{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "microsoft-advertising-api",
    "name": "Microsoft Advertising API",
    "vendor": "Microsoft",
    "vendorUrl": "https://learn.microsoft.com/en-us/advertising/guides/",
    "kind": "http-api",
    "category": "advertising",
    "summary": "Microsoft's API for Microsoft Advertising (formerly Bing Ads) search, shopping and audience campaigns. It covers campaign management, bulk upload and download, reporting, ad insight, billing and account management over REST and SOAP.",
    "url": "https://www.anchorterminal.com/tools/microsoft-advertising-api",
    "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-advertising-api.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-advertising-api.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-advertising-api.json",
    "repo": "https://github.com/BingAds/BingAds-Python-SDK",
    "license": "Proprietary service. The .NET, Java, Python and PHP SDKs are MIT",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://campaign.api.bingads.microsoft.com/CampaignManagement/v13",
    "packages": [
      {
        "registry": "pypi",
        "name": "msads"
      }
    ],
    "auth": "oauth",
    "authNotes": "OAuth 2.0 authorisation code grant through Microsoft Entra ID with the single scope `https://ads.microsoft.com/msads.manage`, or Google OAuth 2.0 with an `IdentityProvider` header. Every call also needs a developer token, which a Super Admin requests self-serve in the Microsoft Advertising developer settings. A person registers the app and grants consent in a browser, and multi-factor authentication is required. Access follows the user's role (Super Admin, Standard, Advertiser Campaign Manager, Viewer). No partner or sales approval was found in the reviewed documentation.",
    "pricing": "free",
    "pricingNotes": "No fee for API access was found in the reviewed documentation, and no statement that it is free either. Advertising spend is billed to the advertiser's account. The sandbox needs no payment method (sign-up has a Skip payment information step) and takes the shared developer token BBD37VB98, so testing can start without a contract or card (checked 2026-10-08).",
    "priceSummary": "Free",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the Microsoft Advertising guides or reference pages (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 7,
    "popularity": {
      "githubStars": 128,
      "npmWeekly": null,
      "pypiWeekly": 18920,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://learn.microsoft.com/en-us/advertising/guides/",
    "capabilities": [
      "ads.reporting",
      "ads.campaigns",
      "ads.budgets",
      "ads.audiences",
      "ads.creatives"
    ],
    "tags": [
      "hosted",
      "official",
      "oauth",
      "rest",
      "soap",
      "sandbox",
      "mcp",
      "python",
      "java",
      "dotnet",
      "php",
      "status-page"
    ],
    "lastRelease": "2026-09-29",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 60.3,
      "grade": "C",
      "agentReady": false,
      "rank": 360,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 4,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 63,
        "maintenance": 61,
        "payments": 30,
        "reliability": 60,
        "schema": 79,
        "security": 60,
        "transparency": 64
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 60,
          "points": 12,
          "reason": "Graded on the public API, read with the hosted lines. Platform health blog at status.ads.microsoft.com with areas for each API and dated posts (20). 40 posts from 20 July to 7 October 2026, 21 tagged Reporting API and all of those for delayed data, from three hours to six days. None reports the Campaign Management, Bulk, Customer Management or Ad Insight APIs down. Scored between minor and major for the frequency (15). Throttling is documented without numbers, and the Bulk and Reporting limits are called internal and subject to change (5). Wait 60 seconds after error 117 and up to 15 minutes after Bulk error 4204, with partial success on writes, but no idempotency key found (10). No SLA found (0). Version 13 is generally available. The MCP server is in open beta and isn't the surface graded (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 79,
          "points": 12.84,
          "reason": "A public WSDL for each of the six SOAP services, and REST URLs with JSON templates on every operation page. No public OpenAPI file was found, only a generated `openapi_client` inside the SDKs (15). learn.microsoft.com/llms.txt returns 404, but every page is returned as Markdown for `Accept: text/markdown` (10). Reference pages state each element's purpose, limits and required headers, with guides per service (15). Typed data objects and value sets, required elements marked (13). Request and response templates in SOAP and JSON with ValueHere placeholders, code examples in four languages and an operation error code list (11). Version 13 with dated monthly release notes (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 63,
          "points": 10.24,
          "reason": "Reports take a chosen column list and Get operations take IDs and `ReturnAdditionalFields`, but entity responses return whole objects (15). `PageInfo` paging and predicates on Search operations, report filters and scopes, and entity selection on bulk downloads (17). Numeric and symbolic error codes, a `TrackingId` on every response and `PartialErrors` per item, though SOAP faults arrive as HTTP 500 and some failures are an unmapped internal error (15). No idempotency key or validate-only mode found. Partial update on most campaign objects is the only retry aid (5). SDKs for .NET, Java, Python and PHP. Each call needs a token and up to three more headers (11)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 60,
          "points": 10.5,
          "reason": "OAuth 2.0 through Entra ID or Google with refresh tokens and required multi-factor authentication, but one scope, `msads.manage`, covers every read and write (22). Access is limited by user role, with a read-only Viewer role and per-account access, and the MCP server is read-only. Nothing asks for confirmation before a delete (13). Search term reports and ad text return content written by outsiders, and no injection guidance was found (3). A campaign change history report and a `TrackingId` per call (10). MSRC disclosure policy and bounty, though microsoft.com's security.txt expired on 23 September 2026. Certifications covering Microsoft Advertising weren't checked (12)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "No x402, MPP or L402 (0). No fee for API access was found, and none is stated as waived. Ad spend is set by auction, so no unit price is published (10). The sandbox needs no payment method and takes a shared developer token (20). A person signs up, registers an Entra app and grants consent in a browser (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 61,
          "points": 5.34,
          "reason": "SDK 13.0.30 published on 29 September 2026, and `msads` 13.0.30 reached PyPI on 30 September (30). Two dated release-note entries (August and September 2026) and two SDK releases in the last 90 days, short of three (0). The Python SDK repository shows 54 open issues, two from July 2026 with no reply, while release pull requests merge within days. Microsoft says it monitors the Q\u0026A forum, which we didn't check (10). Current official SDKs in four languages (15). Azure Pipelines CI is configured, its matrix names Python 3.7 while the docs require 3.8, and HISTORY.rst carries three entries dated 2027 (6)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 64,
          "points": 5.6,
          "note": "editorial 38, provenance 90",
          "reason": "Closed service with MIT SDKs. The Microsoft Advertising Agreement page renders only with JavaScript, so we couldn't read the terms (10). The Microsoft privacy statement applies, and the docs give reporting data retention periods, but no API-specific retention statement was found (12). SOAP's end date of 31 January 2027 is announced with migration guides, and the release notes carry a breaking-changes section (16). Sub-processors and data locations for Microsoft Advertising weren't checked (0)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Reports take a chosen column list and Get operations take IDs and `ReturnAdditionalFields`, but entity responses return whole objects (15). `PageInfo` paging and predicates on Search operations, report filters and scopes, and entity selection on bulk downloads (17). Numeric and symbolic error codes, a `TrackingId` on every response and `PartialErrors` per item, though SOAP faults arrive as HTTP 500 and some failures are an unmapped internal error (15). No idempotency key or validate-only mode found. Partial update on most campaign objects is the only retry aid (5). SDKs for .NET, Java, Python and PHP. Each call needs a token and up to three more headers (11).",
          "maintenance": "SDK 13.0.30 published on 29 September 2026, and `msads` 13.0.30 reached PyPI on 30 September (30). Two dated release-note entries (August and September 2026) and two SDK releases in the last 90 days, short of three (0). The Python SDK repository shows 54 open issues, two from July 2026 with no reply, while release pull requests merge within days. Microsoft says it monitors the Q\u0026A forum, which we didn't check (10). Current official SDKs in four languages (15). Azure Pipelines CI is configured, its matrix names Python 3.7 while the docs require 3.8, and HISTORY.rst carries three entries dated 2027 (6).",
          "payments": "No x402, MPP or L402 (0). No fee for API access was found, and none is stated as waived. Ad spend is set by auction, so no unit price is published (10). The sandbox needs no payment method and takes a shared developer token (20). A person signs up, registers an Entra app and grants consent in a browser (0).",
          "reliability": "Graded on the public API, read with the hosted lines. Platform health blog at status.ads.microsoft.com with areas for each API and dated posts (20). 40 posts from 20 July to 7 October 2026, 21 tagged Reporting API and all of those for delayed data, from three hours to six days. None reports the Campaign Management, Bulk, Customer Management or Ad Insight APIs down. Scored between minor and major for the frequency (15). Throttling is documented without numbers, and the Bulk and Reporting limits are called internal and subject to change (5). Wait 60 seconds after error 117 and up to 15 minutes after Bulk error 4204, with partial success on writes, but no idempotency key found (10). No SLA found (0). Version 13 is generally available. The MCP server is in open beta and isn't the surface graded (10).",
          "schema": "A public WSDL for each of the six SOAP services, and REST URLs with JSON templates on every operation page. No public OpenAPI file was found, only a generated `openapi_client` inside the SDKs (15). learn.microsoft.com/llms.txt returns 404, but every page is returned as Markdown for `Accept: text/markdown` (10). Reference pages state each element's purpose, limits and required headers, with guides per service (15). Typed data objects and value sets, required elements marked (13). Request and response templates in SOAP and JSON with ValueHere placeholders, code examples in four languages and an operation error code list (11). Version 13 with dated monthly release notes (15).",
          "security": "OAuth 2.0 through Entra ID or Google with refresh tokens and required multi-factor authentication, but one scope, `msads.manage`, covers every read and write (22). Access is limited by user role, with a read-only Viewer role and per-account access, and the MCP server is read-only. Nothing asks for confirmation before a delete (13). Search term reports and ad text return content written by outsiders, and no injection guidance was found (3). A campaign change history report and a `TrackingId` per call (10). MSRC disclosure policy and bounty, though microsoft.com's security.txt expired on 23 September 2026. Certifications covering Microsoft Advertising weren't checked (12).",
          "transparency": "Closed service with MIT SDKs. The Microsoft Advertising Agreement page renders only with JavaScript, so we couldn't read the terms (10). The Microsoft privacy statement applies, and the docs give reporting data retention periods, but no API-specific retention statement was found (12). SOAP's end date of 31 January 2027 is announced with migration guides, and the release notes carry a breaking-changes section (16). Sub-processors and data locations for Microsoft Advertising weren't checked (0)."
        },
        "sources": [
          {
            "what": "API overview and SOAP retirement notice",
            "url": "https://learn.microsoft.com/en-us/advertising/guides/?view=bingads-13",
            "seen": "2026-10-08"
          },
          {
            "what": "get started, developer token and headers",
            "url": "https://learn.microsoft.com/en-us/advertising/guides/get-started?view=bingads-13",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth with Entra ID and Google",
            "url": "https://learn.microsoft.com/en-us/advertising/guides/authentication-oauth?view=bingads-13",
            "seen": "2026-10-08"
          },
          {
            "what": "access and refresh tokens, scope",
            "url": "https://learn.microsoft.com/en-us/advertising/guides/authentication-oauth-get-tokens?view=bingads-13",
            "seen": "2026-10-08"
          },
          {
            "what": "sandbox",
            "url": "https://learn.microsoft.com/en-us/advertising/guides/sandbox?view=bingads-13",
            "seen": "2026-10-08"
          },
          {
            "what": "services protocol, partial success and throttling",
            "url": "https://learn.microsoft.com/en-us/advertising/guides/services-protocol?view=bingads-13",
            "seen": "2026-10-08"
          },
          {
            "what": "service errors and fault model",
            "url": "https://learn.microsoft.com/en-us/advertising/guides/handle-service-errors-exceptions?view=bingads-13",
            "seen": "2026-10-08"
          },
          {
            "what": "SOAP to REST migration",
            "url": "https://learn.microsoft.com/en-us/advertising/guides/migrate-to-rest?view=bingads-13",
            "seen": "2026-10-08"
          },
          {
            "what": "release notes",
            "url": "https://learn.microsoft.com/en-us/advertising/guides/release-notes?view=bingads-13",
            "seen": "2026-10-08"
          },
          {
            "what": "client libraries",
            "url": "https://learn.microsoft.com/en-us/advertising/guides/client-libraries?view=bingads-13",
            "seen": "2026-10-08"
          },
          {
            "what": "account hierarchy and user roles",
            "url": "https://learn.microsoft.com/en-us/advertising/guides/account-hierarchy-permissions?view=bingads-13",
            "seen": "2026-10-08"
          },
          {
            "what": "FAQ, reporting delay",
            "url": "https://learn.microsoft.com/en-us/advertising/guides/faq?view=bingads-13",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server setup",
            "url": "https://learn.microsoft.com/en-us/advertising/guides/mcp-setup?view=bingads-13",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server tools",
            "url": "https://learn.microsoft.com/en-us/advertising/guides/mcp-tools?view=bingads-13",
            "seen": "2026-10-08"
          },
          {
            "what": "AddCampaigns reference, REST URL and JSON",
            "url": "https://learn.microsoft.com/en-us/advertising/campaign-management-service/addcampaigns?view=bingads-13",
            "seen": "2026-10-08"
          },
          {
            "what": "web service addresses and WSDLs",
            "url": "https://learn.microsoft.com/en-us/advertising/guides/web-service-addresses?view=bingads-13",
            "seen": "2026-10-08"
          },
          {
            "what": "platform health blog",
            "url": "https://status.ads.microsoft.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "platform health posts since 10 July 2026",
            "url": "https://status.ads.microsoft.com/wp-json/wp/v2/posts?per_page=100\u0026after=2026-07-10T00:00:00",
            "seen": "2026-10-08"
          },
          {
            "what": "Python SDK repository, tags, licence, CI and history",
            "url": "https://github.com/BingAds/BingAds-Python-SDK",
            "seen": "2026-10-08"
          },
          {
            "what": "msads on PyPI",
            "url": "https://pypi.org/pypi/msads/json",
            "seen": "2026-10-08"
          },
          {
            "what": "msads download counts",
            "url": "https://pypistats.org/api/packages/msads/recent",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://www.microsoft.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "llms.txt (404)",
            "url": "https://learn.microsoft.com/llms.txt",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the Microsoft Advertising Agreement and any API-specific terms, because help.ads.microsoft.com renders only with JavaScript",
          "unchecked: sub-processors, data locations and certifications covering Microsoft Advertising",
          "unchecked: how quickly the Microsoft Q\u0026A forum answers, and GitHub stars and issue counts beyond the GitHub API figures",
          "Whether a production developer token is issued at once or after review. The docs describe a Request Token button and no approval step",
          "Whether Microsoft will publish an OpenAPI file for the REST API, and what the numeric call limits are",
          "Whether the MCP tools carry readOnlyHint annotations, and when the server leaves open beta",
          "The bulk upload row limit is given as 2.5 million on the sandbox page and 4 million on the services protocol page"
        ]
      },
      "negative": 0,
      "verdict": "Version 13 covers campaigns, budgets, audiences, ads and reports over REST with JSON, with a sandbox that needs no payment method and four official SDKs. Call-rate limits are unpublished, no public OpenAPI file or idempotency key was found, and one OAuth scope covers every operation. The SOAP interface retires on 31 January 2027.",
      "bestFor": "Agents that manage or report on Microsoft Advertising accounts, including Google Ads imports.",
      "strengths": [
        "Sandbox with its own endpoints, a shared developer token (BBD37VB98) and sign-up that skips payment information. Ads created there are never served",
        "REST with JSON on every operation page beside SOAP, and Learn returns any page as Markdown for `Accept: text/markdown`",
        "Monthly dated release notes, and SDK 13.0.30 for .NET, Java, Python and PHP published on 29 September 2026",
        "Viewer role is read-only, and a developer token adds no access beyond the signed-in user's role",
        "Official MCP server in open beta with seven read-only tools, filters, sorting and page tokens"
      ],
      "weaknesses": [
        "Call-rate limits carry no numbers. The docs describe a 60-second sliding window, and call the Bulk and Reporting limits internal and subject to change",
        "No public OpenAPI file found. The contract is six WSDLs for SOAP, which retires on 31 January 2027, and a generated client inside the SDKs",
        "One OAuth scope, `msads.manage`, covers reads and writes alike",
        "21 status posts tagged Reporting API between 20 July and 7 October 2026, all for delayed reporting data, one lasting six days",
        "No idempotency key or validate-only mode found, so a retried add can create a duplicate"
      ],
      "agentNotes": [
        "Build and test against the sandbox hosts (`*.api.sandbox.bingads.microsoft.com`) with developer token BBD37VB98. Sandbox and production credentials are separate",
        "Send `Authorization: Bearer \u003ctoken\u003e`, `DeveloperToken`, `CustomerId` and `CustomerAccountId` on REST calls. Use the account ID, never the eight-character account number",
        "Create campaigns with `Status` set to `Paused`, then read them back before activating. No validate-only mode was found",
        "On error 117 (CallRateExceeded) wait 60 seconds. On Bulk error 4204 wait up to 15 minutes",
        "Read `PartialErrors` on every add, update and delete. A call can succeed for some items and fail for others"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 60.3
        }
      ],
      "editorialScores": {
        "ergonomics": 63,
        "maintenance": 61,
        "payments": 30,
        "reliability": 60,
        "schema": 79,
        "security": 60,
        "transparency": 38
      },
      "provenanceScore": 90
    },
    "connect": {
      "install": "pip install msads",
      "http": "curl -X POST https://clientcenter.api.sandbox.bingads.microsoft.com/CustomerManagement/v13/User/Query \\\n  -H \"Authorization: Bearer $MSADS_ACCESS_TOKEN\" \\\n  -H \"DeveloperToken: BBD37VB98\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"UserId\": null}'",
      "config": {
        "servers": {
          "microsoft-ads-mcp": {
            "oauth": {
              "clientId": "\u003cclient-id\u003e"
            },
            "type": "http",
            "url": "https://partner.api.bingads.microsoft.com/ext/mcp/vnext?toolSetNames=OpenBeta"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/ads.reporting",
      "tool": "https://letme.dev/microsoft-advertising-api"
    },
    "sameCompany": [
      "azure-foundry-fine-tuning",
      "azure-ai-content-safety",
      "azure-speech-to-text",
      "azure-text-to-speech",
      "microsoft-agent-framework",
      "microsoft-execution-containers",
      "microsoft-entra-agent-id",
      "azure-key-vault",
      "azure-devops-mcp",
      "microsoft-learn-mcp",
      "playwright-mcp",
      "azure-mcp",
      "azure-translator",
      "microsoft-graph-calendar",
      "dynamics-365-sales",
      "microsoft-excel-graph",
      "outlook-mail-graph"
    ],
    "notable": [
      "SOAP is supported through 31 January 2027 and is scheduled for full deprecation on that date. REST is the base for future API work, with migration guides for each SDK (https://learn.microsoft.com/en-us/advertising/guides/migrate-to-rest?view=bingads-13)",
      "The sandbox has separate credentials and endpoints, a universal developer token (BBD37VB98), a 20,000-row bulk upload limit and test report data for nine report types. Microsoft says it may be down for maintenance without notice (https://learn.microsoft.com/en-us/advertising/guides/sandbox?view=bingads-13)",
      "Campaign Management and Ad Insight calls are throttled per customer over a 60-second sliding window with error 117. The Bulk and Reporting limits are described as internal and subject to change (https://learn.microsoft.com/en-us/advertising/guides/services-protocol?view=bingads-13)",
      "An official MCP server at https://partner.api.bingads.microsoft.com/ext/mcp/vnext?toolSetNames=OpenBeta has seven read-only tools (GetAccounts, GetCampaigns, GetAdGroups, GetAds, GetKeywords, GetAssetGroups, GetAudienceAssociations) and needs the user's own Entra app registration (https://learn.microsoft.com/en-us/advertising/guides/mcp-tools?view=bingads-13)",
      "The platform health blog lists 40 posts from 20 July to 7 October 2026, 21 of them tagged Reporting API and all of those for delayed data. None is tagged Campaign Management, Bulk, Customer Management or Ad Insight API (https://status.ads.microsoft.com/)",
      "Clicks take up to two hours and conversions up to three to reach reports (https://learn.microsoft.com/en-us/advertising/guides/faq?view=bingads-13)"
    ],
    "area": "communication",
    "details": [
      {
        "label": "Services",
        "value": "Campaign Management (189 operations listed), Bulk, Reporting, Ad Insight, Customer Management and Customer Billing, all version 13, each with production and sandbox hosts under api.bingads.microsoft.com"
      },
      {
        "label": "Protocols",
        "value": "REST with JSON (for example POST https://campaign.api.bingads.microsoft.com/CampaignManagement/v13/Campaigns) and SOAP 1.1 with a WSDL per service. SOAP retires on 31 January 2027"
      },
      {
        "label": "Credentials",
        "value": "OAuth 2.0 access token from Entra ID or Google, scope `https://ads.microsoft.com/msads.manage`, plus `DeveloperToken`, `CustomerId` and `CustomerAccountId` headers"
      },
      {
        "label": "Sandbox",
        "value": "sandbox.bingads.microsoft.com, universal developer token BBD37VB98, no payment method, ads never served, 20,000-row bulk uploads, one thread requested"
      },
      {
        "label": "Rate limits",
        "value": "No numbers published. Per-customer 60-second sliding window on Campaign Management and Ad Insight (error 117), Bulk error 4204 with a wait of up to 15 minutes, Reporting error 207 on too many concurrent reports"
      },
      {
        "label": "Batch limits",
        "value": "100 campaigns per AddCampaigns request. Bulk upload files up to 100 MB (the docs give both 2.5 million and 4 million rows)"
      },
      {
        "label": "Reporting delay",
        "value": "Up to two hours for clicks and three for conversions. Reports are submitted, polled and downloaded as files"
      },
      {
        "label": "Roles",
        "value": "Super Admin, Standard user, Advertiser Campaign Manager and Viewer (read-only)"
      },
      {
        "label": "SDKs",
        "value": "Microsoft.BingAds.SDK (.NET), Java, Python `msads` and PHP REST, all 13.0.30 from 29 September 2026, MIT"
      },
      {
        "label": "MCP server",
        "value": "Open beta, remote HTTP, seven read-only entity tools with filters, sorting, PageSize and NextPageToken. Documented for Copilot Studio, VS Code, ChatGPT and Claude"
      },
      {
        "label": "Status",
        "value": "status.ads.microsoft.com, a platform health blog with areas for each API and an RSS feed"
      }
    ],
    "provenance": {
      "legalEntity": "Microsoft Corporation",
      "domain": "microsoft.com",
      "domainRegistered": "1991-05-02",
      "domainNote": "The endpoints are on api.bingads.microsoft.com and the status page on status.ads.microsoft.com. microsoft.com publishes a security.txt, but it passed its Expires date on 2026-09-23.",
      "endpointOnVendorDomain": true,
      "terms": "https://about.ads.microsoft.com/en/resources/policies/microsoft-advertising-agreement",
      "privacy": "https://www.microsoft.com/en-us/privacy/privacystatement",
      "statusPage": "https://status.ads.microsoft.com",
      "changelog": "https://learn.microsoft.com/en-us/advertising/guides/release-notes?view=bingads-13",
      "securityTxt": "expired",
      "checked": "2026-10-08",
      "notes": [
        "The Microsoft Advertising Agreement link redirects to help.ads.microsoft.com, which renders only with JavaScript, so we couldn't read the terms.",
        "www.microsoft.com/.well-known/security.txt carries Expires: 2026-09-23T16:00:00.000Z and points to the MSRC researcher portal, bounty policy and coordinated disclosure policy.",
        "ads.microsoft.com/.well-known/security.txt redirects to a page-not-found error.",
        "RDAP for microsoft.com gives a registration date of 1991-05-02.",
        "The status page is a WordPress blog whose posts are readable through its RSS feed and JSON API."
      ],
      "score": 90,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Microsoft Corporation",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "microsoft.com, registered 1991-05-02 (35 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "campaign.api.bingads.microsoft.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "published, but our reader couldn't read it",
          "points": 7,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects, and has 1 clause that costs points",
          "points": 8,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.ads.microsoft.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "published but past its Expires date",
          "points": 5,
          "max": 10,
          "state": "part"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://about.ads.microsoft.com/en/resources/policies/microsoft-advertising-agreement",
          "state": "unreadable",
          "reason": "the page has 53 words of text without a browser, so the document is drawn by script or sits elsewhere",
          "readAt": "2026-10-08",
          "points": 7,
          "max": 10
        },
        {
          "kind": "privacy",
          "url": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-09-01",
          "words": 33580,
          "points": 8,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: September 2026",
              "says": "Last updated 2026-09-01"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "The data we collect depends on the context of your interactions with Microsoft and the choices you make, including your privacy settings and the products and features you use."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "When you delete an email or item from a mailbox in Outlook.com, the item generally goes into your Deleted Items folder where it remains for approximately 7 days unless you move it back to your inbox, you empty the folder, or the service empties the folder automatically, whichever comes first.",
              "says": "Names a period of 7 days"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Service providers that help us determine your device’s location."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "not use or share student personal data for advertising or similar commercial purposes, such as providing personalized advertising to students;"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "State Data Privacy Notice (including notice at collection details) and the Consumer Health Data Privacy Policy for additional information about your rights and the processing of your personal data."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have a privacy concern, complaint, or question for the Microsoft privacy team or Data Protection Officer, please visit our privacy support and requests page and click on “Contact the Microsoft privacy team or the Microsoft Data Protection Officer” menu.",
              "says": "Names a data protection officer"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "In such cases, we implement legal safeguards-such as standard contractual clauses approved by the European Commission – to help protect your rights and ensure your data remains protected.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "toKnow": [
            {
              "key": "training",
              "label": "Says it may use customer content to train or improve models, and no opt-out was found",
              "found": true,
              "quote": "As part of our efforts to improve and develop our products, we may use your data to develop and train our AI models.",
              "costsPoints": true
            },
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "We also disclose personal data for digital advertising purposes."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "For enterprise and developer products, the customer's agreement with Microsoft takes precedence over this privacy statement where the two conflict.",
              "quote": "In the event of a conflict between our privacy statement and the terms of any agreement(s) between a customer and Microsoft for Enterprise and Developer Products, the terms of those agreement(s) will control."
            },
            {
              "date": "2026-10-08",
              "text": "Prompts and related data sent to the consumer Microsoft Copilot are used to improve services and for relevant advertising.",
              "quote": "Microsoft Copilot also uses prompts and related data to provide and improve services, including relevant advertising."
            },
            {
              "date": "2026-10-08",
              "text": "Microsoft staff manually review some results of its automated systems, including AI, against the source data.",
              "quote": "For example, to build, train, and improve the accuracy of our automated systems – such as AI - we manually review some of the results against the underlying data."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-advertising-api.json",
    "live": {
      "slug": "microsoft-advertising-api",
      "probe": {
        "target": "https://campaign.api.bingads.microsoft.com/CampaignManagement/v13",
        "method": "get",
        "lastAt": "2026-10-08T17:36:40.235083497Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 422,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 439,
        "p95ms24h": 502,
        "samples24h": 25,
        "samples30d": 25,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 25,
            "ok": 25
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.ads.microsoft.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T15:36:56.109035859Z"
      },
      "versions": [
        {
          "registry": "github",
          "name": "BingAds/BingAds-Python-SDK",
          "version": "v13.0.30",
          "released": "2026-09-29",
          "seenAt": "2026-10-08T16:20:36.673165866Z"
        },
        {
          "registry": "pypi",
          "name": "msads",
          "version": "13.0.30",
          "released": "2026-09-30",
          "seenAt": "2026-10-08T16:20:34.683272294Z"
        }
      ],
      "githubStars": 128,
      "pypiWeekly": 18920,
      "securityTxt": {
        "url": "https://microsoft.com/.well-known/security.txt",
        "state": "expired",
        "expires": "2026-09-23T16:00:00.000Z",
        "checkedAt": "2026-10-08T15:39:08.216544687Z"
      },
      "updatedAt": "2026-10-08T17:36:40.235083497Z"
    }
  }
}
