Documentation & trust

Product and API use

Meta Ads API and StoreAdOps

StoreAdOps is a hosted SaaS product and secure tool service for advertisers and agencies that own or are authorized to manage Meta (Facebook and Instagram) advertising accounts through Meta's Marketing API.

Business model

StoreAdOps is currently offered as a free hosted SaaS product with open signup. Paid subscription plans and external billing are not active. StoreAdOps does not sell advertising inventory, purchase media, or operate as an advertising agency. Users remain responsible for their own Meta ad accounts, budgets, and confirmed changes.

Meta permissions requested

After the user chooses to connect Meta, StoreAdOps requests the following permissions through Meta's OAuth consent screen:

The Page workflow is read-only and limited to Page-authored published posts. StoreAdOps does not read comments, follower identities, messages, or audience content and does not publish or moderate Page content.

StoreAdOps advertises its complete tool catalog to every user through the standard /mcp endpoint. Broader Page advertising and Commerce catalog tools remain visible, but return a permission-required response before any Meta API call unless the connection already has their separately reviewed scopes.

How a user connects Meta

  1. The user signs in to StoreAdOps.
  2. The user authorizes Meta OAuth and grants the requested permissions.
  3. StoreAdOps lists only the businesses, ad accounts, and managed Pages inside the business selected during consent.
  4. The user connects an AI client using platform-managed browser OAuth where supported, or a revocable, tenant-scoped API key. The setup guide explains both paths.
  5. The client can request reporting or account operations only for the connected user's selected ad account.

Meta Marketing API use cases

Read workflows include campaign, ad set, and ad structure and performance, creative details, audience targeting research, pixel status, delivery diagnostics, managed-Page discovery, and review of recent Page-authored published posts for ad planning.

Management workflows include user-confirmed campaign, ad set, and ad creation, updates, and pauses. New campaigns are created paused by default.

Safety and authorization controls

Data handling

StoreAdOps retrieves campaign and performance data live rather than accumulating a campaign-data warehouse. It stores encrypted OAuth tokens, selected account metadata, hashed API keys, OAuth state, usage counters, and audit and idempotency records. When growth-analysis features are enabled, bounded encrypted snapshots may be retained with a 30-day expiration; some operational and safety records are retained longer. See the privacy policy for retention and deletion details.

Meta user data is not sold and is not used to train general AI models. Users can revoke access in their Meta account settings and request deletion through support@storeadops.ai.

Meta Ads tools (10 tools)

StoreAdOps exposes the complete Meta Ads tool catalog to connected AI clients: Ten shared tools serve all channels. Use get_capabilities to discover account-eligible operations and their input schemas. Reads do not change campaigns; report starts create explicit report jobs. Changes require a preview, confirmation and an idempotency key. Availability depends on connected accounts, permissions, assets and enabled features.

get_connections_status

    get_capabilities

      query

      • account.verifyRequires granted scopes: ads_read.
      • evidence.meta.audit_meta_accountRequires granted scopes: ads_read.
      • evidence.meta.optimize_meta_budgetRequires granted scopes: ads_read.
      • evidence.meta.optimize_meta_placementsRequires granted scopes: ads_read.
      • evidence.meta.prioritize_meta_recommendationsRequires granted scopes: ads_read.
      • evidence.meta.recommend_meta_bid_strategyRequires granted scopes: ads_read.
      • meta.account.insightsRequires granted scopes: ads_read.
      • meta.ads.getRequires granted scopes: ads_read.
      • meta.ads.insightsRequires granted scopes: ads_read.
      • meta.ads.listRequires granted scopes: ads_read.
      • meta.adsets.getRequires granted scopes: ads_read.
      • meta.adsets.insightsRequires granted scopes: ads_read.
      • meta.adsets.listRequires granted scopes: ads_read.
      • meta.assets.discoverRequires granted scopes: ads_read.
      • meta.assets.validateRequires granted scopes: ads_read.
      • meta.campaigns.getRequires granted scopes: ads_read.
      • meta.campaigns.insightsRequires granted scopes: ads_read.
      • meta.campaigns.listRequires granted scopes: ads_read.
      • meta.catalogs.discoverRequires granted scopes: business_management, catalog_management. Requires separately granted permission catalog_management; not included in the standard connection.
      • meta.catalogs.getRequires granted scopes: business_management, catalog_management. Requires separately granted permission catalog_management; not included in the standard connection.
      • meta.catalogs.productsRequires granted scopes: business_management, catalog_management. Requires separately granted permission catalog_management; not included in the standard connection.
      • meta.catalogs.validateRequires granted scopes: business_management, catalog_management. Requires separately granted permission catalog_management; not included in the standard connection.
      • meta.creative.fatigueRequires granted scopes: ads_read.
      • meta.creatives.listRequires granted scopes: ads_read.
      • meta.delivery.diagnosticsRequires granted scopes: ads_read.
      • meta.pages.creativesRequires granted scopes: business_management, pages_manage_ads. Requires separately granted permission pages_manage_ads; not included in the standard connection.
      • meta.pages.discoverRequires granted scopes: business_management, pages_show_list.
      • meta.pages.getRequires granted scopes: business_management, pages_show_list, pages_read_engagement.
      • meta.pixels.healthRequires granted scopes: ads_read.
      • meta.pixels.listRequires granted scopes: ads_read.
      • meta.spend.diagnosticsRequires granted scopes: ads_read.
      • meta.targeting.browseRequires granted scopes: ads_read.
      • meta.targeting.searchRequires granted scopes: ads_read.

      get_report

      • meta.insights.reportRequires granted scopes: ads_read.

      prepare_change

      • ad.createRequires granted scopes: ads_management.
      • ad.pauseRequires granted scopes: ads_management.
      • ad.removeRequires granted scopes: ads_management.
      • ad.resumeRequires granted scopes: ads_management.
      • ad.updateRequires granted scopes: ads_management.
      • campaign.createRequires granted scopes: ads_management.
      • campaign.pauseRequires granted scopes: ads_management.
      • campaign.removeRequires granted scopes: ads_management.
      • campaign.resumeRequires granted scopes: ads_management.
      • campaign.updateRequires granted scopes: ads_management.
      • campaign_bundle.create:carouselRequires granted scopes: ads_management, business_management, pages_show_list.
      • campaign_bundle.create:imageRequires granted scopes: ads_management, business_management, pages_show_list.
      • campaign_bundle.create:videoRequires granted scopes: ads_management, business_management, pages_show_list.
      • creative.deleteRequires granted scopes: ads_management.
      • group.create:ad_setRequires granted scopes: ads_management. When ad_set.promoted_object.page_id is non-null, also requires granted scopes: business_management, pages_show_list.
      • group.pauseRequires granted scopes: ads_management.
      • group.removeRequires granted scopes: ads_management.
      • group.resumeRequires granted scopes: ads_management.
      • group.updateRequires granted scopes: ads_management.

      execute_change

        get_change_status

          get_merchant_profile

            record_recommendation

              get_recommendation_history

                Frequently asked questions

                What can StoreAdOps do with my Meta account?

                After you authorize Meta OAuth, connected AI clients can read reporting and account structure and, only with your explicit confirmation or a disclosed approval, create or update campaigns, ad sets, and ads in the ad account you selected.

                Will it change my account without asking?

                No. Direct write tools require confirmed=true; approval-backed executions require separately validated execution authority. All provider writes require an idempotency key, and new campaigns are created paused by default so you can review before anything spends.

                Does it generate ad images or videos?

                No. StoreAdOps manages campaigns and ads from creative assets you provide; it does not generate creative media.

                How do I revoke access?

                You can revoke access from your Meta account settings at any time and request deletion through support@storeadops.ai.