facebook-mcp

facebook-mcp

A TypeScript MCP server for the Meta Graph API focused on Facebook Pages, enabling publishing, reading, insights, and moderation tasks.

Category
访问服务器

README

facebook-mcp — Facebook Pages MCP Server

CI CodeQL License: MIT node MCP
status last commit docs Sponsor

📖 Documentation site →

A local-first TypeScript Model Context Protocol (MCP) server for the Meta Graph API, focused on Facebook Pages — publishing, reading & insights, and comment/message moderation — driven from an MCP client (Claude, VS Code, the Inspector…) and operated locally by a Page admin using their own Meta developer app. Least-privilege tokens, plan-and-apply write safety, and no telemetry.

🚧 Status: pre-1.0, in active development. Not yet published to npm. The foundation — HTTP client, auth, write gating, transports, tool registry — is complete and tested; 4 of the 35 planned tools are live today (the read-only core package). The publishing, reading, moderation and messaging packages are next. Interfaces and scope may change until the first tagged release. See the roadmap for what lands when.

Contents: Features · Requirements · Setup · Configure credentials · Tools · Roadmap · Security notes · Documentation · Support · Trademark · License

Features

Area Capability Status
Core & diagnostics Identity, Page listing, rate-limit usage, doctor pre-flight check ✅ Available
Reading Page & post reads, Reels, reactions, cursor pagination 🚧 v0.2.0
Publishing Text / link / photo / video / Reels posts, scheduling, edit & delete 🚧 v0.2.0
Insights & moderation Live-verified metrics; comment hide/unhide/delete, replies, blocking 🚧 v0.3.0
Messaging Conversation reads and replies within the 24-hour window 🚧 v0.4.0
Ads Campaign/adset/ad read + status & budget control (opt-in, off by default) 🚧 v0.5.0

The default profile exposes a deliberately small, curated tool surface — each tool wraps a real, verified capability rather than mirroring every Graph edge.

  • Local-first, no telemetry. Only three Meta hosts are ever reached (graph, graph-video, rupload); nothing phones home.
  • Least-privilege credentials. Works with a never-expiring System User token (Business Manager) or a long-lived Page token — no App Review required for an admin operating their own assets.
  • Safe writes. Tiered plan-and-apply gating; irreversible and spend actions require out-of-band confirmation and are never bypassed by an env flag.
  • Secret hygiene. Value-based redaction at a single choke-point across logs, errors, tool results, and the write journal.
  • Layered architecture. Lint-enforced core ← api ← mcp ← tools layering, tools-as-data with a central package registry.

Requirements

  • Node.js ≥ 22 (enforced by engines and a runtime guard in the launcher; the project targets the version in .nvmrc).
  • A Meta (Facebook) developer app — a Business-type app at Standard Access is enough; no App Review is needed to operate your own assets.
  • A Facebook Page (and, for the opt-in ads package, an ad account) you administer.

Setup

(a) From source (current)

The package is not on npm yet, so build from a clone:

git clone https://github.com/IvanBBaev/facebook-mcp.git
cd facebook-mcp
npm install
npm run build
node build/index.js   # or: ./bin/facebook-mcp.mjs

Configure credentials (see below), then point your MCP client at that command.

(b) Via npx (after the first release)

Both snippets below become available after the first published release — the package is currently unpublished.

Register the server with an MCP client (Claude Desktop, VS Code Chat, the Inspector…) by pointing its command at npx:

{
  "mcpServers": {
    "facebook": {
      "command": "npx",
      "args": ["-y", "@ivanbbaev/facebook-mcp"]
    }
  }
}

Claude Code plugin (installs the server wired up):

/plugin marketplace add IvanBBaev/facebook-mcp
/plugin install facebook-mcp

Configure credentials

facebook-mcp authenticates with a token you already control — there is no App Review, no OAuth callback server, and no hosted component. Provide at least one of the token variables below; the most specific wins (FB_SYSTEM_TOKEN → FB_ACCESS_TOKEN → FB_PAGE_TOKEN):

  • FB_SYSTEM_TOKEN — a never-expiring System User token (Business Manager). Recommended: it does not expire and is scoped to the assets you assign it.
  • FB_ACCESS_TOKEN — a Meta user access token (a long-lived one preferred).
  • FB_PAGE_TOKEN — a long-lived Page token, the no-Business-Manager fallback.

Grant only the permissions the packages you enable actually need (least-privilege), and set FB_APP_SECRET so appsecret_proof is attached to every call — that makes a stolen bare token unusable on its own. Settings are read from an env file at the XDG/%APPDATA% config path, or from real environment variables (which take precedence).

Environment variables

Provide at least one token; everything else is optional tuning. Variables marked Secret are never logged or returned by a tool.

Variable Required Default Description
FB_SYSTEM_TOKEN one of¹ — Secret. Never-expiring System User token (Business Manager). Recommended.
FB_ACCESS_TOKEN one of¹ — Secret. Meta user access token (long-lived preferred).
FB_PAGE_TOKEN one of¹ — Secret. Long-lived Page token — the no-Business-Manager fallback.
FB_APP_ID no — Meta app ID. With FB_APP_SECRET it forms the app access token used to inspect tokens.
FB_APP_SECRET no — Secret. Meta app secret. When set, appsecret_proof is attached so a stolen bare token is unusable.
FB_PAGE_ID no — Default Page ID for Page-scoped tools when no profile is given.
FB_PROFILE_<NAME>_PAGE_ID no — Page ID for a named profile (e.g. FB_PROFILE_BRAND_A_PAGE_ID).
FB_PROFILE_<NAME>_TOKEN no — Secret. Optional per-profile token override.
FB_API_VERSION no v23.0 Graph API version to pin. Off-default values are accepted, but only the default is tested.
FB_WRITE_MODE no plan plan (default) previews a write without mutating; apply executes.
FB_MEDIA_DIR no — Directory permitted as a source for local media uploads.
FB_MAX_RESULT_CHARS no 25000 Character budget before a tool result is truncated (500–10000000).
FB_REQUEST_TIMEOUT_MS no 60000 Per-request timeout in milliseconds (1–600000).
FB_HOST_CONCURRENCY no 4 Max parallel requests per Graph host (1–64).
FB_TRANSPORT no stdio stdio (default) or http (loopback-only Streamable HTTP for local agent clients).
FB_HTTP_TOKEN if http — Secret. Bearer token required by the http transport; it fails closed without it.
FB_HTTP_PORT no 3000 TCP port for the http transport (bind host is fixed to loopback 127.0.0.1).
FB_TOOL_PACKAGES no core Comma/space-separated tool packages to enable. core is always on.
FB_PACKAGES_DENY no — Packages to exclude even if enabled by FB_TOOL_PACKAGES.
FB_PACKAGES_READONLY no — Packages whose write tools are not registered; their read tools stay.
FB_JOURNAL_PATH no XDG path Path to the append-only write journal.
FB_LOG_LEVEL no info Stderr log verbosity: debug, info, warn, error.
FB_AD_ACCOUNT_ID no — Ad account ID for the opt-in ads package (1.1).
FB_ADS_BUDGET_CEILING no — Hard budget ceiling for ads writes, in minor currency units (non-negative integer).
FB_CONFIRM_TOKEN no — Secret. Out-of-band confirmation token authorizing gated write / spend actions.

¹ Provide at least one of FB_SYSTEM_TOKEN, FB_ACCESS_TOKEN or FB_PAGE_TOKEN.

Tools

<!-- GENERATED:TOOLS:BEGIN (regenerate after Wave 4) -->

The always-on core package ships four read-only tools today. The reader, posts, insights, moderation, messages and ads packages are on the roadmap, and this table will grow as they land.

Package Tool Read-only Description
core facebook_whoami yes Report the identity behind the configured token (type, validity, granted permissions, expiry) plus the server and pinned Graph API version.
core facebook_list_pages yes List the Pages the operator administers (via /me/accounts): id, name, category, tasks and token presence. Page tokens are never returned.
core facebook_get_page yes Fetch metadata for one Page — name, category, follower/fan counts, publish state and video upload limits.
core facebook_usage yes Report the most recent Graph rate-limit signals (X-App-Usage, X-Business-Use-Case-Usage) as usage percentages so you can back off before a throttle.

<!-- GENERATED:TOOLS:END -->

Roadmap

Work is tracked publicly on the facebook-mcp roadmap board and grouped into release milestones:

Milestone Scope
v0.1.0 — Core Foundation + core tools (done), live smoke harness
v0.2.0 — Reader & publishing Post/Reels reads, publishing, scheduling, photo/video/Reels media
v0.3.0 — Insights & moderation Page/post/Reel insights, comment moderation, blocking
v0.4.0 — Messaging Conversations and message sending
v0.5.0 — Ads Ads read + control, opt-in and off by default
v1.0.0 — Stable Metadata SSOT, generated docs, release rail, npm publish

The design behind each item is written up in advance in docs/analysis/ — the roadmap is a consequence of that corpus, not a replacement for it.

Security notes

  • Three-host fence. Only graph.facebook.com, graph-video.facebook.com and rupload.facebook.com are ever contacted — the allowlist is fixed in code and not user-configurable, so a redirected or mistyped host cannot silently receive a token.
  • Plan-and-apply write gating. Writes default to plan (a non-mutating preview); apply executes. Irreversible and spend actions additionally require an out-of-band confirmation and are never bypassed by an env flag.
  • Single-choke-point redaction. Secret values are stripped at one place before anything reaches logs, errors, tool results or the write journal; Page access tokens are derived to a boolean and their values never enter a payload.
  • No telemetry, local-first. The server logs only to stderr, collects nothing, and phones home nowhere. The http transport binds loopback (127.0.0.1) only and fails closed without FB_HTTP_TOKEN.

See SECURITY.md for the full model and vulnerability reporting.

Documentation

  • Design corpus — the full pre-implementation analysis lives in docs/analysis/: goals & scope, market positioning, Graph API landscape, auth & security model, architecture, tool catalog, risks, roadmap, corner cases, the v1.0 release definition, and the parallel task-breakdown that drives development.
  • Documentation site — ivanbbaev.github.io/facebook-mcp.

Support

Best-effort, single-maintainer support runs through GitHub — see SUPPORT.md for how to file bugs, feature requests and security reports.

This project is built and maintained in my own time. If it helps, a tip keeps it going:

  • GitHub Sponsors — one-off or recurring, no platform fee.
  • Ko-fi — quick one-off support (also accepts PayPal), the fallback for anyone without a GitHub account.
  • Donatree — every donation method on one page, including local payment options.

Sponsor on GitHub Support on Ko-fi Donate via Donatree

Donating buys no priority support and no SLA — see SUPPORT.md. If money is not an option, starring the repository or filing a good bug report helps just as much.

Trademark

This is an independent, community-built project and is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc. Facebook, Meta and related marks are trademarks of Meta Platforms, Inc., used here only nominatively to indicate compatibility.

License

MIT © 2026 Ivan Baev

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选