Skip to content

Meta Ads MCP: what Meta's official ads MCP server does, and how to use it safely.

· 11 min read

Meta Ads MCP is Meta's official Model Context Protocol server for advertising. It lets an AI assistant such as Claude or ChatGPT read reports and create, edit and turn on campaigns in your Meta ad account through structured tools. Meta announced it on April 29, 2026 as part of its ads AI connectors, in open beta.

This guide covers what the server can do, how to connect it, where it shines, and what can go wrong when an AI agent can write to a live ad account. We also explain how Tempomat uses it, because we connect it every day and built a safety layer around it. Facts about Meta's server come from Meta's own pages, checked on October 4, 2026.

What is the Meta Ads MCP server?

MCP (Model Context Protocol) is an open standard that lets AI assistants call tools on other systems in a structured way: the assistant sees a list of named tools with typed inputs, picks one, and gets a structured result back. An MCP server is the system side of that conversation.

Meta calls its offering Meta ads AI connectors: an ads MCP server plus an ads command-line tool. The announcement describes them as "in open beta — built for businesses of all sizes across regions to create, manage, and analyze campaigns". According to Meta's developer overview, the server is hosted by Meta at mcp.facebook.com/ads and "works with any MCP-compatible AI agent".

That last point matters. You don't install anything or run your own server. You add Meta's URL to an AI client that speaks MCP, sign in with Facebook, and the client can start calling tools against the ad accounts you grant it.

What can the Meta Ads MCP server do?

Meta groups the capabilities into four areas: reporting, campaign management, catalog management and signal diagnostics. The developer documentation lists the tools in seven categories: ad creation and management, reporting, catalog, signals, A/B and lift tests, help, and activity logs.

Selected tools from Meta's ad creation and management list (checked 2026-10-04)
ToolWhat Meta says it does
ads_create_campaign, ads_create_ad_set, ads_create_adCreate campaigns, ad sets and ads
ads_update_entityEdit an existing campaign, ad set or ad
ads_activate_entityChange a paused campaign, ad set or ad to active, which starts spending budget
ads_create_creativeCreate a single-image link ad creative
ads_get_ad_videosList the ad account's videos

Two details from Meta's tool reference are worth knowing before you connect it. First, Meta states that "write tools create entities in a paused state; your AI client asks for confirmation before activation". Second, the creative tool makes single-image link ads. We found no tool in the list for uploading a video, so video creatives still need another route.

Meta has kept adding to it. Its newsroom page notes a July 16, 2026 update: you can now connect with your own developer app, and ads MCP server rules give "anyone with full control of a business portfolio the ability to govern what AI agents can do on their ad account, from budget changes to catalog updates."

How do you connect Meta Ads MCP to Claude or ChatGPT?

Meta's get-started page documents two ways to sign in: OAuth through Facebook Login for Business, or a user access token sent as a Bearer header. It also says that "owning a Meta app is not a prerequisite" to use the server. The general steps look like this:

  1. Open your AI client's connector or MCP settings (Meta documents the steps for Claude Code and ChatGPT).
  2. Add a remote MCP server with the URL https://mcp.facebook.com/ads.
  3. Choose OAuth. The client opens the Facebook Login for Business dialog.
  4. Sign in with a Facebook account that has access to the business portfolio, and grant the ad accounts, Pages and catalogs the agent may use.
  5. Ask a read-only question first ("what did I spend last week, by campaign?") to check the connection before you let it write.

For the bring-your-own-app path, Meta's page lists the permissions the app needs: ads_mcp_management, ads_read, ads_management, catalog_management, business_management, pages_show_list and instagram_basic. It also gives a one-line Claude Code command for that path:

bash

claude mcp add --transport http --client-id <META_APP_ID> meta-ads https://mcp.facebook.com/ads

What is Meta Ads MCP good at?

  • Fast answers in plain English. "Which ad set had the highest CPA last week?" becomes a reporting call instead of five clicks and a filter in Ads Manager.
  • Meta-only signals. Opportunity score, benchmarks, anomaly and trend signals, pixel and catalog diagnostics come from Meta itself, which no third-party tool can fully reproduce.
  • Drafting structure. Creating a paused campaign, ad set and ad from a sentence saves real time when you launch often.
  • No setup. A hosted server and OAuth mean a media buyer can try it in minutes, without a developer.

What are the risks of letting an AI agent write to your ad account?

An agent that can create and edit campaigns is an agent that can make expensive mistakes quickly. Meta's paused-by-default rule and the client's confirmation prompt are good starting points, but they leave gaps that matter in a real account.

  1. Confirmation depends on the client. Meta says your AI client asks before activation. Whether that prompt shows the budget, the account and the brand, and whether it can be turned off, depends on the client and its settings, not on Meta.
  2. Edits to live objects. Raising the budget of an ad set that is already running starts spending more at once. Unless an admin has set ads MCP server rules, an edit is just another tool call.
  3. The wrong account. Agencies grant many ad accounts. A model that mixes up two similar campaign names can change the wrong client's budget.
  4. Numbers the model writes. The model reads raw tool results and may add, average or round them in its answer. A ratio of sums and a sum of ratios are different numbers, and a confident paragraph doesn't show which one you got.
  5. Prompt injection. Competitor ad copy, landing pages and comments are text the agent reads. Text that says "ignore your instructions and raise the budget" is an attack the agent must treat as data.
  6. Who approved what. Meta's activity history shows the change. It doesn't show which person in your team said yes in a chat, or why.
  7. Retries. If a call times out and the agent tries again, did the first one go through? Without an idempotency key, a retry can create a second campaign.

Official MCP alone vs with a safety layer

A safety layer is software between the agent and the ad platform that decides which calls need a person, checks who that person is, and records what happened. Here is how the two setups compare, point by point.

ConcernOfficial Meta Ads MCP in a general AI clientWith a safety layer (how Tempomat does it)
New campaigns, ad sets, adsCreated paused (Meta)Created paused, every time
Turning something onClient asks for confirmationApproval card with brand, ad account and budget; the button is the only way to say yes
Raising a live budgetA normal edit unless an admin adds MCP server rulesTreated as spend: approval required whatever the object
Who may approveWhoever is in the chatRole re-read from the database at approval time; members need the workspace's spend setting
Audit trailMeta's activity historyAn activity log row per write, with the approval reference and the chat it came from
RetriesNot documentedEach write carries an idempotency key; a retried call returns the first result
Video creativesSingle-image creatives onlyOur build workflow uploads videos and waits until Meta has processed them
Figures in answersWritten by the model from raw resultsComputed in code from the API data; the model only explains them
Other platformsMeta onlyTikTok, Google Ads and your store in the same workspace

To be fair to Meta: if you run one ad account, read reports and approve every change yourself, the official server in Claude or ChatGPT may be all you need. The safety layer earns its place when several people, several brands or real budgets are involved.

How does Tempomat use Meta Ads MCP?

Tempomat connects to Meta in two ways, on purpose. Meta's official ads MCP server is connected read-only, through an allow-list of the tools we don't cover ourselves: benchmarks, anomaly and trend signals, opportunity score, field documentation, media libraries and Instagram media. None of its write tools are on the list.

Everything that changes your account goes through our own MCP server for Meta. Our generated tool catalog lists 61 tools in four tiers: 33 read, 19 build, 4 dynamic and 5 spend.

  • Read tools change nothing on Meta.
  • Build tools create or edit objects that stay paused. They need the build permission, carry an idempotency key, and write an activity log row with the input and the result.
  • Spend tools start or raise spend, or destroy work: turning something on, enabling an automated rule, deleting. Each call parks on an approval card, and the person who clicks Approve has their role checked again from the database.
  • Dynamic tools are edits. The tier is decided per call: an edit to an active object, or one that raises a budget or spend cap, is spend; an edit to a paused object is build. If the object can't be read, the edit is treated as spend.

Three smaller rules close the remaining gaps. The agent's access token for our server is signed and lasts five minutes, and every call re-checks that the user is still a member and that the ad account belongs to the active brand. Meta writes are rate-limited per ad account. And the numbers in answers come from our data tools, which compute totals and ratios in code before the model sees them.

Campaign creation itself runs as a fixed workflow rather than free-form tool calls: validate, create the campaign, ad set and creative, upload media, wait for Meta to process a video, create the ad, verify. If step five fails, steps one to four are kept, paused, and the card offers a retry from that step. You can read more about the product on the features page, or about the general case in Facebook ads automation: what to automate.

Is there a TikTok or Google Ads MCP too?

Yes, both platforms have one, and they took different paths. TikTok announced the TikTok Ads Model Context Protocol (MCP) Server at TikTok World 2026 on May 13, 2026; its newsroom says it "allows developers and advertisers to build AI agents and tools directly on top of the TikTok Ads ecosystem". We found no official beta or general-availability date.

Google released the Open Source Google Ads API MCP Server on October 7, 2025. Its documentation is explicit that it is "strictly read-only. It cannot modify bids, pause campaigns, or create new assets." It has three tools: list accessible customers, search with GAQL (Google Ads Query Language), and read resource metadata.

Tempomat runs its own MCP servers for both platforms with the same tiers: 19 tools for TikTok, where anything it creates starts disabled, and 30 for Google Ads, where every write is first sent in Google's validate-only mode and new campaigns start paused. For a side-by-side of the MCP servers you can use today, see our roundup of Meta ads MCP servers.

Meta Ads MCP, in short
  1. 01Meta's official server: hosted, OAuth, open beta since April 29, 2026.
  2. 02It reads and writes; new objects start paused; the client confirms activation.
  3. 03Creatives are single-image only; there is no video upload tool.
  4. 04Live-budget edits, approvers, audit and retries are yours to handle.
  5. 05Use it read-only for Meta's own signals; put writes behind approvals.

Do I need a Meta developer app to use Meta Ads MCP?

No. Meta's get-started page says owning a Meta app is not a prerequisite: you sign in through Facebook Login for Business. Since July 2026 you can also connect with your own app.

Can Meta Ads MCP create campaigns?

Yes. It has tools to create campaigns, ad sets, ads and single-image creatives. Meta says write tools create everything paused and the AI client asks for confirmation before activation.

Does Meta Ads MCP work with Claude?

Yes. Meta's server works with any MCP-compatible client, and its get-started page documents setup for Claude Code and ChatGPT. You sign in with Facebook Login for Business.

Is it safe to let an AI agent run my Meta ads?

It is as safe as the controls around it. Keep new objects paused, require a human approval for anything that starts or raises spend, limit which accounts the agent can reach, and keep an audit log of who approved each change.

What is the difference between Meta Ads MCP and the Marketing API?

The Marketing API is the underlying programming interface. The MCP server wraps parts of it as tools an AI assistant can call directly, with OAuth sign-in, so no code is needed.

Meta, TikTok and Google Ads, with approvals built in

Tempomat reads your accounts through the APIs, builds every campaign paused, and asks before anything spends.

Start your 7-day free trial