Typed beats prompted
A tool with a schema cannot invent a field, target the wrong account or misplace a zero the way generated API calls can. The model chooses which tool to call; it does not compose the request.
Meta Ads MCP
Since 29 April 2026 there has been an official one. Meta's Ads AI Connectors put 29 tools behind a Business OAuth login, and any advertiser can wire them into Claude or ChatGPT in about two minutes. It is good infrastructure. It also cannot see your cost of goods, your refunds or whether a buyer ever came back – and on a live ad set, a write lands the moment the agent decides it should. That gap is what this page is about.
A Meta Ads MCP server exposes Meta's Marketing API to an AI agent through the Model Context Protocol: instead of generating raw API calls, the model calls a fixed set of typed tools – read insights, pause an ad set, set a budget – each with validated parameters and its own permission. Since April 2026 the term covers two things. Meta's own hosted connector is the first: one advertiser, one login, 29 tools, free in beta. The second is what products build on top – a smaller tool surface judged against the order book, with profit after COGS as the verdict and a human approving every write before it reaches the account.
Meta now ships its own MCP server – a hosted endpoint plus a CLI, marketed as Ads AI Connectors. Twenty-nine tools across reporting, campaign management, catalogue and diagnostics, authenticated through Business OAuth with no developer app and no app review. It is free in open beta, it took Meta about two minutes to make trivial, and it is the right answer for a lot of people. It is also single-platform by design, and it has no idea what your products cost.
| Meta Ads official | Kepra | |
|---|---|---|
| What it connects | Your ad account to your AI assistant | Your ad account to your order book, then to an assistant |
| Judges a campaign by | Meta's own reported conversions and ROAS | Profit after COGS, refunds and processor fees, from matched orders |
| Safety on writes | New campaigns land paused – but a budget raise or a pause on a live ad set executes on the call | Every write waits for a human to approve that exact call |
| Write bounds | Whatever the authenticated account permits | Hard limits you set, checked before a human ever sees the proposal |
| Audit trail | Meta's own change history | Approver, evidence cited, response, previous state, one-click revert |
| Across platforms | Meta only – no official connector spans channels | Meta and Google judged against one order book, in one verdict |
| Built for | One advertiser, one account, one chat window | A business where more than one person acts on the number |
When theirs is the right answer
If you are one person who wants to ask Claude what yesterday cost, use Meta's connector. It is free, it is official, and Kepra does not try to replace it. The case for a layer on top starts where a wrong answer costs money: when the verdict has to survive COGS and refunds before anyone acts on it, when the person approving is not the person who asked, and when "the AI changed it" needs to be a sentence with a name and a timestamp attached.
Against the official server’s breadth, this is deliberately narrow – a small surface is a security feature, because every tool the agent does not have is a mistake it cannot make. Reads run freely; that is how the case gets built. Writes wait for you.
| Tool | Access | What it does |
|---|---|---|
| get_campaigns | read | Campaign structure, status and budgets across the account |
| get_insights | read | Spend, impressions and platform-reported results per ad set and ad |
| pause_ad_set | write · approval | Stop delivery on one ad set – the most common fix for a verified leak |
| set_budget | write · approval | Change a daily or lifetime budget, bounded by limits you set |
| set_bid_cap | write · approval | Adjust a bid cap without touching anything else on the ad set |
A tool with a schema cannot invent a field, target the wrong account or misplace a zero the way generated API calls can. The model chooses which tool to call; it does not compose the request.
Read tools run freely – that is how the AI builds its case. Write tools stop at an approval step naming the exact change. Our terms commit to this; it is not a setting that can drift.
Every executed call stores who approved it, the evidence cited, Meta's response and the state it replaced. Undo is one click, not an archaeology exercise.
This is the demo’s own Meta Ads verdict, followed from the first read to the log entry – real numbers, no hypotheticals.
get_insights pulls 30 days on Prospecting – Interests: €9,220 spent, Meta-reported ROAS 2.8. So far the campaign looks like a keeper – which is exactly why platform numbers alone cannot be the judge.
Kepra matches the clicks against real orders: €6,450 actually returned, and 71% of those buyers never came back. The platform graded its own homework; the order book disagrees.
After COGS the campaign is €5,200/mo underwater. The proposal names one call – pause_ad_set – and attaches every number it used to get there.
The exact call sits in AI Actions waiting. Nothing has touched the ad account yet, and nothing will until a human clicks approve on this specific change.
On approval the call executes against the Marketing API in about a second. The log stores who approved it, the evidence cited, Meta's response and the previous state – revert is one click.
Different jobs, not just different quality – which is why the comparison has columns instead of a winner’s podium. Some accounts run all three.
| MCP + approval | Advantage+ | Automated rules | |
|---|---|---|---|
| Who defines "working" | Profit after COGS and repeat behaviour, from your orders | Meta's own conversion counting | Whatever metric you hardcoded |
| Sees your margins | Yes – COGS from Shopify, refunds and fees included | No | No |
| Human approval | Every write, per call | None once enabled | None once enabled |
| Scope of action | Pause, budget, bid – bounded by limits you set | Broad automation inside Meta's own goals | Only what each rule names |
| Audit trail | Full: approver, evidence, response, one-click revert | Meta's change history | Meta's change history |
The loop, on Meta Ads – from the demo
Meta Ads → Kepra
Reading
spend + matched orders
Deciding
profit after COGS and LTV
Your call
nothing moves until you say so
Pushing
executed over MCP, logged
Verdict: Prospecting – Interests spends €9,220/mo. Meta reports ROAS 2.8; matched against real orders it returned €6,450, and 71% of those buyers never came back. After COGS it is €5,200/mo underwater.
A system that only claims wins is a brochure. These are the boundaries, stated as plainly as the features.
A server that exposes Meta's Marketing API to AI agents as typed tools over the Model Context Protocol, an open standard introduced by Anthropic in 2024. The agent calls tools like get_insights or pause_ad_set with validated parameters instead of generating raw API requests. Since 29 April 2026 Meta operates an official one – Ads AI Connectors, 29 tools behind a Business OAuth login – and products like Kepra build a narrower, profit-aware surface on the same protocol.
For plenty of jobs you would not, and we say so. Meta's connector is free, official and takes two minutes. It also reads only Meta's own numbers: it cannot see your cost of goods, your refunds, your processor fees or whether a customer ever came back, because it has no access to your order book. So it can tell you a campaign reported a 2.8 ROAS. It cannot tell you the campaign loses €5,200 a month once the products are paid for. That verdict is the reason Kepra exists.
Partly. Entities it creates land in a paused state, so a new campaign cannot start spending unattended – a sensible default. But that covers creation, not change: raising a budget on a live campaign or pausing a running ad set executes the moment the agent calls the tool. Kepra's write tools stop before that, every time, and name the exact call for a human to approve or decline.
Yes, and it is a reasonable setup. They authenticate separately and neither blocks the other. In practice the connector is convenient for ad-hoc questions inside your chat client, while Kepra owns the numbers that decide budget – profit after COGS across Meta, Google, Shopify and Stripe – and the approval trail behind any change that follows from them.
Because generated API calls fail in expensive ways: a wrong account id, a misplaced zero in a budget, a paused campaign that should have been an ad set. Typed tools make those mistakes structurally impossible, and the approval gate catches the ones judgement can still make.
No. Read tools run freely to build the analysis; every write stops at an approval naming the exact change. That commitment is in our terms, not in a toggle.
Kepra is in private development. The demo is open and shows the full loop on sample data; the waitlist is the way in when access opens.
Campaign structure, spend and insights – what the ads_read permission covers. Kepra matches that against your orders to judge campaigns on profit after COGS rather than platform-reported ROAS.
Safer than the alternatives, if it is done through typed tools: the agent cannot compose raw API calls, every write carries hard bounds and stops at a human approval, and every executed change is logged with one-click revert. The unsafe versions are the other ones – pasting API keys into a chat, or a browser agent clicking around Ads Manager unsupervised.
They do different jobs and can coexist. Advantage+ optimises delivery inside Meta's own attribution and goals; it will never know your COGS or whether customers return. An MCP setup judges from profit and executes decisions you approve. Many accounts run Advantage+ for delivery and use the profit verdicts to decide what deserves budget at all.
The demo is open – no signup. AI Actions shows a proposal, the evidence, and the approval step exactly as it ships.
Also running Google Ads? Google Ads MCP →