Facebook Business Manager · OAuth Scopes
Facebook Business Manager OAuth Scopes
OAuth 2.0
searched
Facebook Business Manager uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
AdvertisingAnalyticsBusiness ManagementMarketingSocial-MediaMessagingCommerceAgentsMCPWebhook
Scopes: 0
Flows:
Method: searched
Scopes (0)
Facebook Business Manager implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.
📄 Provider scope reference: https://developers.facebook.com/docs/permissions
Source
OAuth Scopes
generated: '2026-08-13'
method: searched
source: https://developers.facebook.com/docs/permissions
docs: https://developers.facebook.com/docs/permissions
specification: API Commons OAuthScopes
specificationVersion: '0.1'
provider: Facebook Business Manager
providerId: facebook-business-manager
description: >-
Meta calls OAuth scopes "permissions" and publishes them in a single Permissions Reference for Meta
Technologies APIs. Permissions are app-user-granted and gated by App Review; Advanced Access to any
permission additionally requires Business Verification. The list below was read from that reference page on
2026-08-13, plus the machine-readable scopes_supported arrays served by Meta's two MCP servers at
/.well-known/oauth-protected-resource/{ads,devtools}.
Note: derive-oauth-scopes.py produced nothing for this repo because the OpenAPI files in openapi/ declare a
bearer http securityScheme rather than an oauth2 scheme with a scopes map — the scopes below are searched
from the docs, not derived from a spec.
access_tiers:
- name: Standard Access
description: Default tier. Applies to data the app owns or manages. No App Review required for most permissions.
- name: Advanced Access
description: >-
Required to access data owned by other businesses/users. Requires App Review, Business Verification,
and (for permissions touching user data) an annual Data Use Checkup and, for advanced permissions, a
Data Protection Assessment.
policies:
- name: 90-day regrant
description: If an app does not use a permission for 90 days, the app user must grant it again.
- name: Granular consent
description: App users may grant or deny any subset of the permissions an app requests.
- name: Least privilege
description: >-
Meta names over-requesting as a common cause of App Review rejection ("Only select permissions that
your app needs to function as intended").
mcp_scopes:
- server: https://mcp.facebook.com/ads
source: https://mcp.facebook.com/.well-known/oauth-protected-resource/ads
method: probed
scopes:
- ads_management
- ads_read
- catalog_management
- business_management
- pages_show_list
- instagram_basic
- ads_mcp_management
- server: https://mcp.facebook.com/devtools
source: https://mcp.facebook.com/.well-known/oauth-protected-resource/devtools
method: probed
scopes:
- developer_tools_mcp_app_read
- developer_tools_mcp_app_management
scopes:
- name: public_profile
group: default
description: Default permission granted with every Facebook Login. Basic profile fields.
- name: email
group: default
description: The app user's primary email address.
- name: ads_management
group: ads
description: >-
Read and manage the ad accounts the app owns or has been granted access to. Programmatically create
campaigns, manage ads, fetch ad metrics. Dependencies: pages_read_engagement, pages_show_list.
- name: ads_read
group: ads
description: Read-only access to ads performance data for owned or granted ad accounts.
- name: ads_mcp_management
group: ads
description: >-
Access the Meta ads Model Context Protocol (MCP) server and enable AI agents to interact with Meta Ads
on behalf of advertisers — create and manage campaigns, retrieve insights and reporting, and manage
business assets like catalogs, ad accounts and pixels.
- name: attribution_read
group: ads
description: Read Meta attribution and measurement data.
- name: read_insights
group: insights
description: Read Insights data for Pages, apps and web domains the app user owns.
- name: read_audience_network_insights
group: insights
description: Read Audience Network insights for apps the app user administers.
- name: business_management
group: business
description: Read and write Business Manager assets, users and asset assignments.
- name: catalog_management
group: commerce
description: Create, read, update and delete product catalogs owned by a business.
- name: commerce_manage_accounts
group: commerce
description: Manage commerce accounts for a business.
- name: commerce_account_manage_orders
group: commerce
description: Manage orders on a commerce account.
- name: commerce_account_read_orders
group: commerce
description: Read orders on a commerce account.
- name: commerce_account_read_reports
group: commerce
description: Read commerce account reports.
- name: commerce_account_read_settings
group: commerce
description: Read commerce account settings.
- name: leads_retrieval
group: ads
description: Download lead data generated by Lead Ads forms on Pages the app user manages.
- name: pages_show_list
group: pages
description: List the Pages the app user manages.
- name: pages_read_engagement
group: pages
description: Read content, engagement and metadata on Pages the app user manages.
- name: pages_read_user_content
group: pages
description: Read user-generated content (posts, comments, ratings) on managed Pages.
- name: pages_manage_posts
group: pages
description: Create, edit and delete posts on managed Pages.
- name: pages_manage_engagement
group: pages
description: Create, edit and delete comments and likes on managed Pages.
- name: pages_manage_metadata
group: pages
description: Manage Page settings and subscribe/unsubscribe apps to Page webhooks.
- name: pages_manage_ads
group: pages
description: Manage ads associated with a Page.
- name: pages_manage_cta
group: pages
description: Manage the call-to-action button on a Page.
- name: pages_manage_instant_articles
group: pages
description: Manage Instant Articles on behalf of Pages the app user administers.
- name: pages_messaging
group: messaging
description: Send and receive messages through a Page (Messenger Platform).
- name: pages_utility_messaging
group: messaging
description: Send utility (non-promotional) messages through a Page.
- name: pages_events
group: pages
description: Log Page events for advertising and analytics.
- name: pages_user_gender
group: pages
description: Read the gender of a user interacting with a managed Page.
- name: pages_user_locale
group: pages
description: Read the locale of a user interacting with a managed Page.
- name: pages_user_timezone
group: pages
description: Read the time zone of a user interacting with a managed Page.
- name: publish_video
group: media
description: Publish live and on-demand video to a Page, group or user.
- name: instagram_basic
group: instagram
description: Read basic metadata and media for an Instagram Business or Creator account.
- name: instagram_business_basic
group: instagram
description: Basic access under Business Login for Instagram.
- name: instagram_content_publish
group: instagram
description: Publish content to an Instagram Business account.
- name: instagram_business_content_publish
group: instagram
description: Publish content under Business Login for Instagram.
- name: instagram_manage_comments
group: instagram
description: Read and manage comments on Instagram media.
- name: instagram_business_manage_comments
group: instagram
description: Manage comments under Business Login for Instagram.
- name: instagram_manage_insights
group: instagram
description: Read insights for an Instagram Business account and its media.
- name: instagram_manage_messages
group: instagram
description: Send and receive Instagram Direct messages.
- name: instagram_business_manage_messages
group: instagram
description: Messaging under Business Login for Instagram.
- name: instagram_manage_events
group: instagram
description: Log events for an Instagram Business account.
- name: instagram_manage_upcoming_events
group: instagram
description: Manage upcoming events on an Instagram Business account.
- name: instagram_manage_contents
group: instagram
description: Manage content on an Instagram Business account.
- name: instagram_manage_engagement
group: instagram
description: Manage engagement on an Instagram Business account.
- name: instagram_shopping_tag_products
group: instagram
description: Tag products from a catalog in Instagram media.
- name: instagram_branded_content_brand
group: instagram
description: Branded content access on the brand side.
- name: instagram_branded_content_ads_brand
group: instagram
description: Run partnership ads against creator branded content.
- name: instagram_branded_content_creator
group: instagram
description: Branded content access on the creator side.
- name: instagram_creator_marketplace_discovery
group: instagram
description: Discover creators in the Instagram Creator Marketplace.
- name: instagram_creator_marketplace_messaging
group: instagram
description: Message creators in the Instagram Creator Marketplace.
- name: whatsapp_business_management
group: whatsapp
description: Manage WhatsApp Business Accounts, phone numbers, templates and settings.
- name: whatsapp_business_messaging
group: whatsapp
description: Send and receive messages through the WhatsApp Business Platform Cloud API.
- name: whatsapp_business_manage_events
group: whatsapp
description: Log WhatsApp business events.
- name: threads_basic
group: threads
description: Read basic profile and media data for a Threads account.
- name: threads_business_basic
group: threads
description: Basic access for Threads business accounts.
- name: threads_content_publish
group: threads
description: Publish posts to Threads.
- name: threads_delete
group: threads
description: Delete Threads posts.
- name: threads_read_replies
group: threads
description: Read replies to Threads posts.
- name: threads_manage_replies
group: threads
description: Hide, unhide and reply to Threads replies.
- name: threads_manage_mentions
group: threads
description: Read and respond to Threads mentions.
- name: threads_manage_insights
group: threads
description: Read Threads media and account insights.
- name: threads_keyword_search
group: threads
description: Search Threads by keyword.
- name: threads_location_tagging
group: threads
description: Tag locations on Threads posts.
- name: threads_profile_discovery
group: threads
description: Discover public Threads profiles.
- name: threads_share_to_instagram
group: threads
description: Share Threads content to Instagram.
- name: threads_user_id
group: threads
description: Access the Threads user id.
- name: manage_app_solutions
group: apps
description: Manage app solutions on behalf of a business.
- name: manage_fundraisers
group: social
description: Create and manage fundraisers on behalf of the app user.
- name: user_age_range
group: user
description: The app user's age range bucket.
- name: user_birthday
group: user
description: The app user's birthday.
- name: user_friends
group: user
description: The app user's friends who also use the app.
- name: user_gender
group: user
description: The app user's gender.
- name: user_hometown
group: user
description: The app user's hometown.
- name: user_likes
group: user
description: Pages the app user has liked.
- name: user_link
group: user
description: The URL of the app user's Facebook profile.
- name: user_location
group: user
description: The app user's current city.
- name: user_messenger_contact
group: user
description: Contact the app user on Messenger following a defined interaction.
- name: user_photos
group: user
description: Photos the app user has uploaded or is tagged in.
- name: user_posts
group: user
description: Posts on the app user's timeline.
- name: user_videos
group: user
description: Videos the app user has uploaded or is tagged in.
- name: gaming_profile
group: gaming
description: Gaming-scoped profile access.
- name: gaming_user_locale
group: gaming
description: Gaming-scoped locale access.
- name: developer_tools_mcp_app_read
group: mcp
description: >-
Read access for the Meta Devtools MCP server. Sourced from
https://mcp.facebook.com/.well-known/oauth-protected-resource/devtools, not from the Permissions
Reference page.
- name: developer_tools_mcp_app_management
group: mcp
description: >-
Management access for the Meta Devtools MCP server. Sourced from
https://mcp.facebook.com/.well-known/oauth-protected-resource/devtools.
scope_count: 82
completeness_note: >-
Meta's Permissions Reference is paginated A-Z in a partly client-rendered layout. The list above is what
was legible in the served markup on 2026-08-13 plus the two MCP servers' machine-readable scope arrays.
It is a large and representative sample, not a guaranteed exhaustive enumeration; treat
https://developers.facebook.com/docs/permissions as canonical.
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com