{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "meta-marketing-api",
    "name": "Meta Marketing API",
    "vendor": "Meta Platforms, Inc.",
    "vendorUrl": "https://developers.facebook.com",
    "kind": "http-api",
    "category": "advertising",
    "summary": "Meta's Marketing API creates and manages campaigns, ad sets, ads, creatives and audiences across Facebook, Instagram, Messenger and WhatsApp, and reports performance through Ads Insights. It is a versioned Graph API with OAuth access tokens.",
    "url": "https://www.anchorterminal.com/tools/meta-marketing-api",
    "markdownUrl": "https://www.anchorterminal.com/tools/meta-marketing-api.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/meta-marketing-api.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/meta-marketing-api.json",
    "repo": "https://github.com/facebook/facebook-python-business-sdk",
    "license": "Proprietary service under the Meta Platform Terms. The Business SDKs and the codegen specs on GitHub carry Meta's own platform licence, which allows use only with Meta's APIs",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://graph.facebook.com",
    "packages": [
      {
        "registry": "pypi",
        "name": "facebook-business"
      },
      {
        "registry": "npm",
        "name": "facebook-nodejs-business-sdk"
      },
      {
        "registry": "pypi",
        "name": "meta-ads"
      }
    ],
    "auth": "oauth",
    "authNotes": "Every call needs an access token from a Meta developer app with the Marketing API product added. Access is self-serve at the Limited tier. A user token comes from the Facebook Login OAuth dialogue with the `ads_read` or `ads_management` scope, and a system user token, created in Meta Business Suite, doesn't expire. Managing ad accounts owned by other businesses needs advanced access to those permissions through App Review, and business verification may be required. Full access (higher rate limits and the Business Manager API) is granted from the App Dashboard after 500 successful calls in 15 days with an error rate under 15 per cent.",
    "pricing": "free",
    "pricingNotes": "No charge for API calls was found in the Platform Terms or the Marketing API documentation. Access tiers differ by rate limit, and ad spend is billed to the ad account. An agent can start without a contract. Limited access is automatic when the Marketing API product is added to an app, and a sandbox ad account takes read and write calls with no funding source (checked 2026-10-08).",
    "priceSummary": "Free",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the Marketing API documentation, the llms.txt indexes or the Platform Terms (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 1604,
      "npmWeekly": 500852,
      "pypiWeekly": 1089043,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://developers.facebook.com/docs/marketing-apis/",
    "llmsTxt": "https://developers.facebook.com/documentation/ads-commerce/llms.txt",
    "capabilities": [
      "ads.reporting",
      "ads.campaigns",
      "ads.budgets",
      "ads.audiences",
      "ads.creatives"
    ],
    "tags": [
      "hosted",
      "free",
      "oauth",
      "app-review",
      "sandbox",
      "mcp",
      "cli",
      "llms-txt",
      "python",
      "typescript",
      "php",
      "ruby",
      "java",
      "status-page",
      "bug-bounty"
    ],
    "lastRelease": "2026-09-21",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 67.7,
      "grade": "B",
      "agentReady": false,
      "rank": 187,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 2,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 77,
        "maintenance": 74,
        "payments": 30,
        "reliability": 80,
        "schema": 76,
        "security": 61,
        "transparency": 68
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 80,
          "points": 16,
          "reason": "Graded on the public Marketing API. metastatus.com lists Marketing API with two components, Ads Creation and Editing API and Ads Insights API, and an incident history (20). Neither Marketing API nor Graph API shows an incident in the 90 days to 8 October 2026. The last was on 12 June 2026, about three hours on creation and editing. Ads Manager's Ads Delivery component had four incidents in the window (16 and 19 July, 21 August, 22 September), two marked high disruption for over two hours each, so we departed from the full 30 (25). Rate limits are published with numbers per tier and use case (15). The docs ask for exponential backoff and name usage headers with `estimated_time_to_regain_access`, but no idempotency key for writes was found (10). No SLA found (0). The API is generally available, while the Ads MCP server was announced in open beta (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 76,
          "points": 12.35,
          "reason": "No OpenAPI document. Meta publishes its own JSON specs for 1,105 objects in facebook/facebook-business-sdk-codegen, refreshed on 17 September 2026, and a 47-request Postman collection (15). llms.txt indexes and a Markdown copy of each guide and reference page, with a section of rules for AI agents (10). Reference pages describe each field and guides cover when to use asynchronous reports, batches and sandbox mode, with little on when not to use an endpoint (13). Parameters carry types, enums, defaults and required marks, though targeting and creative specs travel as JSON strings in form fields (11). Request examples per endpoint in several languages and an error reference with codes and subcodes. Examples still use v25.0, and one Insights example uses v2.7 (12). Numbered versions, per-version changelogs and a dated out-of-cycle log (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 77,
          "points": 12.51,
          "reason": "Responses can be sized with `fields`, `limit`, Insights `level` and summaries. The Ads MCP server is not what we graded, and its 91 documented tools would score lower here (20). Cursor paging, `filtering`, date presets, breakdowns, asynchronous report runs, batch requests and ETags (20). Errors carry `code`, `error_subcode`, `error_user_title`, `error_user_msg` and `fbtrace_id`, and the error reference maps codes to causes (17). No idempotency key was found in the reviewed documentation. `execution_options=validate_only` tests a write without performing it, and objects can be created paused (8). Business SDKs in five languages, but npm's Node.js package is two versions behind, every path needs a version, and campaign creation needs `special_ad_categories` as well as name, objective and status (12)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 61,
          "points": 10.68,
          "reason": "OAuth 2.0 access tokens with scopes, revocable, with system users for servers and optional `appsecret_proof`. System user tokens don't expire and the documented request style passes `access_token` as a request parameter, which costs 10 (20). `ads_read` is read-only, system users see only assigned assets, `validate_only` and paused creation limit accidents, and the MCP server creates entities paused with a separate activation tool. The API itself has no approval step before a write that spends (14). Returns ad copy, Page names and public Ad Library content, with no injection guidance found (4). Ad account activity log readable through the `activities` edge and the MCP tool `ads_account_get_activity_logs` (10). security.txt valid to 7 November 2026, a bug bounty at bugbounty.meta.com and a published disclosure policy. No SOC 2 or ISO 27001 statement for this API was found in the pages read (13)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "No x402, MPP or L402 (0). No charge for API calls was found and no price list exists for the API. Tiers differ by rate limit and ad spend is billed to the ad account, so we scored the middle value (10). Limited access is automatic with no card, and a sandbox ad account needs no funding source (20). A person has to create a Meta account and a developer app in a browser, and App Review applies to managing other businesses' accounts (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 74,
          "points": 6.48,
          "reason": "Python SDK 26.0.2 on PyPI on 21 September 2026 and the `meta-ads` CLI 1.2.0 on 29 September (30). Marketing API v26.0 on 29 July, and SDK tags 25.0.3, 26.0.0, 26.0.1 and 26.0.2 between 17 July and 17 September (20). Closed service with a dated changelog, a support page and a developer community group. The Marketing API changelog and versioning pages still name v25.0 as current, the out-of-cycle log ends on 28 June 2026, and the 30 newest open issues on the Python SDK repository are spam with no replies (7). Official SDKs in five languages, current on PyPI at 26.0.2, while npm's latest is 24.0.1 from 21 November 2025 (10). CI and publish workflows in the SDK repositories, with generated code and a changelog that stops at v25.0.3 (7)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 68,
          "points": 5.95,
          "note": "editorial 41, provenance 94",
          "reason": "Editorial half only. Closed service with clear Platform Terms and Developer Policies, both last updated 3 February 2026. The SDKs use Meta's own platform licence, which isn't an OSI licence (15). The Platform Terms set out what a developer may do with Platform Data, deletion duties and Meta's audit rights. Meta's privacy policy and data processing terms render only with JavaScript and weren't read, so retention on Meta's side is unscored (10). A written 90-day minimum for version removal, expiry dates per version and dated deprecation notices such as Poll ads on 27 October 2026 (20). The terms name Meta Platforms Ireland Limited and Meta Platforms, Inc. as controllers for EEA and UK transfers. No subprocessor list or data location list was read (3)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Responses can be sized with `fields`, `limit`, Insights `level` and summaries. The Ads MCP server is not what we graded, and its 91 documented tools would score lower here (20). Cursor paging, `filtering`, date presets, breakdowns, asynchronous report runs, batch requests and ETags (20). Errors carry `code`, `error_subcode`, `error_user_title`, `error_user_msg` and `fbtrace_id`, and the error reference maps codes to causes (17). No idempotency key was found in the reviewed documentation. `execution_options=validate_only` tests a write without performing it, and objects can be created paused (8). Business SDKs in five languages, but npm's Node.js package is two versions behind, every path needs a version, and campaign creation needs `special_ad_categories` as well as name, objective and status (12).",
          "maintenance": "Python SDK 26.0.2 on PyPI on 21 September 2026 and the `meta-ads` CLI 1.2.0 on 29 September (30). Marketing API v26.0 on 29 July, and SDK tags 25.0.3, 26.0.0, 26.0.1 and 26.0.2 between 17 July and 17 September (20). Closed service with a dated changelog, a support page and a developer community group. The Marketing API changelog and versioning pages still name v25.0 as current, the out-of-cycle log ends on 28 June 2026, and the 30 newest open issues on the Python SDK repository are spam with no replies (7). Official SDKs in five languages, current on PyPI at 26.0.2, while npm's latest is 24.0.1 from 21 November 2025 (10). CI and publish workflows in the SDK repositories, with generated code and a changelog that stops at v25.0.3 (7).",
          "payments": "No x402, MPP or L402 (0). No charge for API calls was found and no price list exists for the API. Tiers differ by rate limit and ad spend is billed to the ad account, so we scored the middle value (10). Limited access is automatic with no card, and a sandbox ad account needs no funding source (20). A person has to create a Meta account and a developer app in a browser, and App Review applies to managing other businesses' accounts (0).",
          "reliability": "Graded on the public Marketing API. metastatus.com lists Marketing API with two components, Ads Creation and Editing API and Ads Insights API, and an incident history (20). Neither Marketing API nor Graph API shows an incident in the 90 days to 8 October 2026. The last was on 12 June 2026, about three hours on creation and editing. Ads Manager's Ads Delivery component had four incidents in the window (16 and 19 July, 21 August, 22 September), two marked high disruption for over two hours each, so we departed from the full 30 (25). Rate limits are published with numbers per tier and use case (15). The docs ask for exponential backoff and name usage headers with `estimated_time_to_regain_access`, but no idempotency key for writes was found (10). No SLA found (0). The API is generally available, while the Ads MCP server was announced in open beta (10).",
          "schema": "No OpenAPI document. Meta publishes its own JSON specs for 1,105 objects in facebook/facebook-business-sdk-codegen, refreshed on 17 September 2026, and a 47-request Postman collection (15). llms.txt indexes and a Markdown copy of each guide and reference page, with a section of rules for AI agents (10). Reference pages describe each field and guides cover when to use asynchronous reports, batches and sandbox mode, with little on when not to use an endpoint (13). Parameters carry types, enums, defaults and required marks, though targeting and creative specs travel as JSON strings in form fields (11). Request examples per endpoint in several languages and an error reference with codes and subcodes. Examples still use v25.0, and one Insights example uses v2.7 (12). Numbered versions, per-version changelogs and a dated out-of-cycle log (15).",
          "security": "OAuth 2.0 access tokens with scopes, revocable, with system users for servers and optional `appsecret_proof`. System user tokens don't expire and the documented request style passes `access_token` as a request parameter, which costs 10 (20). `ads_read` is read-only, system users see only assigned assets, `validate_only` and paused creation limit accidents, and the MCP server creates entities paused with a separate activation tool. The API itself has no approval step before a write that spends (14). Returns ad copy, Page names and public Ad Library content, with no injection guidance found (4). Ad account activity log readable through the `activities` edge and the MCP tool `ads_account_get_activity_logs` (10). security.txt valid to 7 November 2026, a bug bounty at bugbounty.meta.com and a published disclosure policy. No SOC 2 or ISO 27001 statement for this API was found in the pages read (13).",
          "transparency": "Editorial half only. Closed service with clear Platform Terms and Developer Policies, both last updated 3 February 2026. The SDKs use Meta's own platform licence, which isn't an OSI licence (15). The Platform Terms set out what a developer may do with Platform Data, deletion duties and Meta's audit rights. Meta's privacy policy and data processing terms render only with JavaScript and weren't read, so retention on Meta's side is unscored (10). A written 90-day minimum for version removal, expiry dates per version and dated deprecation notices such as Poll ads on 27 October 2026 (20). The terms name Meta Platforms Ireland Limited and Meta Platforms, Inc. as controllers for EEA and UK transfers. No subprocessor list or data location list was read (3)."
        },
        "sources": [
          {
            "what": "Marketing API overview (Markdown)",
            "url": "https://developers.facebook.com/documentation/ads-commerce/marketing-api/overview.md",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limiting",
            "url": "https://developers.facebook.com/documentation/ads-commerce/marketing-api/overview/rate-limiting",
            "seen": "2026-10-08"
          },
          {
            "what": "authorisation, access tiers and App Review",
            "url": "https://developers.facebook.com/documentation/ads-commerce/marketing-api/get-started/authorization",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication and token types",
            "url": "https://developers.facebook.com/documentation/ads-commerce/marketing-api/get-started/authentication",
            "seen": "2026-10-08"
          },
          {
            "what": "versioning policy",
            "url": "https://developers.facebook.com/documentation/ads-commerce/marketing-api/overview/versioning",
            "seen": "2026-10-08"
          },
          {
            "what": "Marketing API changelog and versions",
            "url": "https://developers.facebook.com/documentation/ads-commerce/marketing-api/marketing-api-changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "v26.0 changelog",
            "url": "https://developers.facebook.com/documentation/ads-commerce/marketing-api/marketing-api-changelog/version26.0",
            "seen": "2026-10-08"
          },
          {
            "what": "Graph API changelog with Marketing API versions",
            "url": "https://developers.facebook.com/docs/graph-api/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "2026 out-of-cycle changes",
            "url": "https://developers.facebook.com/documentation/ads-commerce/marketing-api/out-of-cycle-changes/occ-2026",
            "seen": "2026-10-08"
          },
          {
            "what": "error reference",
            "url": "https://developers.facebook.com/documentation/ads-commerce/marketing-api/error-reference",
            "seen": "2026-10-08"
          },
          {
            "what": "campaign reference with execution_options",
            "url": "https://developers.facebook.com/documentation/ads-commerce/marketing-api/reference/ad-account/campaigns",
            "seen": "2026-10-08"
          },
          {
            "what": "best practices, paging, batch and sandbox",
            "url": "https://developers.facebook.com/documentation/ads-commerce/marketing-api/best-practices",
            "seen": "2026-10-08"
          },
          {
            "what": "Graph API rate limiting headers",
            "url": "https://developers.facebook.com/docs/graph-api/overview/rate-limiting",
            "seen": "2026-10-08"
          },
          {
            "what": "Graph API error handling",
            "url": "https://developers.facebook.com/docs/graph-api/guides/error-handling",
            "seen": "2026-10-08"
          },
          {
            "what": "llms.txt with agent rules",
            "url": "https://developers.facebook.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "ads and commerce llms.txt index",
            "url": "https://developers.facebook.com/documentation/ads-commerce/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "Ads MCP server overview, setup and tools",
            "url": "https://developers.facebook.com/documentation/ads-commerce/ads-ai-connectors/ads-mcp-server/ads-mcp-server-overview",
            "seen": "2026-10-08"
          },
          {
            "what": "Ads MCP protected resource metadata",
            "url": "https://mcp.facebook.com/.well-known/oauth-protected-resource/ads",
            "seen": "2026-10-08"
          },
          {
            "what": "Ads AI connectors announcement",
            "url": "https://www.facebook.com/business/news/meta-ads-ai-connectors",
            "seen": "2026-10-08"
          },
          {
            "what": "Ads CLI setup",
            "url": "https://developers.facebook.com/documentation/ads-commerce/ads-ai-connectors/ads-cli/setup/get-started",
            "seen": "2026-10-08"
          },
          {
            "what": "Marketing API status history",
            "url": "https://metastatus.com/data/outages/marketing-api.history.json",
            "seen": "2026-10-08"
          },
          {
            "what": "Ads Manager status history",
            "url": "https://metastatus.com/data/outages/ads-manager.history.json",
            "seen": "2026-10-08"
          },
          {
            "what": "sandbox mode post",
            "url": "https://developers.facebook.com/ads/blog/post/2016/10/19/sandbox-ad-accounts/",
            "seen": "2026-10-08"
          },
          {
            "what": "system users overview",
            "url": "https://developers.facebook.com/docs/marketing-api/system-users/overview",
            "seen": "2026-10-08"
          },
          {
            "what": "Meta Platform Terms",
            "url": "https://developers.facebook.com/terms",
            "seen": "2026-10-08"
          },
          {
            "what": "Developer Policies",
            "url": "https://developers.facebook.com/devpolicy",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://www.facebook.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "API specs and Postman collection",
            "url": "https://github.com/facebook/facebook-business-sdk-codegen",
            "seen": "2026-10-08"
          },
          {
            "what": "Python SDK tags and issues",
            "url": "https://github.com/facebook/facebook-python-business-sdk",
            "seen": "2026-10-08"
          },
          {
            "what": "Python SDK on PyPI",
            "url": "https://pypi.org/project/facebook-business/",
            "seen": "2026-10-08"
          },
          {
            "what": "Node.js SDK on npm",
            "url": "https://registry.npmjs.org/facebook-nodejs-business-sdk/latest",
            "seen": "2026-10-08"
          },
          {
            "what": "Ads CLI on PyPI",
            "url": "https://pypi.org/project/meta-ads/",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=ads-mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "official Postman workspace (JavaScript only)",
            "url": "https://www.postman.com/meta/facebook-marketing-api/overview",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: Meta's privacy policy and data processing terms on facebook.com render only with JavaScript, so retention periods, subprocessors and data locations weren't read",
          "unchecked: the Ads MCP server's tool schemas and annotations, which need an access token to list. Tool names and descriptions come from the documentation",
          "unchecked: whether the Ads MCP server is still in open beta. The 29 April 2026 announcement says open beta and the documentation doesn't state a status",
          "unchecked: the official Postman workspace page renders only with JavaScript. The collection in facebook/facebook-business-sdk-codegen was read instead",
          "No statement that Marketing API calls are free was found. The absence of any price is the basis for the pricing field",
          "No idempotency key, Retry-After header or SLA was found in the reviewed documentation",
          "The Marketing API changelog and versioning pages name v25.0 as current while the Graph API changelog, the v26.0 changelog page and the SDKs show v26.0 from 29 July 2026",
          "Sandbox limits come from a 2017 post and the best practices page. Not tested, as we had no test account"
        ]
      },
      "negative": 0,
      "verdict": "Reporting, campaign, budget, audience and creative endpoints sit behind `ads_read` and `ads_management` scopes, with a `validate_only` option and sandbox ad accounts for checking a change before it spends. New apps are held to a score of 60 per ad account, with a 300-second block at the limit, and the documented requests pass the access token as a parameter.",
      "bestFor": "The direct route to Facebook, Instagram, Messenger, WhatsApp and Threads advertising for reporting, campaign and budget changes, audiences and creatives.",
      "strengths": [
        "`execution_options=validate_only` runs the validation rules on a campaign write without performing it, and sandbox ad accounts accept writes with no funding source",
        "`ads_read` is a read-only scope, and system users hold only the ad accounts, Pages and catalogues assigned to them",
        "llms.txt indexes and a Markdown copy of every guide and reference page, with a section of rules for AI agents",
        "Rate limits are published with numbers per tier, with usage headers that estimate the time until access returns",
        "Breaking changes ship only in numbered versions with at least 90 days' notice, and v26.0 followed on 29 July 2026"
      ],
      "weaknesses": [
        "Default Limited access allows a score of 60 per ad account (read 1, write 3) and blocks for 300 seconds at the limit",
        "The documented request style passes `access_token` as a request parameter, and system user tokens don't expire",
        "No idempotency key was found in the reviewed documentation, so a retried create can make a second campaign",
        "npm's `facebook-nodejs-business-sdk` is still 24.0.1 from 21 November 2025, while GitHub is at v26.0.2 and v24.0 expired on 6 October 2026",
        "The Marketing API changelog and versioning pages still name v25.0 as current, ten weeks after v26.0"
      ],
      "agentNotes": [
        "Put a version in every path, such as /v26.0/act_\u003cAD_ACCOUNT_ID\u003e/campaigns. Unversioned Marketing API calls fail",
        "Create campaigns, ad sets and ads with `status=PAUSED`, and send `execution_options=[\"validate_only\"]` first to test a write without making it",
        "Ask for `ads_read` alone when the task is reporting. `ads_management` can change budgets and activate spend",
        "Read `X-Business-Use-Case-Usage` and `X-Ad-Account-Usage` after each call and wait for `estimated_time_to_regain_access` on errors 17, 613 and 80004",
        "Change an ad set budget at most four times an hour and an account spending limit at most ten times a day"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 67.7
        }
      ],
      "editorialScores": {
        "ergonomics": 77,
        "maintenance": 74,
        "payments": 30,
        "reliability": 80,
        "schema": 76,
        "security": 61,
        "transparency": 41
      },
      "provenanceScore": 94
    },
    "connect": {
      "install": "pip install facebook_business",
      "http": "curl -G \\\n  -d \"access_token=\u003cACCESS_TOKEN\u003e\" \\\n  \"https://graph.facebook.com/v25.0/me/adaccounts\"",
      "claudeCode": "claude mcp add --transport http --client-id \u003cMETA_APP_ID\u003e meta-ads https://mcp.facebook.com/ads"
    },
    "letme": {
      "capability": "https://letme.dev/ads.reporting",
      "tool": "https://letme.dev/meta-marketing-api"
    },
    "sameCompany": [
      "whatsapp-cloud-api"
    ],
    "notable": [
      "Rate limits are scored per ad account. Limited access allows a score of 60 with a 300-second block, Full access 9,000 with a 60-second block, and a read costs 1 point and a write 3 (https://developers.facebook.com/documentation/ads-commerce/marketing-api/overview/rate-limiting)",
      "Full access to the Marketing API Access Tier needs 500 successful Marketing API calls in 15 days and an error rate under 15 per cent over the last 500 calls, a threshold lowered from 1,500 on 4 May 2026 (https://developers.facebook.com/documentation/ads-commerce/marketing-api/get-started/authorization)",
      "`execution_options` on campaign writes accepts `validate_only`, which runs the validation rules without performing the mutation (https://developers.facebook.com/documentation/ads-commerce/marketing-api/reference/ad-account/campaigns)",
      "Marketing API v26.0 was released on 29 July 2026. v24.0 expired on 6 October 2026, and versions run on a 90-day deprecation schedule with auto-upgrade for unaffected endpoints (https://developers.facebook.com/docs/graph-api/changelog)",
      "Meta hosts an official Ads MCP server at https://mcp.facebook.com/ads, announced in open beta on 29 April 2026, with 91 documented tools across reporting, ad management, catalogues, datasets, experiments and activity logs (https://developers.facebook.com/documentation/ads-commerce/ads-ai-connectors/ads-mcp-server/ads-mcp-server-overview)",
      "metastatus.com lists Marketing API with two components. Its history holds three incidents in 2026, the latest on 12 June for about three hours on ad creation and editing (https://metastatus.com/marketing-api)",
      "developers.facebook.com/llms.txt asks AI agents to name themselves and their model in the User-Agent header on Marketing API and Ads MCP requests (https://developers.facebook.com/llms.txt)"
    ],
    "area": "communication",
    "details": [
      {
        "label": "API",
        "value": "Graph API at https://graph.facebook.com/v26.0, with nodes and edges for ad accounts, campaigns, ad sets, ads, creatives, custom audiences and Ads Insights. The reference index lists 378 pages"
      },
      {
        "label": "Versions",
        "value": "v26.0 released 29 July 2026, v25.0 released 18 February 2026, v24.0 expired 6 October 2026. A new version about every four months, at least 90 days' overlap, and unversioned calls fail"
      },
      {
        "label": "Access",
        "value": "A Meta developer app with the Marketing API product. Limited access is automatic. Full access needs 500 successful calls in 15 days and an error rate under 15 per cent. Managing other businesses' ad accounts needs advanced access to `ads_read` or `ads_management` through App Review, and business verification may apply"
      },
      {
        "label": "Credentials",
        "value": "OAuth user access tokens (short-lived, or long-lived at about 60 days) and system user tokens that don't expire. Scopes `ads_read` and `ads_management`. `appsecret_proof` can be required on server calls"
      },
      {
        "label": "Rate limits",
        "value": "Per ad account score of 60 (Limited) or 9,000 (Full), decaying over 300 seconds. `ads_management` use case 300 or 100,000 calls an hour plus 40 per active ad. `ads_insights` 600 or 190,000 an hour plus 400 per active ad. 100 writes a second per app and ad account"
      },
      {
        "label": "Change limits",
        "value": "Ad set budget four changes an hour, account spending limit ten changes a day, 5,000 archived objects per ad account"
      },
      {
        "label": "Checking a change",
        "value": "`execution_options=validate_only` on writes, `status=PAUSED` on create, and sandbox ad accounts that take writes without a funding source but can't create ads or creatives"
      },
      {
        "label": "Errors",
        "value": "JSON error object with `code`, `error_subcode`, `error_user_title`, `error_user_msg` and `fbtrace_id`. Throttling codes 4, 17, 613 and 80000 to 80014"
      },
      {
        "label": "Paging and sizing",
        "value": "Cursor paging with `before`, `after` and `limit`, field selection with `fields`, `filtering` and `level` on Insights, asynchronous report runs, batch requests and ETags"
      },
      {
        "label": "SDKs",
        "value": "Meta Business SDK for Python, Node.js, PHP, Ruby and Java, generated from JSON specs in facebook/facebook-business-sdk-codegen. Python `facebook-business` 26.0.2 on PyPI (21 September 2026). npm `facebook-nodejs-business-sdk` 24.0.1 (21 November 2025)"
      },
      {
        "label": "MCP server",
        "value": "https://mcp.facebook.com/ads, Meta-hosted, OAuth through Facebook Login for Business or a Bearer user access token, 91 documented tools. Write tools create entities paused, and `ads_activate_entity` is a separate step. Open beta per the 29 April 2026 announcement"
      },
      {
        "label": "CLI",
        "value": "`meta-ads` 1.2.0 on PyPI (29 September 2026), Python 3.12 or later, system user token, JSON output and `--no-input` for scripts"
      },
      {
        "label": "Status",
        "value": "metastatus.com, with Ads Creation and Editing API and Ads Insights API as Marketing API components, and a JSON and RSS history"
      },
      {
        "label": "Terms",
        "value": "Meta Platform Terms and Developer Policies, both last updated 3 February 2026. Ads API access may drop to Development access after 30 days without use"
      }
    ],
    "provenance": {
      "legalEntity": "Meta Platforms, Inc.",
      "domain": "facebook.com",
      "domainRegistered": "1997-03-29",
      "endpointOnVendorDomain": true,
      "terms": "https://developers.facebook.com/terms",
      "privacy": "https://www.facebook.com/privacy/policy/",
      "statusPage": "https://metastatus.com",
      "changelog": "https://developers.facebook.com/documentation/ads-commerce/marketing-api/marketing-api-changelog",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The Meta Platform Terms (last updated 3 February 2026) name Meta Platforms, Inc. for UK data transfers and Meta Platforms Ireland Limited as controller of EEA data.",
        "The API answers at graph.facebook.com and the Ads MCP server at mcp.facebook.com, both facebook.com subdomains.",
        "www.facebook.com/.well-known/security.txt names a contact, the bug bounty policy at bugbounty.meta.com and a vulnerability disclosure policy, and expires on 7 November 2026. developers.facebook.com has no security.txt of its own.",
        "RDAP for facebook.com gives a registration date of 1997-03-29.",
        "The privacy policy and the data processing terms on facebook.com render only with JavaScript, so their text wasn't read.",
        "The Marketing API changelog page still shows v25.0 as the latest version. The Graph API changelog and the v26.0 changelog page show v26.0 from 29 July 2026."
      ],
      "score": 94,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Meta Platforms, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "facebook.com, registered 1997-03-29 (29 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "graph.facebook.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 4 of the 7 things a reader expects",
          "points": 7.4,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "published, but our reader couldn't read it",
          "points": 7,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "metastatus.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://developers.facebook.com/terms",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-02-03",
          "words": 7065,
          "points": 7.4,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated February 3, 2026",
              "says": "Last updated 2026-02-03"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": false
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": false
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "If you fail to comply with these Terms or any other applicable terms or policies, we may suspend or terminate your App or account, as described below."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "We reserve the right to amend these Terms and will use commercially reasonable efforts to provide you with prior notice of any material amendments.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "You will not sell, transfer, or sublicense Platform to anyone."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "We may suspend or end your App’s access to any Platform APIs, permissions, or features that your App has not used or accessed within a 28-day period with or without notice to you."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The licence Meta takes over content a developer supplies through the Platform, for operating or improving any Meta Product, continues after the developer stops using the Platform.",
              "quote": "This license remains in effect even if you stop using Platform."
            },
            {
              "date": "2026-10-08",
              "text": "Meta may make public statements about its relationship with the developer or the developer's use of the Platform.",
              "quote": "We can issue a press release or otherwise make public statements or disclosures describing our relationship with you or your use of Platform."
            },
            {
              "date": "2026-10-08",
              "text": "Meta may audit a developer's systems and records, and the developer pays Meta's reasonable audit costs if the audit finds non-compliance.",
              "quote": "vi. If an Audit reveals any non-compliance by you or your Service Provider(s) then you will reimburse us for all of our reasonable costs and expenses associated with conducting the Audit and any related follow-up Audits."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.facebook.com/privacy/policy/",
          "state": "unreadable",
          "reason": "robots.txt asks readers like ours not to fetch it",
          "readAt": "2026-10-08",
          "points": 7,
          "max": 10
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/meta-marketing-api.json",
    "live": {
      "slug": "meta-marketing-api",
      "probe": {
        "target": "https://graph.facebook.com",
        "method": "get",
        "lastAt": "2026-10-08T18:20:34.672748362Z",
        "lastOk": true,
        "lastStatus": 400,
        "lastMs": 125,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 131,
        "p95ms24h": 189,
        "samples24h": 33,
        "samples30d": 33,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 33,
            "ok": 33
          }
        ]
      },
      "vendorStatus": {
        "page": "https://metastatus.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T17:50:51.416434747Z"
      },
      "versions": [
        {
          "registry": "github",
          "name": "facebook/facebook-python-business-sdk",
          "version": "26.0.2",
          "released": "2026-09-21",
          "seenAt": "2026-10-08T16:20:32.10844618Z"
        },
        {
          "registry": "npm",
          "name": "facebook-nodejs-business-sdk",
          "version": "24.0.1",
          "seenAt": "2026-10-08T16:20:30.20877898Z"
        },
        {
          "registry": "pypi",
          "name": "facebook-business",
          "version": "26.0.2",
          "released": "2026-09-21",
          "seenAt": "2026-10-08T16:20:30.005647872Z"
        },
        {
          "registry": "pypi",
          "name": "meta-ads",
          "version": "1.2.0",
          "released": "2026-09-29",
          "seenAt": "2026-10-08T16:20:31.070786739Z"
        }
      ],
      "githubStars": 1605,
      "npmWeekly": 500852,
      "pypiWeekly": 1089043,
      "securityTxt": {
        "url": "https://facebook.com/.well-known/security.txt",
        "state": "valid",
        "expires": "2026-11-07T07:38:40-08:00",
        "checkedAt": "2026-10-08T15:38:40.384187776Z"
      },
      "pages": [
        {
          "url": "https://developers.facebook.com/documentation/ads-commerce/marketing-api/marketing-api-changelog",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:17:35.237810199Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "f3469d786112"
        },
        {
          "url": "https://developers.facebook.com/terms",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:17:39.648337351Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "b317e3abcc1f"
        }
      ],
      "updatedAt": "2026-10-08T18:20:34.672748362Z"
    }
  }
}
