The Contractors Marketing API

Internal agency operations console

Meta operations proof console

This public reviewer console shows how The Contractors Marketing API helps the agency manage authorized client business portfolios, Facebook Pages, ad accounts, reporting, and operator-authorized campaign creation. Redacted live TCM readbacks load from the review endpoint, while the review campaign action stays private-code gated and server-forced to PAUSED.

App The Contractors Marketing API
App ID 2922907381250168
Business The Contractors Marketing
Token source Loading readback
Live API Loading

Requested access

Permission coverage map

Readiness status Prep only Live readback endpoint fails closed when proof is incomplete
Runtime permission checks Loading runtime checks Granted scopes are verified separately from Meta App Review approval
ads_read insights Pending live wiring Usable spend, impressions, clicks, and reach rows are pulled from the configured proof account
ads_management proof Loading creation evidence A receipt-owned campaign must read back status=PAUSED and effective_status=PAUSED
Marketing API tier Same-day check required Final dashboard check must show no active warning
Proof write controls Code-gated Private reviewer code required; campaign account, objective, budget-sharing mode, name prefix, and status stay server-owned
business_management

Business asset validation

Purpose
Confirm the authorized business portfolio and assigned assets.
Test on this page
Business proof section
Live proof
Business, ad account, Page, and asset table readbacks.
Safety boundary
Readback only; no asset assignment changes from the page.
pages_show_list

Assigned Page selection

Purpose
List assigned Pages and bind the correct Page to ad identity.
Test on this page
Page list proof section
Live proof
Selected Page, masked Page ID, category, and Business Manager assignment.
Safety boundary
No Page publishing or Page setting changes from the demo.
pages_read_engagement

Page health readback

Purpose
Read Page engagement context before campaign planning.
Test on this page
Page engagement proof
Live proof
Followers, fan count, talking-about count, and evidence log row.
Safety boundary
Read-only Page metrics; no organic Page content mutation.
ads_read

Ad reporting readback

Purpose
Read campaign objects and Ads Insights for reporting and audits.
Test on this page
Ads read proof section
Live proof
Spend, impressions, clicks, reach, campaigns, ads, and creatives.
Safety boundary
Reporting calls do not mutate delivery assets.
ads_management

Paused campaign creation

Purpose
Create one new operator-authorized review campaign through the Marketing API.
Live proof
Sanitized creation receipt followed by exact-ID PAUSED readback in Created by this app.
Safety boundary
The server allowlists the proof account, forces campaign-only creation and status=PAUSED, caps runs, and rejects arbitrary Meta fields.
Marketing API Access Tier

API throughput proof

The final submission uses same-day Meta Developers evidence showing Marketing API Access Tier testing complete and the required success-rate gate passing.

System-user authorization context

Authorization and asset grant path

The Contractors Marketing API is an internal agency operations app. It does not use a public consumer Facebook Login flow in this demo. Access is granted through Meta Business Manager by installing the app for the business, assigning assets to a system user, and issuing The Contractors Marketing API-scoped system-user tokens.

App authorization The Contractors Marketing API App ID 2922907381250168
Token type System user Grant path documented; live readback loading
Required scopes Mapped for review business, Page, ads read, and ads management scopes
Assigned assets Needs live verification Business Manager grants drive the internal console
Workflow step What Meta should see Why no public login appears
Business Manager grant System user is installed for the verified TCM business portfolio. System-user flow is server-to-server based.
Asset assignment Assigned Pages and ad accounts are read back from the API. Client assets are granted in Business Manager, not selected by a public user.
Permission proof Each requested permission will be shown in the live evidence log after endpoint wiring. The demo uses app-scoped system-user tokens, never browser-exposed tokens.

Permission proof: business_management

Business portfolio and asset access

Loading redacted live Meta readbacks from the review endpoint.

Business portfolio 1282278913857645 Waiting for system-user proof
Ad accounts Configured in Meta TCM system-user ad account readback will be verified in the live pass
Pages Mapped Requires TCM system-user token live readback before submission
Instagram Optional placement context Checked for eligible placements
Asset Type Access check Workflow use
The Contractors Marketing Business portfolio Pending live readback Client identity, permissions, asset ownership
The Contractors Marketing Facebook Page ADVERTISE task Ad identity, Page posts, engagement context
TCM Demo Ad Account Ad account Read and manage Campaigns, ad groups, ads, reporting
Instagram placement inventory Instagram account Placement check Feed, Stories, Reels, Explore placement planning

Permission proof: pages_show_list

Business Manager assigned Page list

This pages_show_list proof uses the Pages assigned to the TCM system user in Meta Business Manager. The selected Page is then bound to ad identity, placement planning, and Page engagement checks before campaign setup.

TCM
Selected Page

The Contractors Marketing

Primary client Page used to validate Page access before campaign setup.

Permission proof: pages_read_engagement Needs live readback Live Page metrics must be verified before ad setup proof
Publishing identity Mapped to TCM Page Mapped to eligible ad placements
Content source Signal How the app uses it
Facebook Page profile Page name, masked Page ID, category, Business Manager assignment Confirm the Business Manager-assigned client Page before ad setup.
Page engagement metrics Followers, fans, talking-about count Validate the Page health signal before campaign setup.
Recent Page posts (optional) Recent post rows, if available Optional content context when the Page token returns post rows.
Instagram business account Account connection and placement eligibility Show whether Instagram placements can be used for ads.

Permission proof: ads_read

Campaign reporting and object readback

Permission proof: ads_read

ads_read
Spend Pending
Impressions Pending
Clicks Pending
Reach Pending

Loading campaign-level ads_read insight metrics from the authorized reporting proof account.

Campaign insight row Spend Impressions Clicks / reach
TCM Reporting Proof $0.00 Pending live row Pending live row
Campaign object Status Object readback Relationship
TCM Reporting Proof Paused Campaign object Related to campaign-level insight rows above

Permission proof: ads_management

ads_management

The action below creates one new campaign in the connected, allowlisted TCM review account. The browser cannot choose a Meta account, objective, budget-sharing mode, name prefix, delivery status, budget, targeting, creative, URL, or placement.

App identityThe Contractors Marketing API
Connected businessLoading
Allowlisted proof accountLoading
Token typeLoading
Runtime scopeChecking ads_management
Server-enforced statePAUSED campaign only
Server-owned campaign policy Loading the fixed review campaign name prefix and objective

Creation remains disabled until the app, system-user token, runtime scope, business, and proof account pass server validation.

Enter the private reviewer code from Meta testing instructions. A server-generated idempotency key prevents duplicate creation on retry.

Recent exact-ID evidence

Created by this app — last 1 hour

Loading

Loading sanitized receipts from the last one-hour reviewer display window. Underlying audit records remain durable.

Created Campaign Returned Meta ID (masked) Readback state Review run
Loading Created by this app receipts

Marketing API Access Tier + audit trail

Operations evidence log

API call target Same-day check required Use Meta Developers request/edit evidence; no warm-up runs from this page
Error-rate target Non-blocking Do not submit if Meta testing shows a new warning
Mutation policy Campaign create only Allowlisted account and server-owned fields; status is always PAUSED
Live proof state Loading live readback Waiting for API readback
Step Permission Operations evidence Safety control
1. Validate app token public_profile The Contractors Marketing API app ID, operator identity, granted scopes Secrets are never exposed in the UI
2. Select business business_management Business portfolio and assigned assets read back Only authorized client assets are displayed
3. Select Page pages_show_list Business Manager-assigned Pages listed for the connected business Wrong Page selection blocks ad setup
4. Read Page engagement pages_read_engagement Page and content engagement is shown for planning Data is retained only for authorized workflow needs
5. Read campaigns ads_read Spend, impressions, clicks, reach, campaigns, ad sets, ads, and creatives read back Reporting views do not mutate delivery assets
6. Create review campaign ads_management Private-code-gated API action creates one campaign and returns a sanitized receipt Account, objective, name prefix, rate cap, idempotency key, and status=PAUSED are server enforced
7. Verify created campaign ads_management The server reads the exact returned campaign ID back, persists it privately, and shows only a masked ID in Created by this app Successful proof requires status=PAUSED and effective_status=PAUSED; retries reuse the original receipt