Guide · Meta Marketing API

Meta Marketing API access for your own ads app, and the day a client tries to connect

Meta tells you everything is fine. No error, no upgrade button you can find. Then a client tries to connect and gets told the app isn’t available. This is what sits between those two moments.

Own use or public app ↓

Short answer: to read your own ad accounts, a Meta app in Development mode with standard access to ads_read is enough. The moment another business connects, the app needs Live mode, advanced access, business verification and usually App Review. Meta’s official ads MCP server, open to developers since July 2026, is the alternative to building all of this yourself.

Do you need your own Meta app at all?

Maybe not. Meta runs its own ads MCP server. It opened in beta in April 2026 and to any developer with their own Meta app on 16 July 2026, according to Meta’s developer blog. It has tools for reporting, creating and managing ads, catalogs and more.

Two details matter before you pick it:

Your own app makes sense when you want to decide what the model sees and how the numbers are treated before it sees them, or when you want read-only by construction rather than by a rule someone can change. That is why we built ours.

Or see what your team should look at first: the Paid Media Capacity Check, being built now

What does a Meta app need for the Marketing API?

One thing surprises people who come from Google: there is no sandbox tier. Meta’s authorisation page is explicit about it:

“Calls on ANY access level are against production data.”

Meta for Developers, Marketing API authorization, read on 28 September 2026.

Test writes need an account where spending is impossible. We test ad creation on an ad account of our own that is closed, and anything live runs with a budget of €1.

Own use or public: what does each one ask you for?

Meta uses two sets of words that sound alike and are not. Standard and advanced access belong to each permission and decide who can grant it. Limited and Full access are tiers of the Marketing API itself, renamed from the old standard and advanced tiers, and mostly decide your rate limits.

Own use: your own ad accountsPublic: other businesses connect
App modeDevelopment. Only people with a role on the app can grant permissions.Live. Anyone can be asked, but only for permissions approved through App Review.
Permission accessStandard access to ads_read is enough for ad accounts you manage.Advanced access to each permission you ask clients for.
Business verificationNot needed while only people with a role on the app use it.Required for advanced access.
Marketing API tierLimited: the default, heavily rate-limited, meant for development. One system user plus one admin system user.Full: at least 500 Marketing API calls in the last 15 days with under 15% errors. Ten system users plus one admin.
TokenA system user in your own business portfolio, or your own long-lived token.Each client’s token, through Facebook Login.
Best forReading your own accounts through your own MCP.A product other agencies sign into.

The number of ad accounts is not what the tiers limit. Both can manage an unlimited number, and in the Climent Ads Assistant app ads_read on Limited access returned all 23 ad accounts the user could see. What Limited access limits is how often you can call: on the development tier a reading call costs one point against a ceiling of 60, where the standard tier allows 9,000.

Or see what your team should look at first: the Paid Media Capacity Check, being built now

What happened when a client tried to connect?

For weeks everything worked. The dashboard showed nothing wrong, I couldn’t find a single error, and I couldn’t find any obvious way to upgrade. Then a client tried to connect and was told it wasn’t possible, because the app wasn’t published. Zero guidance on what to do next.

Looking back, the rule was in the table above the whole time. In Development mode only people with a role on the app can grant permissions, and the only person testing was me. Everything works when the only user is the developer.

Was it worth building?

I’ll be honest about the cost. For one business with a few accounts, hiring someone is cheaper than building an app, keeping it updated and pushing it through every phase. I built it anyway, after spending close to €15,000 on ad management software that never earned its place. I wanted a tool made by a paid media specialist for paid media, and nobody sold one.

Today I still read my own accounts with my personal long-lived token, and the review for other users is under way. This page is the prequel to that review. When it’s through, I’ll write down what Meta asked for.

Which permissions should you request, and why?

The smallest set that does the job, because every permission you add changes what App Review looks at.

PermissionWhat it gives youBest for
ads_readAds Insights reporting on the ad accounts you own or were granted. No other permission needed.Any MCP that only reads. It is the only Meta ads permission our product asks for.
ads_managementReading and managing ad accounts. Brings two Page permissions with it: pages_read_engagement and pages_show_list.Only if the MCP writes. Asking for it to read makes the review bigger for nothing.
business_managementReading and writing through the Business Manager API. Brings the same two Page permissions.Only if you manage business assets through the API, not to read ads.
read_insightsInsights for Pages, apps and domains.Nothing to do with ad performance, despite the name.

For your own use, a system user is the cleaner token for anything that runs unattended: it belongs to the business, not to a person who might leave or change their password. My personal token works, but it expires, and Meta can change user token lifetimes without notice.

How do you keep it safe once it works?

A token that reads your ad accounts is a key to real money, and ad accounts get taken over far more easily than people think. When you manage clients you are not risking your own business any more, you are risking theirs. Ask for ads_read unless you truly write, keep the system user in the business that owns the accounts, and keep something watching for anything strange: a campaign nobody planned, targeting the whole world, a random name, spend that matches nothing in your plan.

Or see what your team should look at first: the Paid Media Capacity Check, being built now

What I still don’t know

What App Review will ask for this time, and how long it takes. Meta’s pages describe the steps, not the questions a reviewer asks, so the only honest answer is the next page of this series.

And whether assets owned by the business that claimed the app count as your own under standard access. The documentation I read doesn’t say, and I’d rather leave the question open than guess.

Or skip the build: the Meta Ads MCP options, and what each one can change

Questions people actually ask

Does Limited access to the Marketing API limit how many ad accounts I can read?

No. Both Limited and Full access can manage an unlimited number of ad accounts. Limited access is heavily rate-limited and meant for development. In our own app, ads_read on Limited access returned all 23 ad accounts the user could see.

Do I need business verification to read my own ad accounts?

No. If only people with a role on your app use it, standard access is enough and business verification is not required. It becomes necessary for advanced access, which is what you need when other businesses connect their accounts through your app.

What is the difference between standard or advanced access and Limited or Full access?

Standard and advanced access are set per permission, such as ads_read, and decide who can grant it. Limited and Full access are tiers of the Marketing API itself, renamed from the old standard and advanced tiers, and mainly decide your rate limits.

Why can a client not connect to my Meta app?

Usually because the app is in Development mode, where only people with a role on the app can grant permissions. Everything works while you are the only tester. For a client outside the app, it needs Live mode and advanced access to each permission, which means business verification and App Review.

Do I need read_insights to read ad performance?

No. read_insights covers insights for Pages, apps and domains, not ads. Ad performance comes through ads_read, which gives Ads Insights reporting on the ad accounts you own or were granted.

Related reading

Last updated:

Who wrote this

I’m Manu. I’m a media buyer, and I built Climent Ads Assistant because no ads software I paid for was worth it. It reads Meta, Google Ads, GA4 and Search Console one client at a time, and changes a campaign only through a proposal that a person signs in the product. On Meta it only reads.