Facebook Business Manager · OAuth Scopes

Facebook Business Manager OAuth Scopes

OAuth 2.0 searched

Facebook Business Manager uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

AdvertisingAnalyticsBusiness ManagementMarketingSocial-MediaMessagingCommerceAgentsMCPWebhook
Scopes: 0 Flows: Method: searched

Scopes (0)

Facebook Business Manager implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.

Source

OAuth Scopes

Raw ↑
generated: '2026-08-13'
method: searched
source: https://developers.facebook.com/docs/permissions
docs: https://developers.facebook.com/docs/permissions
specification: API Commons OAuthScopes
specificationVersion: '0.1'
provider: Facebook Business Manager
providerId: facebook-business-manager
description: >-
  Meta calls OAuth scopes "permissions" and publishes them in a single Permissions Reference for Meta
  Technologies APIs. Permissions are app-user-granted and gated by App Review; Advanced Access to any
  permission additionally requires Business Verification. The list below was read from that reference page on
  2026-08-13, plus the machine-readable scopes_supported arrays served by Meta's two MCP servers at
  /.well-known/oauth-protected-resource/{ads,devtools}.
  Note: derive-oauth-scopes.py produced nothing for this repo because the OpenAPI files in openapi/ declare a
  bearer http securityScheme rather than an oauth2 scheme with a scopes map — the scopes below are searched
  from the docs, not derived from a spec.
access_tiers:
  - name: Standard Access
    description: Default tier. Applies to data the app owns or manages. No App Review required for most permissions.
  - name: Advanced Access
    description: >-
      Required to access data owned by other businesses/users. Requires App Review, Business Verification,
      and (for permissions touching user data) an annual Data Use Checkup and, for advanced permissions, a
      Data Protection Assessment.
policies:
  - name: 90-day regrant
    description: If an app does not use a permission for 90 days, the app user must grant it again.
  - name: Granular consent
    description: App users may grant or deny any subset of the permissions an app requests.
  - name: Least privilege
    description: >-
      Meta names over-requesting as a common cause of App Review rejection ("Only select permissions that
      your app needs to function as intended").
mcp_scopes:
  - server: https://mcp.facebook.com/ads
    source: https://mcp.facebook.com/.well-known/oauth-protected-resource/ads
    method: probed
    scopes:
      - ads_management
      - ads_read
      - catalog_management
      - business_management
      - pages_show_list
      - instagram_basic
      - ads_mcp_management
  - server: https://mcp.facebook.com/devtools
    source: https://mcp.facebook.com/.well-known/oauth-protected-resource/devtools
    method: probed
    scopes:
      - developer_tools_mcp_app_read
      - developer_tools_mcp_app_management
scopes:
  - name: public_profile
    group: default
    description: Default permission granted with every Facebook Login. Basic profile fields.
  - name: email
    group: default
    description: The app user's primary email address.
  - name: ads_management
    group: ads
    description: >-
      Read and manage the ad accounts the app owns or has been granted access to. Programmatically create
      campaigns, manage ads, fetch ad metrics. Dependencies: pages_read_engagement, pages_show_list.
  - name: ads_read
    group: ads
    description: Read-only access to ads performance data for owned or granted ad accounts.
  - name: ads_mcp_management
    group: ads
    description: >-
      Access the Meta ads Model Context Protocol (MCP) server and enable AI agents to interact with Meta Ads
      on behalf of advertisers — create and manage campaigns, retrieve insights and reporting, and manage
      business assets like catalogs, ad accounts and pixels.
  - name: attribution_read
    group: ads
    description: Read Meta attribution and measurement data.
  - name: read_insights
    group: insights
    description: Read Insights data for Pages, apps and web domains the app user owns.
  - name: read_audience_network_insights
    group: insights
    description: Read Audience Network insights for apps the app user administers.
  - name: business_management
    group: business
    description: Read and write Business Manager assets, users and asset assignments.
  - name: catalog_management
    group: commerce
    description: Create, read, update and delete product catalogs owned by a business.
  - name: commerce_manage_accounts
    group: commerce
    description: Manage commerce accounts for a business.
  - name: commerce_account_manage_orders
    group: commerce
    description: Manage orders on a commerce account.
  - name: commerce_account_read_orders
    group: commerce
    description: Read orders on a commerce account.
  - name: commerce_account_read_reports
    group: commerce
    description: Read commerce account reports.
  - name: commerce_account_read_settings
    group: commerce
    description: Read commerce account settings.
  - name: leads_retrieval
    group: ads
    description: Download lead data generated by Lead Ads forms on Pages the app user manages.
  - name: pages_show_list
    group: pages
    description: List the Pages the app user manages.
  - name: pages_read_engagement
    group: pages
    description: Read content, engagement and metadata on Pages the app user manages.
  - name: pages_read_user_content
    group: pages
    description: Read user-generated content (posts, comments, ratings) on managed Pages.
  - name: pages_manage_posts
    group: pages
    description: Create, edit and delete posts on managed Pages.
  - name: pages_manage_engagement
    group: pages
    description: Create, edit and delete comments and likes on managed Pages.
  - name: pages_manage_metadata
    group: pages
    description: Manage Page settings and subscribe/unsubscribe apps to Page webhooks.
  - name: pages_manage_ads
    group: pages
    description: Manage ads associated with a Page.
  - name: pages_manage_cta
    group: pages
    description: Manage the call-to-action button on a Page.
  - name: pages_manage_instant_articles
    group: pages
    description: Manage Instant Articles on behalf of Pages the app user administers.
  - name: pages_messaging
    group: messaging
    description: Send and receive messages through a Page (Messenger Platform).
  - name: pages_utility_messaging
    group: messaging
    description: Send utility (non-promotional) messages through a Page.
  - name: pages_events
    group: pages
    description: Log Page events for advertising and analytics.
  - name: pages_user_gender
    group: pages
    description: Read the gender of a user interacting with a managed Page.
  - name: pages_user_locale
    group: pages
    description: Read the locale of a user interacting with a managed Page.
  - name: pages_user_timezone
    group: pages
    description: Read the time zone of a user interacting with a managed Page.
  - name: publish_video
    group: media
    description: Publish live and on-demand video to a Page, group or user.
  - name: instagram_basic
    group: instagram
    description: Read basic metadata and media for an Instagram Business or Creator account.
  - name: instagram_business_basic
    group: instagram
    description: Basic access under Business Login for Instagram.
  - name: instagram_content_publish
    group: instagram
    description: Publish content to an Instagram Business account.
  - name: instagram_business_content_publish
    group: instagram
    description: Publish content under Business Login for Instagram.
  - name: instagram_manage_comments
    group: instagram
    description: Read and manage comments on Instagram media.
  - name: instagram_business_manage_comments
    group: instagram
    description: Manage comments under Business Login for Instagram.
  - name: instagram_manage_insights
    group: instagram
    description: Read insights for an Instagram Business account and its media.
  - name: instagram_manage_messages
    group: instagram
    description: Send and receive Instagram Direct messages.
  - name: instagram_business_manage_messages
    group: instagram
    description: Messaging under Business Login for Instagram.
  - name: instagram_manage_events
    group: instagram
    description: Log events for an Instagram Business account.
  - name: instagram_manage_upcoming_events
    group: instagram
    description: Manage upcoming events on an Instagram Business account.
  - name: instagram_manage_contents
    group: instagram
    description: Manage content on an Instagram Business account.
  - name: instagram_manage_engagement
    group: instagram
    description: Manage engagement on an Instagram Business account.
  - name: instagram_shopping_tag_products
    group: instagram
    description: Tag products from a catalog in Instagram media.
  - name: instagram_branded_content_brand
    group: instagram
    description: Branded content access on the brand side.
  - name: instagram_branded_content_ads_brand
    group: instagram
    description: Run partnership ads against creator branded content.
  - name: instagram_branded_content_creator
    group: instagram
    description: Branded content access on the creator side.
  - name: instagram_creator_marketplace_discovery
    group: instagram
    description: Discover creators in the Instagram Creator Marketplace.
  - name: instagram_creator_marketplace_messaging
    group: instagram
    description: Message creators in the Instagram Creator Marketplace.
  - name: whatsapp_business_management
    group: whatsapp
    description: Manage WhatsApp Business Accounts, phone numbers, templates and settings.
  - name: whatsapp_business_messaging
    group: whatsapp
    description: Send and receive messages through the WhatsApp Business Platform Cloud API.
  - name: whatsapp_business_manage_events
    group: whatsapp
    description: Log WhatsApp business events.
  - name: threads_basic
    group: threads
    description: Read basic profile and media data for a Threads account.
  - name: threads_business_basic
    group: threads
    description: Basic access for Threads business accounts.
  - name: threads_content_publish
    group: threads
    description: Publish posts to Threads.
  - name: threads_delete
    group: threads
    description: Delete Threads posts.
  - name: threads_read_replies
    group: threads
    description: Read replies to Threads posts.
  - name: threads_manage_replies
    group: threads
    description: Hide, unhide and reply to Threads replies.
  - name: threads_manage_mentions
    group: threads
    description: Read and respond to Threads mentions.
  - name: threads_manage_insights
    group: threads
    description: Read Threads media and account insights.
  - name: threads_keyword_search
    group: threads
    description: Search Threads by keyword.
  - name: threads_location_tagging
    group: threads
    description: Tag locations on Threads posts.
  - name: threads_profile_discovery
    group: threads
    description: Discover public Threads profiles.
  - name: threads_share_to_instagram
    group: threads
    description: Share Threads content to Instagram.
  - name: threads_user_id
    group: threads
    description: Access the Threads user id.
  - name: manage_app_solutions
    group: apps
    description: Manage app solutions on behalf of a business.
  - name: manage_fundraisers
    group: social
    description: Create and manage fundraisers on behalf of the app user.
  - name: user_age_range
    group: user
    description: The app user's age range bucket.
  - name: user_birthday
    group: user
    description: The app user's birthday.
  - name: user_friends
    group: user
    description: The app user's friends who also use the app.
  - name: user_gender
    group: user
    description: The app user's gender.
  - name: user_hometown
    group: user
    description: The app user's hometown.
  - name: user_likes
    group: user
    description: Pages the app user has liked.
  - name: user_link
    group: user
    description: The URL of the app user's Facebook profile.
  - name: user_location
    group: user
    description: The app user's current city.
  - name: user_messenger_contact
    group: user
    description: Contact the app user on Messenger following a defined interaction.
  - name: user_photos
    group: user
    description: Photos the app user has uploaded or is tagged in.
  - name: user_posts
    group: user
    description: Posts on the app user's timeline.
  - name: user_videos
    group: user
    description: Videos the app user has uploaded or is tagged in.
  - name: gaming_profile
    group: gaming
    description: Gaming-scoped profile access.
  - name: gaming_user_locale
    group: gaming
    description: Gaming-scoped locale access.
  - name: developer_tools_mcp_app_read
    group: mcp
    description: >-
      Read access for the Meta Devtools MCP server. Sourced from
      https://mcp.facebook.com/.well-known/oauth-protected-resource/devtools, not from the Permissions
      Reference page.
  - name: developer_tools_mcp_app_management
    group: mcp
    description: >-
      Management access for the Meta Devtools MCP server. Sourced from
      https://mcp.facebook.com/.well-known/oauth-protected-resource/devtools.
scope_count: 82
completeness_note: >-
  Meta's Permissions Reference is paginated A-Z in a partly client-rendered layout. The list above is what
  was legible in the served markup on 2026-08-13 plus the two MCP servers' machine-readable scope arrays.
  It is a large and representative sample, not a guaranteed exhaustive enumeration; treat
  https://developers.facebook.com/docs/permissions as canonical.
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com