MCP security

Keep AI access explicit, read-only, and revocable.

Adstudio MCP uses OAuth and a personal connection. It reaches every workspace you are a member of now and in the future; platform Read permissions apply across those memberships while your role remains the boundary.

A personal connection is deliberate at every boundary.

Personal OAuth

Workspace membership

Platform Read

Selected account

Role bounds are retained. Access is read-only and can be revoked in Settings → MCP.
Google Ads live Meta Ads live OAuth Read-only Source-labelled

The connection has visible gates

The endpoint is public. Your permission is not.

OAuth connects the client without asking you to paste an access token into chat. Discover active integrations, then select the workspace, platform, and account for each scoped read. Google Ads and Meta Ads are live providers today.

Every public MCP tool is read-only. To revoke access, remove your personal connection in Adstudio Settings → MCP, then remove the connector from your AI client. If a returned scope looks wrong, stop using the connection and contact Support.

Grounded work, less context switching

Context that survives the question.

01

OAuth instead of pasted credentials

The client connection is completed through OAuth; the public endpoint URL itself is not a secret or credential.

02

Membership and role remain in force

A personal connection spans workspaces you are a member of now and in the future, but never exceeds your role or platform Read permission.

03

Provenance makes the boundary reviewable

Responses name provider and selected account, with period, currency, attribution, freshness, truncation, and unresolved coverage where relevant.

Connection, with boundaries

Three deliberate steps.

A useful answer starts with a connection whose scope is clear.

  1. 01

    Create a personal connection

    In Adstudio Settings → MCP, create your personal connection.

  2. 02

    Enable platform Read

    Choose Google Ads and/or Meta Ads. Your Adstudio role remains the boundary.

  3. 03

    Select before you ask

    Discover accounts, then explicitly name the workspace, platform, and account for a scoped read.

FAQ

Security and access, plainly stated.

Remove your personal MCP connection in Adstudio Settings → MCP, then remove the connector from your AI client. If a returned scope looks wrong, stop using the connection and contact Support.

Use the public MCP endpoint, https://useadstudio.com/api/mcp, in your compatible AI client and complete OAuth. Start with account discovery before an account-scoped question.

Google Ads and Meta Ads are live today. The MCP compares separate, source-labelled reads; it does not treat provider metrics, currencies, attribution models, or periods as interchangeable.

Nothing. Every current public MCP tool is read-only. It does not create, edit, pause, or delete campaigns, ads, budgets, audiences, or other advertising objects.

Start with account discovery, then explicitly choose one workspace, platform, and account for every scoped call. The server never guesses an account on your behalf.

A personal connection reaches workspaces you are a member of now and in the future. Platform Read permission applies across those memberships and never exceeds your Adstudio role.

Adstudio MCP

Bring accountable answers into the conversation.

Connect once, choose the account you mean, and keep the source context attached to every result.

Privacy Policy·Terms of Service