (94ad503999a7), read on 2026-10-07. The repository is watched and re-audited when it changes.