npm · @ivanbaev/facebook-mcp
$npx -y @ivanbaev/facebook-mcp@0.7.0 FB_SYSTEM_TOKEN · secret — System-user access token (Business Manager). Takes precedence over FB_ACCESS_TOKEN and FB_PAGE_TOKEN when several are set.
FB_ACCESS_TOKEN · secret — Primary user access token. At least one of FB_SYSTEM_TOKEN, FB_ACCESS_TOKEN or FB_PAGE_TOKEN must be set.
FB_PAGE_TOKEN · secret — Long-lived Page access token used as a fallback credential when no user or system-user token is configured.
FB_APP_ID — Meta app ID; combined with FB_APP_SECRET it forms the app access token used to authorize /debug_token inspection.
FB_APP_SECRET · secret — Meta app secret. When set, appsecret_proof is attached to every call so a stolen bare token cannot be used on its own.
FB_PAGE_ID — Default Facebook Page ID, used when a tool call omits an explicit profile argument.
FB_API_VERSION — Graph API version to target. Defaults to the tested pinned version; other values are accepted verbatim as an escape hatch but are not tested.
FB_REQUEST_TIMEOUT_MS — Per-request timeout in milliseconds; integer in [1, 600000].
FB_HOST_CONCURRENCY — Maximum number of in-flight requests per Graph host; integer in [1, 64].
FB_MAX_RESULT_CHARS — Character budget applied by the result shaper before a tool result is truncated; integer in [500, 10000000].
FB_WRITE_MODE — Write gating mode: plan (validating dry-run preview, the default) or apply. It never covers the irreversible and spend tiers, which always need a per-call apply plus a plan_id.
FB_CONFIRM_TOKEN · secret — Operator confirmation token for out-of-band approval of irreversible or spend actions. The server prompts through MCP elicitation where the client supports it; otherwise the caller passes this value as the confirm_token tool argument.
FB_MEDIA_DIR — Directory permitted for local media uploads. Unset means URL-only uploads and no local file access at all.
FB_JOURNAL_PATH — Path to the append-only write journal. Defaults to the XDG/%APPDATA% state path; the file is created owner-only (0600) and rotates by size.
FB_TOOL_PACKAGES — Comma-separated tool packages or profiles to expose (e.g. core,posts,reader, or the profiles core|all|reader|publisher|moderator|ads). Omit for the default profile, which excludes ads.
FB_PACKAGES_DENY — Comma-separated packages to exclude even when FB_TOOL_PACKAGES enables them. Deny wins over allow.
FB_PACKAGES_READONLY — Comma-separated packages whose write tools are not registered at all; the read tools of those packages stay available.
FB_TRANSPORT — Transport protocol: stdio (default) or http. The http transport binds 127.0.0.1 only and fails closed without FB_HTTP_TOKEN.
FB_HTTP_TOKEN · secret — Bearer token guarding the HTTP transport; required when FB_TRANSPORT=http (the server refuses to start without it).
FB_HTTP_PORT — Port for the HTTP transport (loopback only); used when FB_TRANSPORT=http. Integer in [1, 65535].
FB_AD_ACCOUNT_ID — Default ad account ID (act_… or the bare numeric id) for the opt-in ads package.
FB_ADS_BUDGET_CEILING — Hard ceiling for any ads budget write, in minor currency units (e.g. cents). Non-negative integer; a write above it is refused.
FB_LOG_LEVEL — Stderr log verbosity: debug, info, warn or error. Logs never go to stdout — that is the stdio protocol channel.