Meta Marketing API
by Meta Platforms, Inc. HTTP API in Advertising & campaign operations
Hosted
Meta Platforms, Inc. · facebook.com since 1997 · status page · who's behind it
Meta's Marketing API creates and manages campaigns, ad sets, ads, creatives and audiences across Facebook, Instagram, Messenger and WhatsApp, and reports performance through Ads Insights. It is a versioned Graph API with OAuth access tokens.
Good for The direct route to Facebook, Instagram, Messenger, WhatsApp and Threads advertising for reporting, campaign and budget changes, audiences and creatives.
Is this your product? Claim this listing or verify it
Assessment. Reporting, campaign, budget, audience and creative endpoints sit behind ads_read and ads_management scopes, with a validate_only option and sandbox ad accounts for checking a change before it spends. New apps are held to a score of 60 per ad account, with a 300-second block at the limit, and the documented requests pass the access token as a parameter.
Facts
- Transport
- HTTP
- Endpoint
https://graph.facebook.com- Auth
- OAuth
- Pricing
- Free · Free
- x402
- No
- Licence
- Proprietary service under the Meta Platform Terms. The Business SDKs and the codegen specs on GitHub carry Meta's own platform licence, which allows use only with Meta's APIs
- Packages
pypifacebook-businessnpmfacebook-nodejs-business-sdkpypimeta-ads- llms.txt
- published
- Last release
- GitHub stars
- 1.6k
- npm / week
- 501k
- PyPI / week
- 1.1M
- API
- Graph API at https://graph.facebook.com/v26.0, with nodes and edges for ad accounts, campaigns, ad sets, ads, creatives, custom audiences and Ads Insights. The reference index lists 378 pages
- Versions
- v26.0 released 29 July 2026, v25.0 released 18 February 2026, v24.0 expired 6 October 2026. A new version about every four months, at least 90 days' overlap, and unversioned calls fail
- Access
- A Meta developer app with the Marketing API product. Limited access is automatic. Full access needs 500 successful calls in 15 days and an error rate under 15 per cent. Managing other businesses' ad accounts needs advanced access to
ads_readorads_managementthrough App Review, and business verification may apply - Credentials
- OAuth user access tokens (short-lived, or long-lived at about 60 days) and system user tokens that don't expire. Scopes
ads_readandads_management.appsecret_proofcan be required on server calls - Rate limits
- Per ad account score of 60 (Limited) or 9,000 (Full), decaying over 300 seconds.
ads_managementuse case 300 or 100,000 calls an hour plus 40 per active ad.ads_insights600 or 190,000 an hour plus 400 per active ad. 100 writes a second per app and ad account - Change limits
- Ad set budget four changes an hour, account spending limit ten changes a day, 5,000 archived objects per ad account
- Checking a change
execution_options=validate_onlyon writes,status=PAUSEDon create, and sandbox ad accounts that take writes without a funding source but can't create ads or creatives- Errors
- JSON error object with
code,error_subcode,error_user_title,error_user_msgandfbtrace_id. Throttling codes 4, 17, 613 and 80000 to 80014 - Paging and sizing
- Cursor paging with
before,afterandlimit, field selection withfields,filteringandlevelon Insights, asynchronous report runs, batch requests and ETags - SDKs
- Meta Business SDK for Python, Node.js, PHP, Ruby and Java, generated from JSON specs in facebook/facebook-business-sdk-codegen. Python
facebook-business26.0.2 on PyPI (21 September 2026). npmfacebook-nodejs-business-sdk24.0.1 (21 November 2025) - MCP server
- https://mcp.facebook.com/ads, Meta-hosted, OAuth through Facebook Login for Business or a Bearer user access token, 91 documented tools. Write tools create entities paused, and
ads_activate_entityis a separate step. Open beta per the 29 April 2026 announcement - CLI
meta-ads1.2.0 on PyPI (29 September 2026), Python 3.12 or later, system user token, JSON output and--no-inputfor scripts- Status
- metastatus.com, with Ads Creation and Editing API and Ads Insights API as Marketing API components, and a JSON and RSS history
- Terms
- Meta Platform Terms and Developer Policies, both last updated 3 February 2026. Ads API access may drop to Development access after 30 days without use
- Capabilities
- ads.reporting ads.campaigns ads.budgets ads.audiences ads.creatives
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
execution_options=validate_onlyruns the validation rules on a campaign write without performing it, and sandbox ad accounts accept writes with no funding sourceads_readis a read-only scope, and system users hold only the ad accounts, Pages and catalogues assigned to them- llms.txt indexes and a Markdown copy of every guide and reference page, with a section of rules for AI agents
- Rate limits are published with numbers per tier, with usage headers that estimate the time until access returns
- Breaking changes ship only in numbered versions with at least 90 days' notice, and v26.0 followed on 29 July 2026
Weaknesses
- Default Limited access allows a score of 60 per ad account (read 1, write 3) and blocks for 300 seconds at the limit
- The documented request style passes
access_tokenas a request parameter, and system user tokens don't expire - No idempotency key was found in the reviewed documentation, so a retried create can make a second campaign
- npm's
facebook-nodejs-business-sdkis still 24.0.1 from 21 November 2025, while GitHub is at v26.0.2 and v24.0 expired on 6 October 2026 - The Marketing API changelog and versioning pages still name v25.0 as current, ten weeks after v26.0
Before you call it notes for agents
- Put a version in every path, such as /v26.0/act_<AD_ACCOUNT_ID>/campaigns. Unversioned Marketing API calls fail
- Create campaigns, ad sets and ads with
status=PAUSED, and sendexecution_options=["validate_only"]first to test a write without making it - Ask for
ads_readalone when the task is reporting.ads_managementcan change budgets and activate spend - Read
X-Business-Use-Case-UsageandX-Ad-Account-Usageafter each call and wait forestimated_time_to_regain_accesson errors 17, 613 and 80004 - Change an ad set budget at most four times an hour and an account spending limit at most ten times a day
Who's behind it provenance 94/100
- Legal entity namedMeta Platforms, Inc.20/20
- Domain agefacebook.com, registered 1997-03-29 (29 years)15/15
- Endpoint on the vendor's domaingraph.facebook.com15/15
- Terms of serviceread, states 4 of the 7 things a reader expects7.4/10
- Privacy policypublished, but our reader couldn't read it7/10
- Status pagemetastatus.com10/10
- Changelogpublished10/10
- security.txtvalid10/10
Terms and privacy, as read
Terms of service dated 2026-02-03, states 4 of 7, 1 to know
TL;DR Dated 2026-02-03. States 4 of the 7 things a reader expects, and we didn't find the governing law, a liability limit or a service level. To know before relying on it, cut-off without notice or for any reason.
Says access can be ended without notice or for any reason
We may suspend or end your App’s access to any Platform APIs, permissions, or features that your App has not used or accessed within a 28-day period with or without notice to you.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Gives the date it was last updated Last updated 2026-02-03
Last updated February 3, 2026
Without a date nobody can tell which version they agreed to.
Names the governing law or courts
Not found in the text.
Says where a dispute would be heard and under whose law.
States a limit on its liability
Not found in the text.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
If you fail to comply with these Terms or any other applicable terms or policies, we may suspend or terminate your App or account, as described below.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Says it gives notice of a change
We reserve the right to amend these Terms and will use commercially reasonable efforts to provide you with prior notice of any material amendments.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
You will not sell, transfer, or sublicense Platform to anyone.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
The licence Meta takes over content a developer supplies through the Platform, for operating or improving any Meta Product, continues after the developer stops using the Platform.
This license remains in effect even if you stop using Platform.
Noted by a second reader on 2026-10-08.
Meta may make public statements about its relationship with the developer or the developer's use of the Platform.
We can issue a press release or otherwise make public statements or disclosures describing our relationship with you or your use of Platform.
Noted by a second reader on 2026-10-08.
Meta may audit a developer's systems and records, and the developer pays Meta's reasonable audit costs if the audit finds non-compliance.
vi. If an Audit reveals any non-compliance by you or your Service Provider(s) then you will reimburse us for all of our reasonable costs and expenses associated with conducting the Audit and any related follow-up Audits.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 7,065 words
Privacy policy our reader couldn't read it
TL;DR Our reader couldn't read it, so nothing here is checked. The document is published and scores 7 of 10 until we can.
robots.txt asks readers like ours not to fetch it.
The document · read 2026-10-08
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The Meta Platform Terms (last updated 3 February 2026) name Meta Platforms, Inc. for UK data transfers and Meta Platforms Ireland Limited as controller of EEA data.
The API answers at graph.facebook.com and the Ads MCP server at mcp.facebook.com, both facebook.com subdomains.
www.facebook.com/.well-known/security.txt names a contact, the bug bounty policy at bugbounty.meta.com and a vulnerability disclosure policy, and expires on 7 November 2026. developers.facebook.com has no security.txt of its own.
RDAP for facebook.com gives a registration date of 1997-03-29.
The privacy policy and the data processing terms on facebook.com render only with JavaScript, so their text wasn't read.
The Marketing API changelog page still shows v25.0 as the latest version. The Graph API changelog and the v26.0 changelog page show v26.0 from 29 July 2026.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 16:44 UTC
Probed every five minutes at https://graph.facebook.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- Vendor status page unknown, no machine-readable status found · 1 hour ago
- github
facebook/facebook-python-business-sdk26.0.2, released 2026-09-21 - npm
facebook-nodejs-business-sdk24.0.1 - pypi
facebook-business26.0.2, released 2026-09-21 - pypi
meta-ads1.2.0, released 2026-09-29 - GitHub stars 1.6k
- npm downloads a week 501k
- PyPI downloads a week 1.1M
- security.txt valid, expires 2026-11-07T07:38:40-08:00 · 1 hour ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/meta-marketing-api.json
Notable
- Rate limits are scored per ad account. Limited access allows a score of 60 with a 300-second block, Full access 9,000 with a 60-second block, and a read costs 1 point and a write 3 source
- Full access to the Marketing API Access Tier needs 500 successful Marketing API calls in 15 days and an error rate under 15 per cent over the last 500 calls, a threshold lowered from 1,500 on 4 May 2026 source
execution_optionson campaign writes acceptsvalidate_only, which runs the validation rules without performing the mutation source- Marketing API v26.0 was released on 29 July 2026. v24.0 expired on 6 October 2026, and versions run on a 90-day deprecation schedule with auto-upgrade for unaffected endpoints source
- Meta hosts an official Ads MCP server at https://mcp.facebook.com/ads, announced in open beta on 29 April 2026, with 91 documented tools across reporting, ad management, catalogues, datasets, experiments and activity logs source
- metastatus.com lists Marketing API with two components. Its history holds three incidents in 2026, the latest on 12 June for about three hours on ad creation and editing source
- developers.facebook.com/llms.txt asks AI agents to name themselves and their model in the User-Agent header on Marketing API and Ads MCP requests source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 16.0 | |
Graded on the public Marketing API. metastatus.com lists Marketing API with two components, Ads Creation and Editing API and Ads Insights API, and an incident history (20). Neither Marketing API nor Graph API shows an incident in the 90 days to 8 October 2026. The last was on 12 June 2026, about three hours on creation and editing. Ads Manager's Ads Delivery component had four incidents in the window (16 and 19 July, 21 August, 22 September), two marked high disruption for over two hours each, so we departed from the full 30 (25). Rate limits are published with numbers per tier and use case (15). The docs ask for exponential backoff and name usage headers with estimated_time_to_regain_access, but no idempotency key for writes was found (10). No SLA found (0). The API is generally available, while the Ads MCP server was announced in open beta (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 12.3 | |
| No OpenAPI document. Meta publishes its own JSON specs for 1,105 objects in facebook/facebook-business-sdk-codegen, refreshed on 17 September 2026, and a 47-request Postman collection (15). llms.txt indexes and a Markdown copy of each guide and reference page, with a section of rules for AI agents (10). Reference pages describe each field and guides cover when to use asynchronous reports, batches and sandbox mode, with little on when not to use an endpoint (13). Parameters carry types, enums, defaults and required marks, though targeting and creative specs travel as JSON strings in form fields (11). Request examples per endpoint in several languages and an error reference with codes and subcodes. Examples still use v25.0, and one Insights example uses v2.7 (12). Numbered versions, per-version changelogs and a dated out-of-cycle log (15). | |||
| Agent ergonomics | 13%16.2 | 12.5 | |
Responses can be sized with fields, limit, Insights level and summaries. The Ads MCP server is not what we graded, and its 91 documented tools would score lower here (20). Cursor paging, filtering, date presets, breakdowns, asynchronous report runs, batch requests and ETags (20). Errors carry code, error_subcode, error_user_title, error_user_msg and fbtrace_id, and the error reference maps codes to causes (17). No idempotency key was found in the reviewed documentation. execution_options=validate_only tests a write without performing it, and objects can be created paused (8). Business SDKs in five languages, but npm's Node.js package is two versions behind, every path needs a version, and campaign creation needs special_ad_categories as well as name, objective and status (12). | |||
| Security & auth | 14%17.5 | 10.7 | |
OAuth 2.0 access tokens with scopes, revocable, with system users for servers and optional appsecret_proof. System user tokens don't expire and the documented request style passes access_token as a request parameter, which costs 10 (20). ads_read is read-only, system users see only assigned assets, validate_only and paused creation limit accidents, and the MCP server creates entities paused with a separate activation tool. The API itself has no approval step before a write that spends (14). Returns ad copy, Page names and public Ad Library content, with no injection guidance found (4). Ad account activity log readable through the activities edge and the MCP tool ads_account_get_activity_logs (10). security.txt valid to 7 November 2026, a bug bounty at bugbounty.meta.com and a published disclosure policy. No SOC 2 or ISO 27001 statement for this API was found in the pages read (13). | |||
| Payments & pricing | 10%12.5 | 3.8 | |
| No x402, MPP or L402 (0). No charge for API calls was found and no price list exists for the API. Tiers differ by rate limit and ad spend is billed to the ad account, so we scored the middle value (10). Limited access is automatic with no card, and a sandbox ad account needs no funding source (20). A person has to create a Meta account and a developer app in a browser, and App Review applies to managing other businesses' accounts (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 6.5 | |
Python SDK 26.0.2 on PyPI on 21 September 2026 and the meta-ads CLI 1.2.0 on 29 September (30). Marketing API v26.0 on 29 July, and SDK tags 25.0.3, 26.0.0, 26.0.1 and 26.0.2 between 17 July and 17 September (20). Closed service with a dated changelog, a support page and a developer community group. The Marketing API changelog and versioning pages still name v25.0 as current, the out-of-cycle log ends on 28 June 2026, and the 30 newest open issues on the Python SDK repository are spam with no replies (7). Official SDKs in five languages, current on PyPI at 26.0.2, while npm's latest is 24.0.1 from 21 November 2025 (10). CI and publish workflows in the SDK repositories, with generated code and a changelog that stops at v25.0.3 (7). | |||
| Transparency & trusteditorial 41, provenance 94 | 7%8.8 | 6.0 | |
| Editorial half only. Closed service with clear Platform Terms and Developer Policies, both last updated 3 February 2026. The SDKs use Meta's own platform licence, which isn't an OSI licence (15). The Platform Terms set out what a developer may do with Platform Data, deletion duties and Meta's audit rights. Meta's privacy policy and data processing terms render only with JavaScript and weren't read, so retention on Meta's side is unscored (10). A written 90-day minimum for version removal, expiry dates per version and dated deprecation notices such as Poll ads on 27 October 2026 (20). The terms name Meta Platforms Ireland Limited and Meta Platforms, Inc. as controllers for EEA and UK transfers. No subprocessor list or data location list was read (3). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 67.7 · B | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 17 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Meta Marketing API, or have the agent fetch /fixes/meta-marketing-api.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Meta Marketing API From Anchor Terminal's listing at https://www.anchorterminal.com/tools/meta-marketing-api, the October 2026 research run, assessed 8 October 2026. Grade B, 67.7 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Meta Marketing API: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Payments & pricing, 30 out of 100, up to 8.8 more on the total Why it scored 30: No x402, MPP or L402 (0). No charge for API calls was found and no price list exists for the API. Tiers differ by rate limit and ad spend is billed to the ad account, so we scored the middle value (10). Limited access is automatic with no card, and a sandbox ad account needs no funding source (20). A person has to create a Meta account and a developer app in a browser, and App Review applies to managing other businesses' accounts (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 2. Security & auth, 61 out of 100, up to 6.8 more on the total Why it scored 61: OAuth 2.0 access tokens with scopes, revocable, with system users for servers and optional `appsecret_proof`. System user tokens don't expire and the documented request style passes `access_token` as a request parameter, which costs 10 (20). `ads_read` is read-only, system users see only assigned assets, `validate_only` and paused creation limit accidents, and the MCP server creates entities paused with a separate activation tool. The API itself has no approval step before a write that spends (14). Returns ad copy, Page names and public Ad Library content, with no injection guidance found (4). Ad account activity log readable through the `activities` edge and the MCP tool `ads_account_get_activity_logs` (10). security.txt valid to 7 November 2026, a bug bounty at bugbounty.meta.com and a published disclosure policy. No SOC 2 or ISO 27001 statement for this API was found in the pages read (13). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 3. Reliability, 80 out of 100, up to 4 more on the total Why it scored 80: Graded on the public Marketing API. metastatus.com lists Marketing API with two components, Ads Creation and Editing API and Ads Insights API, and an incident history (20). Neither Marketing API nor Graph API shows an incident in the 90 days to 8 October 2026. The last was on 12 June 2026, about three hours on creation and editing. Ads Manager's Ads Delivery component had four incidents in the window (16 and 19 July, 21 August, 22 September), two marked high disruption for over two hours each, so we departed from the full 30 (25). Rate limits are published with numbers per tier and use case (15). The docs ask for exponential backoff and name usage headers with `estimated_time_to_regain_access`, but no idempotency key for writes was found (10). No SLA found (0). The API is generally available, while the Ads MCP server was announced in open beta (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 4. Schema & documentation, 76 out of 100, up to 3.9 more on the total Why it scored 76: No OpenAPI document. Meta publishes its own JSON specs for 1,105 objects in facebook/facebook-business-sdk-codegen, refreshed on 17 September 2026, and a 47-request Postman collection (15). llms.txt indexes and a Markdown copy of each guide and reference page, with a section of rules for AI agents (10). Reference pages describe each field and guides cover when to use asynchronous reports, batches and sandbox mode, with little on when not to use an endpoint (13). Parameters carry types, enums, defaults and required marks, though targeting and creative specs travel as JSON strings in form fields (11). Request examples per endpoint in several languages and an error reference with codes and subcodes. Examples still use v25.0, and one Insights example uses v2.7 (12). Numbered versions, per-version changelogs and a dated out-of-cycle log (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 5. Agent ergonomics, 77 out of 100, up to 3.7 more on the total Why it scored 77: Responses can be sized with `fields`, `limit`, Insights `level` and summaries. The Ads MCP server is not what we graded, and its 91 documented tools would score lower here (20). Cursor paging, `filtering`, date presets, breakdowns, asynchronous report runs, batch requests and ETags (20). Errors carry `code`, `error_subcode`, `error_user_title`, `error_user_msg` and `fbtrace_id`, and the error reference maps codes to causes (17). No idempotency key was found in the reviewed documentation. `execution_options=validate_only` tests a write without performing it, and objects can be created paused (8). Business SDKs in five languages, but npm's Node.js package is two versions behind, every path needs a version, and campaign creation needs `special_ad_categories` as well as name, objective and status (12). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 6. Transparency & trust, 68 out of 100, up to 2.8 more on the total Made of editorial 41, provenance 94. Why it scored 68: Editorial half only. Closed service with clear Platform Terms and Developer Policies, both last updated 3 February 2026. The SDKs use Meta's own platform licence, which isn't an OSI licence (15). The Platform Terms set out what a developer may do with Platform Data, deletion duties and Meta's audit rights. Meta's privacy policy and data processing terms render only with JavaScript and weren't read, so retention on Meta's side is unscored (10). A written 90-day minimum for version removal, expiry dates per version and dated deprecation notices such as Poll ads on 27 October 2026 (20). The terms name Meta Platforms Ireland Limited and Meta Platforms, Inc. as controllers for EEA and UK transfers. No subprocessor list or data location list was read (3). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Terms of service: read, states 4 of the 7 things a reader expects (7.4 of 10) - Privacy policy: published, but our reader couldn't read it (7 of 10) ## 7. Maintenance & community, 74 out of 100, up to 2.3 more on the total Why it scored 74: Python SDK 26.0.2 on PyPI on 21 September 2026 and the `meta-ads` CLI 1.2.0 on 29 September (30). Marketing API v26.0 on 29 July, and SDK tags 25.0.3, 26.0.0, 26.0.1 and 26.0.2 between 17 July and 17 September (20). Closed service with a dated changelog, a support page and a developer community group. The Marketing API changelog and versioning pages still name v25.0 as current, the out-of-cycle log ends on 28 June 2026, and the 30 newest open issues on the Python SDK repository are spam with no replies (7). Official SDKs in five languages, current on PyPI at 26.0.2, while npm's latest is 24.0.1 from 21 November 2025 (10). CI and publish workflows in the SDK repositories, with generated code and a changelog that stops at v25.0.3 (7). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: Meta's privacy policy and data processing terms on facebook.com render only with JavaScript, so retention periods, subprocessors and data locations weren't read - unchecked: the Ads MCP server's tool schemas and annotations, which need an access token to list. Tool names and descriptions come from the documentation - unchecked: whether the Ads MCP server is still in open beta. The 29 April 2026 announcement says open beta and the documentation doesn't state a status - unchecked: the official Postman workspace page renders only with JavaScript. The collection in facebook/facebook-business-sdk-codegen was read instead - No statement that Marketing API calls are free was found. The absence of any price is the basis for the pricing field - No idempotency key, Retry-After header or SLA was found in the reviewed documentation - The Marketing API changelog and versioning pages name v25.0 as current while the Graph API changelog, the v26.0 changelog page and the SDKs show v26.0 from 29 July 2026 - Sandbox limits come from a 2017 post and the best practices page. Not tested, as we had no test account ## Weaknesses - Default Limited access allows a score of 60 per ad account (read 1, write 3) and blocks for 300 seconds at the limit - The documented request style passes `access_token` as a request parameter, and system user tokens don't expire - No idempotency key was found in the reviewed documentation, so a retried create can make a second campaign - npm's `facebook-nodejs-business-sdk` is still 24.0.1 from 21 November 2025, while GitHub is at v26.0.2 and v24.0 expired on 6 October 2026 - The Marketing API changelog and versioning pages still name v25.0 as current, ten weeks after v26.0 ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Put a version in every path, such as /v26.0/act_<AD_ACCOUNT_ID>/campaigns. Unversioned Marketing API calls fail - Create campaigns, ad sets and ads with `status=PAUSED`, and send `execution_options=["validate_only"]` first to test a write without making it - Ask for `ads_read` alone when the task is reporting. `ads_management` can change budgets and activate spend - Read `X-Business-Use-Case-Usage` and `X-Ad-Account-Usage` after each call and wait for `estimated_time_to_regain_access` on errors 17, 613 and 80004 - Change an ad set budget at most four times an hour and an account spending limit at most ten times a day ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: Meta's privacy policy and data processing terms on facebook.com render only with JavaScript, so retention periods, subprocessors and data locations weren't read
- unchecked: the Ads MCP server's tool schemas and annotations, which need an access token to list. Tool names and descriptions come from the documentation
- unchecked: whether the Ads MCP server is still in open beta. The 29 April 2026 announcement says open beta and the documentation doesn't state a status
- unchecked: the official Postman workspace page renders only with JavaScript. The collection in facebook/facebook-business-sdk-codegen was read instead
- No statement that Marketing API calls are free was found. The absence of any price is the basis for the pricing field
- No idempotency key, Retry-After header or SLA was found in the reviewed documentation
- The Marketing API changelog and versioning pages name v25.0 as current while the Graph API changelog, the v26.0 changelog page and the SDKs show v26.0 from 29 July 2026
- Sandbox limits come from a 2017 post and the best practices page. Not tested, as we had no test account
Sources 34
- Marketing API overview (Markdown) developers.facebook.com · seen 2026-10-08
- rate limiting developers.facebook.com · seen 2026-10-08
- authorisation, access tiers and App Review developers.facebook.com · seen 2026-10-08
- authentication and token types developers.facebook.com · seen 2026-10-08
- versioning policy developers.facebook.com · seen 2026-10-08
- Marketing API changelog and versions developers.facebook.com · seen 2026-10-08
- v26.0 changelog developers.facebook.com · seen 2026-10-08
- Graph API changelog with Marketing API versions developers.facebook.com · seen 2026-10-08
- 2026 out-of-cycle changes developers.facebook.com · seen 2026-10-08
- error reference developers.facebook.com · seen 2026-10-08
- campaign reference with execution_options developers.facebook.com · seen 2026-10-08
- best practices, paging, batch and sandbox developers.facebook.com · seen 2026-10-08
- Graph API rate limiting headers developers.facebook.com · seen 2026-10-08
- Graph API error handling developers.facebook.com · seen 2026-10-08
- llms.txt with agent rules developers.facebook.com · seen 2026-10-08
- ads and commerce llms.txt index developers.facebook.com · seen 2026-10-08
- Ads MCP server overview, setup and tools developers.facebook.com · seen 2026-10-08
- Ads MCP protected resource metadata mcp.facebook.com · seen 2026-10-08
- Ads AI connectors announcement facebook.com · seen 2026-10-08
- Ads CLI setup developers.facebook.com · seen 2026-10-08
- Marketing API status history metastatus.com · seen 2026-10-08
- Ads Manager status history metastatus.com · seen 2026-10-08
- sandbox mode post developers.facebook.com · seen 2026-10-08
- system users overview developers.facebook.com · seen 2026-10-08
- Meta Platform Terms developers.facebook.com · seen 2026-10-08
- Developer Policies developers.facebook.com · seen 2026-10-08
- security.txt facebook.com · seen 2026-10-08
- API specs and Postman collection github.com · seen 2026-10-08
- Python SDK tags and issues github.com · seen 2026-10-08
- Python SDK on PyPI pypi.org · seen 2026-10-08
- Node.js SDK on npm registry.npmjs.org · seen 2026-10-08
- Ads CLI on PyPI pypi.org · seen 2026-10-08
- official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-08
- official Postman workspace (JavaScript only) postman.com · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Free Free No charge for API calls was found in the Platform Terms or the Marketing API documentation. Access tiers differ by rate limit, and ad spend is billed to the ad account. An agent can start without a contract. Limited access is automatic when the Marketing API product is added to an app, and a sandbox ad account takes read and write calls with no funding source (checked 2026-10-08).
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/meta-marketing-api.xml, or this listing's score history at history.json.
Connect
Install
pip install facebook_business
First request
curl -G \
-d "access_token=<ACCESS_TOKEN>" \
"https://graph.facebook.com/v25.0/me/adaccounts"
Claude Code
claude mcp add --transport http --client-id <META_APP_ID> meta-ads https://mcp.facebook.com/ads
Through letme picks today, calling later
GET https://letme.dev/meta-marketing-api
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Google Ads API BBLinkedIn Marketing APIs BMicrosoft Advertising API CAmazon Ads API C
Head to head Amazon Ads API vs Meta Marketing API · Google Ads API vs Meta Marketing API · LinkedIn Marketing APIs vs Meta Marketing API · Meta Marketing API vs Microsoft Advertising API
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Google Ads API Google | BB | 76.4 | ads.reporting ads.campaigns ads.budgets ads.audiences ads.creatives | no |
| LinkedIn Marketing APIs LinkedIn Corporation | B | 62.4 | ads.reporting ads.campaigns ads.budgets ads.audiences ads.creatives | no |
| Microsoft Advertising API Microsoft | C | 60.3 | ads.reporting ads.campaigns ads.budgets ads.audiences ads.creatives | no |
| Amazon Ads API Amazon | C | 59 | ads.reporting ads.campaigns ads.budgets ads.audiences ads.creatives | no |
Machine-readable
- JSON
/api/v1/tools/meta-marketing-api.json· historyhistory.json· badge/badges/meta-marketing-api.svg· changes feed/feeds/tools/meta-marketing-api.xml - Markdown
/tools/meta-marketing-api.md· slim/tools/meta-marketing-api.min.md(or sendAccept: text/markdown) - Fix list
/fixes/meta-marketing-api.md·/fixes/meta-marketing-api.json - From a terminal
anchor tool meta-marketing-api --md(the CLI) · over MCPget_tool {"slug": "meta-marketing-api"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/meta-marketing-api"><img src="https://www.anchorterminal.com/badges/meta-marketing-api.svg" alt="Meta Marketing API on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/meta-marketing-api)<a href="https://www.anchorterminal.com/tools/meta-marketing-api">Meta Marketing API on Anchor Terminal</a>It counts on a page on developers.facebook.com or one of its subdomains, or the README of github.com/facebook/facebook-python-business-sdk.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "meta-marketing-api", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.
