Meta ads MCP server rules: cap what an AI agent can do
Meta's ads MCP rules deny an agent action on one ad account or catalog, such as budget increases above 20%. What the rule fields are and where Sume adds a cap.

A Meta ads MCP server rule denies one specific agent action on one ad account or product catalog. Meta's example is to deny any budget increase above 20%, or to deny delivery status changes. You set rules in Meta Business Suite settings, or through a Marketing API endpoint for many assets at once.
The rule model below comes from Meta's Rules best practices page, read 2026-09-29. Meta says the feature is in limited availability. Sume is not connected to Meta ads; the last section covers the spend gates on Sume's side of an agent workflow, from MCP tools and gates.
Which actions can a rule deny?
Each ad account rule pairs an action with a trigger_type. The three budget triggers also accept an optional budget_dimension of daily, lifetime or both, which defaults to both.
| Action | Trigger | What the rule denies |
|---|---|---|
create_campaign | always | Creating campaigns |
create_ad_set | always | Creating ad sets |
create_ad | always | Creating ads |
edit_budget | percentage_change | Budget increases above a percentage (max_percentage) |
edit_budget | absolute_change | Budget increases above an amount (max_amount_cents) |
edit_budget | absolute_max | Budgets above a ceiling (max_value_cents) |
edit_targeting | always | Targeting and audience changes |
edit_creative | always | Creative changes |
edit_status | always | Delivery status changes |
all | always | Every agent action on the account |
How do I set a 20% budget rule by API?
Meta's example posts one rule to the ad account's ads_mcp_rules path on ads-api.facebook.com, version v25.0. Send metadata as a JSON string inside a form POST.
curl -sS -X POST \
"https://ads-api.facebook.com/v25.0/marketing-api/businesses/<BUSINESS_ID>/accounts/act_<AD_ACCOUNT_ID>/ads_mcp_rules" \
-d "action=edit_budget" \
-d "trigger_type=percentage_change" \
-d "status=active" \
-d 'metadata={"max_percentage":20,"budget_dimension":"both"}' \
-d "access_token=$META_ACCESS_TOKEN"How do I turn a rule off, and what fails?
There is no DELETE verb. Post the same rule again with status=paused.
- Writes are keyed on the
(action, trigger_type)pair, so posting the same pair again updates the rule instead of duplicating it. - On an ad account a paused rule is kept and still returned with
statusofpaused; on a catalog it is removed. - If your business is not enrolled, the ad account endpoint returns error code 10 and the catalog endpoint returns HTTP 403.
- There is no batch endpoint: one call per rule per asset.
- The two endpoints return different error shapes: Graph-style for ad accounts, RFC 7807 problem details for catalogs.
What caps the Sume side of the same agent?
Meta's rules only govern Meta actions. If the agent also generates media through Sume's hosted MCP, Sume's paid tools take an optional max_spend_usd, which Sume enforces only when you pass it, and an optional dry_run=true that previews admission and cost without submitting the job. Paid calls also require an idempotency_key.
Meta's own MCP page adds a general warning: an agent can call anything its granted scopes allow, including in response to instructions hidden in tool output, so keep an app at the Read scope unless the agent needs to make changes. The spend-cap side for Sume Formats is in Format run generation spend cap.
Sources
Related posts
More in Integrations
- n8n Agents: give an agent a Sume video workflow
n8n's new Agents can use workflows and MCP servers as tools. A workflow that calls Sume keeps the API key out of the agent's hands.
- n8n AI agent HTTP Request tool for video jobs
Attach the HTTP Request node to an n8n AI agent as a tool and use Optimize Response to hand the model only a job's status and result URL.
- n8n error workflow: make it fire when an API job fails
An n8n error workflow runs only when an execution fails. A remote job that ends failed is a normal 200 read, so check its status and throw with Stop And Error.
- n8n HTTP Request timeout: what to do when a job takes minutes
The n8n HTTP Request node's Timeout option aborts slow responses. For jobs that take minutes, submit async, then poll with a Wait node.
Written by Sume