A plain-language overview of the access we'll request, what each permission lets us do, who on your team should connect, and what to expect during setup.
What to expect
Connecting takes a couple of minutes. When you add the Meta Ads integration in Medialake, you'll be redirected to the official Facebook login screen, then a consent screen ("Review MedialakeAI's access request") describing the access in Meta's own words — you'll see "Access your Facebook ads and related stats", which is the ads_read permission explained in the table below. You approve it yourself and can revoke our access at any time. We never see or store your password — the login happens entirely on Meta's site, and once you approve you're returned to Medialake.
We follow the principle of least privilege: we only request the access the work actually needs. MedialakeAI is a reporting and media platform — we never create, edit, pause, or spend anything in your ad account. All data is read through Meta's official Marketing API (Graph API v21.0).
You Medialake Meta │ connect source │ │ │────────────────────────▶│ │ │ redirect to Meta │ │ │◀────────────────────────│ │ │ log in & grant access │ │ │──────────────────────────────────────────────────▶│ │ redirect with code │ │ │◀──────────────────────────────────────────────────│ │ │ exchange code │ │ │────────────────────────▶│ │ │ long-lived token │ │ │◀────────────────────────│ │ source authorized │ │ │◀────────────────────────│ │
Verifying it's really us
On the consent screen, check that the app requesting access is:
App name: MedialakeAI
App ID:
714235083542447Developer / business: Medialake AI (verified by Meta)
If the app name doesn't match, stop and contact us. Never approve a Meta connection request you weren't expecting.
Who should do the connecting
The connection is tied to the person who logs in (authorized with a Meta User access token), not just your business. Please have it done by someone who:
Has a role on the ad account(s) — at minimum View performance (Analyst), which is all we need; Admin or Advertiser (Manage campaigns) work too. Check under Business Settings → People or per account under Business Settings → Ad accounts.
Is a permanent member of your team. If the person who authorized us leaves your company or loses their Meta access, the connection expires and someone else will need to reconnect.
Their personal Facebook login is used only to authorize the connection — we get access to your ad accounts, never their personal profile, friends, or messages.
Limiting what we can access
We inherit exactly the connecting person's access — nothing more, enforced by Meta on every request. So to keep the connection as narrow as possible, an admin can grant a team member view-only access (View performance / Analyst) to only the ad accounts in scope, and have that person connect. We then can't see any other account, independently of the permissions requested.
You choose what we sync
Meta's consent screen doesn't include an account picker — you'll simply see the access request. Once you approve and are redirected back to Medialake, you select the specific ad account(s) you'd like us to sync. Either way, Medialake only ever has access to the ad accounts the connecting Facebook user is assigned to — accounts outside their access are invisible to us.
The permissions we request
We offer two connection configurations. Which one you're on determines exactly what appears on the consent screen.
Config: read-only, minimal permissions (recommended)
The default configuration — every client connects with this unless they've asked for more.
Permission (scope) | What it lets us do | How we use it |
See the name and profile photo of the person connecting — just to confirm who authorized. Granted automatically with any Facebook login. | READ ONLY | |
View campaigns, ad sets, ads, and performance metrics (impressions, clicks, spend, conversions). Powers dashboards and reports. | READ ONLY |
Both permissions are read-only — nothing in your account can be created, edited, paused, deleted, or spent by us.
Config: business management (optional, on request)
Everything above, plus:
Permission (scope) | What it lets us do | How we use it |
List the ad accounts owned by your Business Manager — including accounts the connecting person hasn't been individually assigned to. | READ ONLY (see note) |
Useful if you'd rather have us discover every business-owned ad account automatically than assign each one to the connecting person. Meta labels this permission read + write, but we only use it to list accounts — no changes are ever made to your Business Manager. Reach out to [email protected] to enable this configuration.
Meta's own description of every permission is in its Permissions Reference.
Verified by Meta
Our app doesn't get these permissions just by asking. Each one was individually approved through Meta's App Review, where we justify and demonstrate exactly how it's used; Medialake AI is a Meta-verified business; and every year Meta requires us to recertify how each permission is used through its Data Use Checkup. Unused or unjustified permissions are revoked by Meta.
What we can't see or do
Regardless of which permissions you grant, we cannot:
See or store your password, or log in as you
Access personal profiles, friend lists, or private messages
Add or change payment methods, or spend money on your account
Staying connected
Meta access tokens expire periodically (roughly every 60 days) and Meta does not provide refresh tokens, so an expired connection can't be renewed in the background. Tokens are also revoked early if the authorizing person changes their Facebook password or resets two-factor authentication. If that happens, just reconnect from the Meta Ads integration in Medialake — this is normal and takes a minute.
Revoking access
You're in control at any time. To remove MedialakeAI:
Business Settings → Integrations → Connected apps → select MedialakeAI → Remove, or
Your personal Facebook Settings → Business Integrations → remove MedialakeAI
Revoking immediately stops all access; no action needed on our side.
Troubleshooting
Issues while connecting typically relate to the connecting user not having the necessary permissions on the ad account, or to custom settings within your organization that restrict third-party OAuth apps. If you get stuck, contact [email protected] and we'll walk you through it.
Further reading (Meta documentation)
Permissions Reference — what each scope grants
Facebook Login for Business — the login flow Medialake uses
Access tokens & long-lived tokens — token lifetime and why there are no refresh tokens
Marketing API — the API the connector reads from
You can review or withdraw any of these permissions at any time in Meta Business Settings.
