Meta Ads MCP Server Ships With Every Write Action On — Here's the Audit Your Agency Needs Today
Meta's MCP permissions panel shipped with all 7 write actions enabled by default — including budget edits and campaign creation. If your agency manages client accounts through one portfolio, they're all exposed. Here's the 5-step audit we run at Mintec.
Meta Ads MCP Server Ships With Every Write Action On — Here's the Audit Your Agency Needs Today
On August 20, Jon Loomer published the first detailed field report on Meta's MCP server permissions panel: accounts arrived allowing "7 of 7" write actions by default — including the two that move money without anyone approving them. If your agency manages client accounts through a single Business Manager portfolio, every one of them is exposed — and the client never signed off on this.
We have been running the MCP server against our own and client accounts at Mintec since July, and this is the security gap that more agencies will discover when it is already too late: the MCP server is not insecure — the defaults are configured to hand you maximum access on day one, and most teams do not even know the panel exists.
The 7 actions that were enabled by default
When Meta shipped the MCP server permissions panel on July 16, 2026, every ad account arrived with these write actions turned on:
| Action | What it does | Risk level |
|---|---|---|
| Edit or set budgets | Changes how much a campaign spends | High — moves money |
| Create campaigns | Full structure from a natural-language brief | High |
| Create ad sets | Segmentation and bidding | Medium |
| Create ads | Creative and copy | Medium |
| Edit targeting | Changes who sees your ads | Medium |
| Edit creative | Modifies images, text, links | Medium |
| Edit status | Pauses or activates campaigns | High — can stop delivery |
Two of these actions — budgets and status — can move money or kill campaigns without a human approving them. Both were on by default. Nobody turned them on. Meta turned them on for you.
The portfolio problem: every client account exposed
This is where it gets serious for agencies.
Authorization happens at the Business Manager portfolio level — not at the individual account level. If your agency has one portfolio containing5 client accounts, and someone connects an AI agent to that portfolio, all5 accounts are exposed with the same7 write actions — unless someone manually goes account by account and turns them off.
The client never authorized an AI agent to touch their account. The client authorized your agency to manage their campaigns. But your agency's portfolio now has an agent with write access to everything.
This is not a hypothetical scenario. It is what Meta configured as the default.
MCP server vs CLI: the difference with a real budget attached
One operational detail most people miss: there are two paths for an AI agent to interact with your Meta account, and they behave very differently.
Official MCP server (mcp.facebook.com/ads): Campaigns created land paused until a human activates them. This is a safety net — if an agent creates a campaign by mistake, it does not spend money until someone reviews it.
Meta CLI (command-line tool): Campaigns are created active by default unless you explicitly pass a paused flag. If your engineering team is using the CLI instead of the MCP server, a rogue campaign can start spending money immediately.
The difference between "paused by default" and "active by default" is the difference between catching an error in the morning review and finding$2,000 in phantom spend on Monday at8am.
The 5-step audit we run at Mintec
After Loomer published his findings, we ran this audit across every client account we manage. It takes roughly20 minutes per account. Here is what we did:
Step1: Business Settings > Integrations > Ads MCP Server. Review the full list of exposed accounts and catalogs. If you do not see this section, your portfolio does not have access to the panel yet — but that does not mean the accounts are safe, it means you cannot see what is enabled.
Step2: Click Details on each account. This is where the7 actions live. In every account we reviewed, all7 were enabled. No exceptions.
Step3: Turn off write actions you do not need. For most client accounts, this means turning off6 write actions and keeping only read. If you are using an agent for automated reporting, that is Tier1 — read-only. You do not need an agent creating campaigns or changing budgets without your oversight.
Step4: Document what stayed on and why. If you left any write action enabled, write down why. "The agent needs to pause campaigns outside business hours" is a valid reason. "I don't know what this option does" is not.
Step5: Repeat with the engineering team. If anyone in your organization is using the CLI instead of the MCP server, verify they are passing the paused flag when creating campaigns. The CLI creates campaigns active by default — this is the opposite of the MCP server's safety net.
The broader pattern: Meta always turns everything on
The7 default write actions are not an accident. They are part of a pattern Meta has been executing all year:
- Advantage+ is the default campaign type for Sales, App, and Leads since January — you cannot choose manually without hunting for the option
- Placement exclusions are being removed from Sales and Leads ad sets — replaced by value rules that can cut your bid by90% but cannot block a placement
- Meta AI can now read your ad account — launched August19 as a free tool for small businesses that connects to your campaigns, analyzes your creative, and builds presentations
- The MCP server shipped with7/7 write actions on — no advance notice, no rollout date, no "configure later" option
The pattern is clear: Meta is moving toward full campaign automation by end of2026. Every layer of manual control you had is being eliminated or disabled by default. Your job as an agency is not to fight automation — it is to configure the right boundaries before the platform configures them for you.
What to do now
- Today: Open Business Settings > Integrations > Ads MCP Server and audit which accounts are exposed. If you cannot see the panel, contact your portfolio admin.
- This week: Turn off write actions you do not need on every account. Leave read-only as the default. Escalate to write only when you have a specific use case and written client approval.
- This month: Document your MCP permissions policy. If your agency does not have a written answer to "what can an AI agent touch," your client's answer will be "nothing" — or worse, "everything."
- Before Q4: Start the App Review request for
ads_mcp_managementif you plan to grant client access. The review queue takes weeks, and the ability to connect agents will be a procurement checkbox for AI-forward clients before the year ends.
Meta's MCP server is the future of how AI agents interact with ad accounts. But the future should not arrive with every key already in the door waiting for someone to pick it up.
FAQ
What are the 7 write actions on Meta's MCP server? Edit or set budgets, create campaigns, create ad sets, create ads, edit targeting, edit creative, and edit status. The first two move money without human approval, and both were enabled by default when the permissions panel shipped in July 2026.
Can an AI agent create live campaigns through the MCP server? Not through the official MCP server — campaigns created via MCP land paused until a human activates them. But through Meta's CLI, campaigns are created active by default unless you pass a paused flag. That difference has budget attached to it.
How do I audit MCP permissions on my Meta Ads account? Go to Business Settings > Integrations > Ads MCP Server. Review every exposed account and catalog. Click Details on each one to see which actions are enabled. Turn off every write action you don't need — especially the two that move money (budgets and status).
Frequently Asked Questions
What are the 7 write actions on Meta's MCP server?
Edit or set budgets, create campaigns, create ad sets, create ads, edit targeting, edit creative, and edit status. The first two move money without human approval, and both were enabled by default when the permissions panel shipped in July 2026.
Can an AI agent create live campaigns through the MCP server?
Not through the official MCP server — campaigns created via MCP land paused until a human activates them. But through Meta's CLI, campaigns are created active by default unless you pass a paused flag. That difference has budget attached to it.
How do I audit MCP permissions on my Meta Ads account?
Go to Business Settings > Integrations > Ads MCP Server. Review every exposed account and catalog. Click Details on each one to see which actions are enabled. Turn off every write action you don't need — especially the two that move money (budgets and status).



