Meta Ads
Org-level connection
Meta Ads is connected once at the org level by an admin. The credential is shared across all groups that have been granted access — individual team members don't need to connect their own accounts.
Getting your API key
Meta only opens its Ads API to an app you own, so each organization creates its own Meta app once. The app, System User, and ad account must all live under the SAME Business Manager.
Create your app: developers.facebook.com → My Apps → Create App → "Business" type, owned by your Business portfolio. Open it and add the "Marketing API" product.
In Business Settings → Users → System Users → Add, create a System User with the Admin role.
Assign assets to that System User: your ad account (grant at least "View performance") AND the app from step 1.
On the System User, click "Generate New Token" → select your app → expiration "Never" → add ads_read (add ads_management only if you want writeback). Copy the token and paste it below.
No Meta App Review is required to read your own ad accounts. If a token is rejected with "API access blocked", the usual cause is that the app, System User, and ad account are not all under the same Business Manager.
Ready to connect?
Sign in to On Belay and open the Integrations page to add Meta Ads.
Permissions (scopes)
These are the data scopes On Belay can be granted for Meta Ads. Your org admin controls which scopes are enabled per group.
| Scope | Description | Access |
|---|---|---|
ads_read | Read ads | Read only |
ads_management | Write ads | Read / Write |
ads_management | Read campaigns | Read only |
ads_management | Write campaigns | Read / Write |
insights | Read insights | Read only |
business_management | Read audiences | Read only |
business_management | Write audiences | Read / Write |
Troubleshooting
"Invalid API key" or "Unauthorized" error
Connected but Claude can't access data
The key expires or stops working
Still stuck? We're happy to help.
Contact support →