Guide · Meta Ads access
Connecting a third-party app to your Meta ad account: what you are actually granting
A reporting tool, an AI assistant or an agency dashboard asks to connect to your Meta ads. The consent screen takes ten seconds. What you agree to there can last for years, so read it once properly.
Short answer: a third-party app connects to your Meta ad account through Facebook Login for Business. During that flow your business picks which assets the app can reach and which permissions it gets. Grant ads_read if the tool only reports, ads_management only if it must change campaigns, and remove the integration in Business integrations the day you stop using it.
What happens when you click Continue?
- You choose the assets. Meta’s documentation for Facebook Login for Business says the connecting business selects the assets the app needs and the permissions it needs. Pick the ad accounts the tool is for, not everything the portfolio owns.
- You choose the permissions. Each one is a separate grant. A tool that asks for more than its job needs is telling you something.
- The app receives a token. For automated work, Meta’s documentation points apps to a business integration system user token, which belongs to your business portfolio rather than to a person and typically does not expire. A user token is short-lived and tied to whoever clicked.
The token is the part people underestimate. Because it belongs to the business and does not expire by itself, the access outlives the person who granted it. Somebody leaves the company, the trial ends, the agency changes, and the integration keeps working until someone removes it.
Source: Meta for Developers, Facebook Login for Business, read on 6 October 2026.
Or see what your team should look at first: the Paid Media Capacity Check, being built nowWhich permissions should a third-party app get?
| Permission | What the app can do | Grant it when |
|---|---|---|
ads_read | Read Ads Insights reporting on the ad accounts you granted. Spend, results, campaigns as they are. | The tool reports, audits or answers questions. That covers dashboards and most AI assistants. |
ads_management | Read and manage the ad accounts: create, edit, pause. Brings two Page permissions with it, pages_read_engagement and pages_show_list. | Only when the tool must change campaigns, and you know who approves those changes. |
business_management | Read and write through the Business Manager API: assets, people, partners. | Rarely. A reporting tool has no reason to manage your business portfolio. |
read_insights | Insights for Pages, apps and domains. Not ad performance, despite the name. | Only if the tool reports on your Page, not your ads. |
A pattern worth knowing: Meta’s own ads MCP server asks for ads_management even when you only want to read, and relies on rules that portfolio admins set to keep an agent read-only. That can be a fine choice, but it is a different promise from a tool that only ever asked for ads_read. A rule can be changed later; a permission that was never granted cannot be used.
App connection, partner access or a person: which one fits?
| Route | Who or what gets in | Best for |
|---|---|---|
| Third-party app | Software, through its token, with the permissions you granted | Reporting, monitoring, AI tools that work without a person clicking |
| Partner access in your business portfolio | Another business, which then assigns its own people | An agency that runs the account with several people |
| A person in your business portfolio | One named person with a role on the ad account | A freelancer or a single employee |
The same rule as on Google applies: give access to named people or to a named business, never to one shared login. When everyone works through one identity, nobody can tell afterwards who changed what. Our Google Ads access levels guide covers the Google side, where passkeys are making shared logins impossible.
How do you see and remove an app connected to your ad account?
In Facebook, open Settings & privacy, then Settings, and find Business integrations in the menu. Every integration connected through your profile is there, with a Remove button next to it.
According to Meta’s help centre, removal stops future calls and does not recall what the app already received. Integrations the app set up while it was connected can also keep access to your portfolio. Check your business settings afterwards, not only the list you removed it from.
My own habit, on Meta and on Google alike: when a tool or an agency relationship ends, the access goes the same day. Waiting until someone remembers is how an old integration ends up reading a client’s numbers a year later.
Building the app yourself instead? Meta Marketing API access for your own ads appWhy does the app say it is not available?
If you try to connect and Meta says the app is not available or not published, the problem is usually on the app’s side, not yours. Apps in Development mode only work for people with a role on the app. For anyone else, the developer needs Live mode, advanced access to each permission, business verification and App Review.
I know this one from the other side of the screen. Our own app worked for weeks while I was the only person testing it, and the first client who tried to connect was told it was not possible. The full story, and what the developer has to do, is in Meta Marketing API access.
What I still don’t know
Whether every third-party app shows you an asset picker, or whether some still take the whole portfolio by default. Meta’s developer pages describe the flow that Facebook Login for Business provides; how each vendor configures it is up to the vendor. Look at the screen in front of you rather than trusting this page or the vendor’s marketing.
See the Meta Ads MCP options, and what each one can changeQuestions people actually ask
What permissions does a reporting tool need on my Meta ad account?
ads_read is enough for reporting: it gives Ads Insights on the ad accounts you granted. A tool that asks for ads_management can also create, edit and pause ads, so grant that only if it has to change campaigns.
How do I remove a third-party app from my Meta ad account?
In Facebook, go to Settings and privacy, Settings, then Business integrations, and click Remove next to the app. Meta notes the app may keep information it already received, and may have set up integrations that still reach your portfolio, so check your business settings too.
Does access granted to a third-party app expire?
Not necessarily. A user token is short-lived, but a business integration system user token belongs to the business portfolio and typically does not expire. Access ends when someone removes the integration.
Why can I not connect an app to my Meta ad account?
Usually because the app is still in Development mode, where only people with a role on the app can grant permissions. The developer needs Live mode, advanced access, business verification and App Review before outside businesses can connect.
Is it safer to give an agency partner access than to connect their app?
Partner access and an app connection solve different problems. Partner access lets the agency’s people work in your account under their own names. An app connection gives software a token. An agency that runs the account usually needs partner access; its reporting tool needs an app connection with ads_read.
Related reading
- Meta Marketing API access for your own ads app. The developer side of the same screen: modes, access levels and App Review.
- Google Ads access levels. The five levels on Google, and why a shared agency login stops working.
- Connect your AI to your ad data. The three ways to get an assistant to your numbers, including the ones that are not ours.
Last updated:
Who wrote this
I’m Manu. I’m a media buyer, and I built Climent Ads Assistant because no ads software I paid for was worth it. It reads Meta, Google Ads, GA4 and Search Console one client at a time. On Meta, the only ads permission it asks for is ads_read.