Meta ads MCP server rules: cap what an AI agent can do

Meta's ads MCP rules deny an agent action on one ad account or catalog, such as budget increases above 20%. What the rule fields are and where Sume adds a cap.

5 min readSume
All posts

A Meta ads MCP server rule denies one specific agent action on one ad account or product catalog. Meta's example is to deny any budget increase above 20%, or to deny delivery status changes. You set rules in Meta Business Suite settings, or through a Marketing API endpoint for many assets at once.

The rule model below comes from Meta's Rules best practices page, read 2026-09-29. Meta says the feature is in limited availability. Sume is not connected to Meta ads; the last section covers the spend gates on Sume's side of an agent workflow, from MCP tools and gates.

Which actions can a rule deny?

Each ad account rule pairs an action with a trigger_type. The three budget triggers also accept an optional budget_dimension of daily, lifetime or both, which defaults to both.

From Meta's Rules best practices, read 2026-09-29.
ActionTriggerWhat the rule denies
create_campaignalwaysCreating campaigns
create_ad_setalwaysCreating ad sets
create_adalwaysCreating ads
edit_budgetpercentage_changeBudget increases above a percentage (max_percentage)
edit_budgetabsolute_changeBudget increases above an amount (max_amount_cents)
edit_budgetabsolute_maxBudgets above a ceiling (max_value_cents)
edit_targetingalwaysTargeting and audience changes
edit_creativealwaysCreative changes
edit_statusalwaysDelivery status changes
allalwaysEvery agent action on the account

How do I set a 20% budget rule by API?

Meta's example posts one rule to the ad account's ads_mcp_rules path on ads-api.facebook.com, version v25.0. Send metadata as a JSON string inside a form POST.

curl -sS -X POST \
  "https://ads-api.facebook.com/v25.0/marketing-api/businesses/<BUSINESS_ID>/accounts/act_<AD_ACCOUNT_ID>/ads_mcp_rules" \
  -d "action=edit_budget" \
  -d "trigger_type=percentage_change" \
  -d "status=active" \
  -d 'metadata={"max_percentage":20,"budget_dimension":"both"}' \
  -d "access_token=$META_ACCESS_TOKEN"

How do I turn a rule off, and what fails?

There is no DELETE verb. Post the same rule again with status=paused.

  • Writes are keyed on the (action, trigger_type) pair, so posting the same pair again updates the rule instead of duplicating it.
  • On an ad account a paused rule is kept and still returned with status of paused; on a catalog it is removed.
  • If your business is not enrolled, the ad account endpoint returns error code 10 and the catalog endpoint returns HTTP 403.
  • There is no batch endpoint: one call per rule per asset.
  • The two endpoints return different error shapes: Graph-style for ad accounts, RFC 7807 problem details for catalogs.

What caps the Sume side of the same agent?

Meta's rules only govern Meta actions. If the agent also generates media through Sume's hosted MCP, Sume's paid tools take an optional max_spend_usd, which Sume enforces only when you pass it, and an optional dry_run=true that previews admission and cost without submitting the job. Paid calls also require an idempotency_key.

Meta's own MCP page adds a general warning: an agent can call anything its granted scopes allow, including in response to instructions hidden in tool output, so keep an app at the Read scope unless the agent needs to make changes. The spend-cap side for Sume Formats is in Format run generation spend cap.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume