MCPLow riskUnclaimed

facebook-mcp

Facebook Pages MCP server for the Meta Graph API — publishing, insights, moderation, messaging

IvanBBaevivanbbaev/facebook-mcp★ 1Updated Aug 27, 2026

server.json

{
  "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
  "name": "io.github.IvanBBaev/facebook-mcp",
  "description": "Facebook Pages MCP server for the Meta Graph API — publishing, insights, moderation, messaging",
  "repository": {
    "url": "https://github.com/IvanBBaev/facebook-mcp",
    "source": "github"
  },
  "version": "0.7.0",
  "websiteUrl": "https://ivanbbaev.github.io/facebook-mcp/",
  "packages": [
    {
      "registryType": "npm",
      "identifier": "@ivanbaev/facebook-mcp",
      "version": "0.7.0",
      "transport": {
        "type": "stdio"
      },
      "environmentVariables": [
        {
          "description": "System-user access token (Business Manager). Takes precedence over FB_ACCESS_TOKEN and FB_PAGE_TOKEN when several are set.",
          "format": "string",
          "isSecret": true,
          "name": "FB_SYSTEM_TOKEN"
        },
        {
          "description": "Primary user access token. At least one of FB_SYSTEM_TOKEN, FB_ACCESS_TOKEN or FB_PAGE_TOKEN must be set.",
          "format": "string",
          "isSecret": true,
          "name": "FB_ACCESS_TOKEN"
        },
        {
          "description": "Long-lived Page access token used as a fallback credential when no user or system-user token is configured.",
          "format": "string",
          "isSecret": true,
          "name": "FB_PAGE_TOKEN"
        },
        {
          "description": "Meta app ID; combined with FB_APP_SECRET it forms the app access token used to authorize /debug_token inspection.",
          "format": "string",
          "name": "FB_APP_ID"
        },
        {
          "description": "Meta app secret. When set, appsecret_proof is attached to every call so a stolen bare token cannot be used on its own.",
          "format": "string",
          "isSecret": true,
          "name": "FB_APP_SECRET"
        },
        {
          "description": "Default Facebook Page ID, used when a tool call omits an explicit profile argument.",
          "format": "string",
          "name": "FB_PAGE_ID"
        },
        {
          "description": "Graph API version to target. Defaults to the tested pinned version; other values are accepted verbatim as an escape hatch but are not tested.",
          "format": "string",
          "default": "v23.0",
          "name": "FB_API_VERSION"
        },
        {
          "description": "Per-request timeout in milliseconds; integer in [1, 600000].",
          "format": "number",
          "default": "60000",
          "name": "FB_REQUEST_TIMEOUT_MS"
        },
        {
          "description": "Maximum number of in-flight requests per Graph host; integer in [1, 64].",
          "format": "number",
          "default": "4",
          "name": "FB_HOST_CONCURRENCY"
        },
        {
          "description": "Character budget applied by the result shaper before a tool result is truncated; integer in [500, 10000000].",
          "format": "number",
          "default": "25000",
          "name": "FB_MAX_RESULT_CHARS"
        },
        {
          "description": "Write gating mode: plan (validating dry-run preview, the default) or apply. It never covers the irreversible and spend tiers, which always need a per-call apply plus a plan_id.",
          "format": "string",
          "default": "plan",
          "choices": [
            "plan",
            "apply"
          ],
          "name": "FB_WRITE_MODE"
        },
        {
          "description": "Operator confirmation token for out-of-band approval of irreversible or spend actions. The server prompts through MCP elicitation where the client supports it; otherwise the caller passes this value as the confirm_token tool argument.",
          "format": "string",
          "isSecret": true,
          "name": "FB_CONFIRM_TOKEN"
        },
        {
          "description": "Directory permitted for local media uploads. Unset means URL-only uploads and no local file access at all.",
          "format": "filepath",
          "name": "FB_MEDIA_DIR"
        },
        {
          "description": "Path to the append-only write journal. Defaults to the XDG/%APPDATA% state path; the file is created owner-only (0600) and rotates by size.",
          "format": "filepath",
          "name": "FB_JOURNAL_PATH"
        },
        {
          "description": "Comma-separated tool packages or profiles to expose (e.g. core,posts,reader, or the profiles core|all|reader|publisher|moderator|ads). Omit for the default profile, which excludes ads.",
          "format": "string",
          "name": "FB_TOOL_PACKAGES"
        },
        {
          "description": "Comma-separated packages to exclude even when FB_TOOL_PACKAGES enables them. Deny wins over allow.",
          "format": "string",
          "name": "FB_PACKAGES_DENY"
        },
        {
          "description": "Comma-separated packages whose write tools are not registered at all; the read tools of those packages stay available.",
          "format": "string",
          "name": "FB_PACKAGES_READONLY"
        },
        {
          "description": "Transport protocol: stdio (default) or http. The http transport binds 127.0.0.1 only and fails closed without FB_HTTP_TOKEN.",
          "format": "string",
          "default": "stdio",
          "choices": [
            "stdio",
            "http"
          ],
          "name": "FB_TRANSPORT"
        },
        {
          "description": "Bearer token guarding the HTTP transport; required when FB_TRANSPORT=http (the server refuses to start without it).",
          "format": "string",
          "isSecret": true,
          "name": "FB_HTTP_TOKEN"
        },
        {
          "description": "Port for the HTTP transport (loopback only); used when FB_TRANSPORT=http. Integer in [1, 65535].",
          "format": "number",
          "default": "3000",
          "name": "FB_HTTP_PORT"
        },
        {
          "description": "Default ad account ID (act_… or the bare numeric id) for the opt-in ads package.",
          "format": "string",
          "name": "FB_AD_ACCOUNT_ID"
        },
        {
          "description": "Hard ceiling for any ads budget write, in minor currency units (e.g. cents). Non-negative integer; a write above it is refused.",
          "format": "number",
          "name": "FB_ADS_BUDGET_CEILING"
        },
        {
          "description": "Stderr log verbosity: debug, info, warn or error. Logs never go to stdout — that is the stdio protocol channel.",
          "format": "string",
          "default": "info",
          "choices": [
            "debug",
            "info",
            "warn",
            "error"
          ],
          "name": "FB_LOG_LEVEL"
        }
      ]
    }
  ]
}

Permissions

DeclaredDetected
Runs code—node
Installs—npm:@ivanbaev/facebook-mcp@0.7.0
Runs install scripts—None
NetworkNoneNone
Needs credentialsFB_ACCESS_TOKENFB_APP_SECRETFB_CONFIRM_TOKENFB_HTTP_TOKENFB_PAGE_TOKENFB_SYSTEM_TOKENFB_ACCESS_TOKENFB_APP_SECRETFB_CONFIRM_TOKENFB_HTTP_TOKENFB_PAGE_TOKENFB_SYSTEM_TOKEN
Outside the workspace—None
Agent tools—None

Checks

Low risk · Nothing worth a warning was found.

Not reviewed by a person · Checked by rules; the model review is not switched on yet.

Versions

  1. #10.7.0latestOct 7, 2026