Meta Ads MCP: Everyone Says 29 Tools. We Counted 91.

On 3 August we published a census of Claude’s connector directory and reported that no first-party connector for Facebook or Google ad accounts appeared in it. That census still holds — we re-ran the directory search on 11 August 2026 and Meta is still not there. What we missed, and corrected on 5 August, is that Meta has run its own MCP server since April. It just isn’t something you install from Claude’s directory.

So we went to read what Meta actually documents about it. Not to set it up — we have not connected this server, we have no screenshots of it running, and nothing below is a test result. What we did is open the seven pages of Meta’s tool inventory and count.

Every guide to this connector says it has 29 tools. Most of them put the number in the title. The documentation lists 91.

Note on links: this guide contains no affiliate links. We normally carry one where a paid tool is the subject of the article. This one is about a free, first-party alternative to the paid bridges — including one we earn from — so a commission link here would undercut the whole piece. We explain that at more length below.

What Meta documents

The server is hosted by Meta at https://mcp.facebook.com/ads, and Meta groups its tools into seven categories. The category pages carry their own update date — 14 July 2026 — and we read all seven on 11 August 2026. Both dates matter, because this inventory has a shelf life and the difference between them is the only honest way to report a moving number.

CategoryTools listed
Catalog creation and management34
Ad creation and management28
Signals and datasets13
Comprehensive reporting7
A/B tests and conversion lift studies7
Help and troubleshooting2
Activity logs1
Total entries92
Distinct tool names91

The gap between 92 and 91 is worth a sentence, because it is the trap waiting for anyone who repeats this exercise. One tool, ads_get_ad_entities, is listed on two pages: it appears under reporting and again under ad management, where the documentation itself points back to the other category. Add the seven pages together and you publish 92. The correct figure is the set of distinct names, and that is 91.

Three things fall out of the count that no guide to this connector mentions.

It is not a reporting tool

Nearly every write-up frames this as a way to ask an assistant about your campaign performance. One widely-shared guide states that two-thirds of the toolset is reporting and catalog work.

Reporting is seven tools out of ninety-one. Eight per cent.

The catalog category alone has thirty-four — more than campaigns, creatives, Instagram and audiences combined. Products, product sets, feeds, feed transformation rules, and the pixel and app event sources wired into them. Meta built a commerce instrument and hung a reporting module off the side of it.

That reframes who should care. If you run an online store with a product feed, this is a substantial piece of infrastructure aimed squarely at you. If you are a creator or a service business with no catalog, roughly a third of the surface area is inert, and the part you came for is the smallest pillar in the building.

The reporting seven are also not quite reporting. Two of them return judgments rather than figures: one produces an account optimisation score out of a hundred with recommendations attached, another flags performance patterns it considers anomalous. Reading numbers and being handed a verdict about them are different products, and the difference belongs to you, not to the tool.

The paused-on-creation guarantee covers three tools out of thirty-six

This is the part where we have to correct the story in Meta’s favour, and then immediately narrow the correction.

The claim circulating hardest about this connector is that it hands an AI agent unsupervised write access to a live ad account with no draft mode and no confirmation step. That is contradicted by Meta’s own documentation. Campaigns, ad sets and ads created through the server are created in a paused state, and the tool that switches something live is separate, documented on its own, and carries an explicit warning that it “starts spending budget”. If you have read that an agent can launch spend without you noticing, the documentation says otherwise.

Now the perimeter. Of the 91 tools, 36 write — they create, modify, delete, activate or spend. The paused-on-creation guarantee applies to exactly three of them: create campaign, create ad set, create ad. The other 33 writes sit outside the sentence entirely, because they do not produce advertising entities that could be paused:

  • The update tool edits a campaign, ad set or ad that already exists — including one already running. Nothing about that is documented as paused, and nothing in the documentation says it isn’t.
  • Sixteen catalog tools create, edit and delete catalogs, products, product sets, feeds and transformation rules, and connect or disconnect the event sources feeding them.
  • Six rewrite the event and parameter rules on your pixel — the configuration that decides what your measurement actually records.
  • One turns an existing organic Instagram post into a paid ad.
  • One uploads or removes hashed personal data on a customer-list audience.

None of that is hidden. It is all in the tool descriptions, in plain language, on pages anyone can open. But the headline safety sentence is about creation, and creation is a twelfth of the writing surface. Repeating the sentence without the perimeter does Meta a favour that Meta did not ask for.

There is also a governance layer that arrived on 16 July and that we have not seen mentioned in a single guide. Alongside opening the server to developers with their own app, Meta launched rules for the ads MCP server: anyone with full control of a business portfolio can constrain what AI agents are allowed to do on the ad account, budget changes and catalog updates included. Whether that is granular enough to matter, we cannot tell you — we have not seen the screen. But its existence changes the shape of the security conversation, and the reason nobody covers it is that almost every guide on this topic was written in early May.

Seven categories, from thirty-four tools to one

Meta’s overview page presents seven categories as peers. One holds 34 tools; “activity logs” holds one, and “help and troubleshooting” holds two. That taxonomy organises a documentation site. It does not describe a distribution of capability, and reading it as a feature list will give you the wrong idea of what this thing is for.

Meta describes the same product three different ways in three places, which is the cleanest evidence that the categories are editorial rather than structural. The business announcement lists four capabilities. The developer overview lists seven. The developer blog, two days later, lists seven different ones — it includes custom audiences and drops activity logs, where the overview does the reverse.

Where the guides diverge from the documentation

We checked the claims that recur across the guides ranking for this topic against Meta’s own pages. This is what survives.

Claim in circulationWhat Meta’s pages say
29 toolsDocumented inventory as of 14 July 2026: 91 distinct tools across seven category pages
Five capability areasSeven categories on the developer overview, four in the business announcement, seven different ones on the developer blog
No developer app requiredPartly true, and the phrase is Meta’s own. See below
No app reviewFalse for agencies: managing data on behalf of other businesses requires advanced access on the MCP permission, which goes through review
Endpoint at mcp.meta.com/ads/<business-id>The documented endpoint is mcp.facebook.com/ads
Phased rollout, US and high-spend accounts firstThe announcement describes an open beta for businesses of all sizes across regions. Meta may still be gating it in practice; it did not announce it that way
No draft mode, no confirmation screenContradicted for creation, silent on the other 33 write tools
CLI installed from npmTwo independent sources citing Meta’s setup page describe a Python package. We have not opened that page ourselves — unresolved
Free during the betaNot found on any Meta page we read. Unverified
Around 200 calls per hour per ad accountNot found on any Meta page we read. The figure circulates from a vendor documenting its own competing bridge

The “no developer app” row deserves its own paragraph, because the obvious reading of it is wrong and the right one is more interesting.

It would be easy to write that the guides invented a frictionless setup that the documentation contradicts. They didn’t. The phrase is Meta’s: the business announcement says the MCP path needs “no developer credentials, API setup, or coding required”. Meanwhile the developer documentation opens by having you create or reuse a Meta app, and the documented command for Claude Code takes an app ID as an argument.

Both are true, because there are two doors. April’s launch was for advertisers, authenticating through Meta’s own login. July’s addition was for developers connecting their own app, which is what the developer pages describe. Meta states plainly that owning an app is not a prerequisite and points to a separate guide for the path without one.

What nobody wrote is that the second door exists. The guides describe April and stop. If you land on one of them, try to follow the developer documentation, and find yourself being asked for an app ID you were promised you wouldn’t need, nothing is broken — you are reading instructions for a different entrance.

Who writes the guides, including us

There is a pattern in who ranks for this query, and naming it is not an accusation of bad faith.

The guides on the first page of results for Meta’s free, first-party connector are published overwhelmingly by companies selling something adjacent: hosted MCP bridges to the same ad accounts, multi-platform connector suites, creative analytics platforms, ad upload tools, media buying agencies. That is ordinary trade publishing. But it means the public record about a free official tool is written almost entirely by people who sell the paid alternative to it, and that shapes which details travel and which don’t.

The direction of the distortion is predictable enough to use as a reading heuristic. Friction on the free path gets under-documented; risk gets over-documented. The claim that this connector has no confirmation step and no draft mode is a good example — it is contradicted by the vendor’s own documentation, and it is published mostly by people who sell bridges with confirmation steps.

Which points at us. We carry an affiliate link for Windsor.ai in other articles — a paid bridge that reads Meta ad data among many other sources, and therefore competes with the thing this article is about. So the same heuristic applies to us, and the answer is structural rather than rhetorical: there is no affiliate link in this article. We took that decision when we planned the piece, for the same reason we corrected our August census — an article that steers you toward a paid aggregator while the free native option sits one paragraph away is not a factual error, it is an integrity problem.

For completeness, since the question is reasonable: a paid bridge still earns its money on things this server does not do. It reads more than one advertising platform through a single connection, it writes to warehouses and spreadsheets, and it gives you one authorisation covering many sources instead of one per platform. If none of those apply to you, the free first-party server is the better starting point, and we would rather say so.

What we couldn’t verify

Everything above is documented, not tested. We read Meta’s pages; we did not connect the server, run a tool, or watch an agent touch an ad account. Specifically open:

  • What a given account actually sees. Meta’s blog tells readers to “ask your agent what tools you have access to”, and says access is being rolled out gradually. So 91 is the documented inventory, not a promise about your account.
  • Whether the update tool asks before changing a live budget. The documentation covers creation. It says nothing either way about edits to something already running.
  • How granular the July governance rules are. Per role, per tool, per spend threshold — unknown until someone with a business portfolio opens the panel.
  • Pricing after the beta, and rate limits. Neither appears on any Meta page we read.
  • The advertiser setup path in Meta’s Business Help Centre. That page decides whether the “paste the URL into Claude” flow everyone shows is documented anywhere by Meta. We could not open it.
  • The CLI package name and its default entity state. Two sources quoting Meta’s setup page disagree with the guides. We have not read that page.

We will add dated updates to this article as these close, the way we did with our August census. If you find one of them answered, the fastest way to reach us is a reply to the newsletter.

If you’re deciding today

Three questions settle it faster than a comparison table.

Do you have a product catalog? If yes, this server is aimed at you more directly than at anyone else, and the thirty-four catalog tools are the reason to look. If no, you are evaluating a much smaller product than the tool count suggests.

Do you need more than Meta? One platform, one connection: the official server is free and authenticates through Meta itself. Several platforms, or data leaving for a warehouse or a spreadsheet: that is what paid bridges are for, and the cost of them is covered in our guide to what MCP connectors actually cost.

Who has write access, and to what? This is the question that outlives the choice of tool. Thirty-six of ninety-one tools write, three of them are documented as reversible-by-default, and the governance panel that could constrain the rest arrived in July with no coverage at all. Before you connect any bridge to an account that spends money — this one, ours, anyone’s — find out what its write surface is and whether you can switch it off — the same questions we walk through in our guide to MCP security for non-developers. On Windsor.ai, the bridge we use ourselves, that switch is a single global toggle with no granularity at all, which we only found by going looking for it.

The free official option is genuinely better than the corpus makes it sound, and genuinely narrower than its own headline sentence implies. Both of those took reading the documentation, and the documentation is free too.

The Claude MCP Playbook

One page per connector: what it does, what it really costs, what breaks. Plus the decision tree for choosing between them, and ready-made stacks by business type. Founding price for the first readers on the list.

Join the waitlist — or read the costs chapter free, twenty connectors priced row by row with the date we checked each one.

You Might Also Like

More on connecting marketing and ad data to Claude, what it costs, and how to do it without handing an assistant more access than you meant to.

Related Posts

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top