@ivanbaev/facebook-mcp

MCPattestiert
v0.7.0Ivan BaevMITAktualisiert vor 6 TnpmGitHub

Local-first TypeScript MCP server for the Meta Graph API that lets an MCP client publish, read and moderate Facebook Pages through your own Meta developer app, with least-privilege tokens, plan-and-apply write safety and no telemetry.

Läuft in
ClaudeCursorCopilotGemini

Abgeleitet aus den Transporten, die dieser Eintrag deklariert (stdio). Ein Client, der hier nicht steht, ist damit nicht ausgeschlossen — Forge kann ihn nur nicht bestätigen.

Attestierter Build
Eine verifizierte Herkunfts-Attestation bindet dieses Artefakt an das gelistete Repository. Den Eintrag hat noch niemand beansprucht — das belegt, wo der Code gebaut wurde, nicht, wer dahintersteht.
76Downloads/Wo.
vor 6 TLetzte Aktualisierung
Liest diese Zugangsdaten
  • FB_SYSTEM_TOKENAPI-Schlüsseloptional

    System-user access token (Business Manager). Takes precedence over FB_ACCESS_TOKEN and FB_PAGE_TOKEN when several are set.

  • FB_ACCESS_TOKENAPI-Schlüsseloptional

    Primary user access token. At least one of FB_SYSTEM_TOKEN, FB_ACCESS_TOKEN or FB_PAGE_TOKEN must be set.

  • FB_PAGE_TOKENAPI-Schlüsseloptional

    Long-lived Page access token used as a fallback credential when no user or system-user token is configured.

  • FB_APP_SECRETAPI-Schlüsseloptional

    Meta app secret. When set, appsecret_proof is attached to every call so a stolen bare token cannot be used on its own.

  • FB_CONFIRM_TOKENAPI-Schlüsseloptional

    Operator confirmation token for out-of-band approval of irreversible or spend actions. The server prompts through MCP elicitation where the client supports it; otherwise the caller passes this value…

  • FB_HTTP_TOKENAPI-Schlüsseloptional

    Bearer token guarding the HTTP transport; required when FB_TRANSPORT=http (the server refuses to start without it).

Vom Autor in der offiziellen MCP-Registry angegeben. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Paket
AutorIvan Baev
LizenzMIT
Version0.7.0
Quellenpm+mcp-registry
Trust-Status
A
85/100Vertrauenswürdig
Im Forge-Index gelistet+10/10
Identität verifiziert · attestierter Build+20/20
Ed25519-Publish-Signatur+0/5
Wird automatisch ergänzt, wenn der Publisher `forge publish` ausführt
Domain-Verifizierung+0/5
Publisher: hinterlege /.well-known/forge.json auf der Paket-Homepage mit { "publisher": "<github-login>" }
npm Trusted Publishing (Sigstore)+5/5
npm-Maintainer-Übereinstimmung+0/5
Publisher: trage den verifizierten GitHub-Login als Maintainer des npm-Pakets ein (npm owner add <login>)
CVE-Scan · sauber+30/30
Statische Analyse · sauber+20/20
Füge das in Claude Code, Cursor oder einen beliebigen KI-Assistenten ein, um alle Lücken zu schließen
StatusIdentität verifiziert
PublisherNicht verifiziert
SignaturNicht signiert
Domain
Herkunft✓ Sigstore-verifiziert · 759675c
Abhängigkeiten✓ 60 aufgelöst+ · keine verwundbar
Tool-Oberfläche39 Tools · 2 privilegiert
Sicherheits-Scan✓ Sauberv0.7.0 · vor 3 TWie gut funktioniert dieser Scan?
EvaluierungenKeine
Indexiert28. Aug. 2026

Die Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.

Tools

39 Tools · 2 privilegiert
Statisch aus dem veröffentlichten Paket extrahiertv0.7.0 · 3d ago

Aus dem Quellcode gelesen, den npm tatsächlich ausliefert, zum Zeitpunkt des Scans. Das Paket wurde nie ausgeführt. Tools, die zur Laufzeit dynamisch registriert werden oder in gebündeltem beziehungsweise minifiziertem Code stecken, können übersehen werden — das hier ist also eine Untergrenze der Tool-Oberfläche, keine vollständige Erhebung.

facebook_list_campaignsList campaigns under one ad account, a cursor page at a time. Each record

List campaigns under one ad account, a cursor page at a time. Each record

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_list_adsetsList ad sets under one ad account, a cursor page at a time. Ad sets are

List ad sets under one ad account, a cursor page at a time. Ad sets are

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_list_adsList individual ads under one ad account, a cursor page at a time. This is

List individual ads under one ad account, a cursor page at a time. This is

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_get_ad_objectRead one campaign, ad set or ad by id. Pass `level` when you know it — the

Read one campaign, ad set or ad by id. Pass `level` when you know it — the

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_ads_insightsRead performance numbers (impressions, clicks, spend, reach, cpc, ctr) for

Read performance numbers (impressions, clicks, spend, reach, cpc, ctr) for

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_ads_report_statusProbe one async insights report run and, with fetch_results:true, read its

Probe one async insights report run and, with fetch_results:true, read its

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_update_ad_objectPause or resume an ads object, or change its budget. Plan-first: without

Pause or resume an ads object, or change its budget. Plan-first: without

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

adsMarketing API access: campaign / ad-set / ad listings with delivery truth,

Marketing API access: campaign / ad-set / ad listings with delivery truth,

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_whoamiReport the identity behind the configured token (type, validity, granted

Report the identity behind the configured token (type, validity, granted

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_list_pagesList the Facebook Pages the operator administers (via /me/accounts): id,

List the Facebook Pages the operator administers (via /me/accounts): id,

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_get_pageFetch metadata for one Page — name, category, follower/fan counts,

Fetch metadata for one Page — name, category, follower/fan counts,

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_usageReport the most recent Graph rate-limit signals (X-App-Usage,

Report the most recent Graph rate-limit signals (X-App-Usage,

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

coreAlways-on identity, Page discovery and rate-limit diagnostics (read-only).

Always-on identity, Page discovery and rate-limit diagnostics (read-only).

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_page_insightsRead Graph insights for one Page in a compact flat shape: one row per

Read Graph insights for one Page in a compact flat shape: one row per

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_post_insightsRead Graph insights for one published post (post_media_view, post_clicks,

Read Graph insights for one published post (post_media_view, post_clicks,

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_reel_insightsRead Graph insights for one Reel from /{video-id}/video_insights — the

Read Graph insights for one Reel from /{video-id}/video_insights — the

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

insightsPage, post and Reel insights: compact reshaped metric series, aggregate

Page, post and Reel insights: compact reshaped metric series, aggregate

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

messagesMessenger conversations for a Page: poll the inbox, read a thread (untrusted

Messenger conversations for a Page: poll the inbox, read a thread (untrusted

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_list_commentsList the comments on a post, photo, video or another comment, newest-first

List the comments on a post, photo, video or another comment, newest-first

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_get_commentRead one comment by ID, optionally with its replies, and report whether a

Read one comment by ID, optionally with its replies, and report whether a

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_reply_to_commentPost a PUBLIC reply under a comment — visible to everyone who can see the

Post a PUBLIC reply under a comment — visible to everyone who can see the

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_hide_commentHide or unhide up to 50 comments in one call (`hidden:true` hides,

Hide or unhide up to 50 comments in one call (`hidden:true` hides,

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_delete_commentprivilegiertPERMANENTLY delete up to 50 comments. This cannot be undone — prefer

PERMANENTLY delete up to 50 comments. This cannot be undone — prefer

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_private_replySend a private message to the author of a comment. TWO hard limits, both

Send a private message to the author of a comment. TWO hard limits, both

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

moderationRead and moderate comments on Page content (list, reply, hide, delete,

Read and moderate comments on Page content (list, reply, hide, delete,

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_create_postCreate a Page post: plain text, a link, a multi-link card carousel, or a

Create a Page post: plain text, a link, a multi-link card carousel, or a

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_create_photo_postPublish ONE photo to a Page, optionally with a caption, as a draft, or

Publish ONE photo to a Page, optionally with a caption, as a draft, or

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_create_video_postUpload a video to a Page. A local path inside FB_MEDIA_DIR is streamed

Upload a video to a Page. A local path inside FB_MEDIA_DIR is streamed

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_create_reelPublish a Facebook Reel through the three-phase upload (start → transfer

Publish a Facebook Reel through the three-phase upload (start → transfer

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_update_postEdit a Page post the app itself created, or move it through the scheduled-post

Edit a Page post the app itself created, or move it through the scheduled-post

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_delete_postprivilegiertPermanently delete a Page post the app itself created — including a

Permanently delete a Page post the app itself created — including a

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_list_scheduled_postsList the Page posts that are queued to publish later, each with its publish

List the Page posts that are queued to publish later, each with its publish

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_get_video_statusPoll where one video stands in Meta's pipeline: uploading, processing,

Poll where one video stands in Meta's pipeline: uploading, processing,

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

postsPublish, schedule, edit and delete Page posts, photos, videos and Reels

Publish, schedule, edit and delete Page posts, photos, videos and Reels

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_list_postsList a Page's posts, one cursor page at a time. `edge` selects WHICH posts:

List a Page's posts, one cursor page at a time. `edge` selects WHICH posts:

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_get_postFetch ONE post by its composite id ("{page-id}_{post-id}" as returned by

Fetch ONE post by its composite id ("{page-id}_{post-id}" as returned by

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_list_reelsList a Page's Reels via the /video_reels edge — the ONLY place Reels are

List a Page's Reels via the /video_reels edge — the ONLY place Reels are

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

facebook_get_reactionsRead the reactions on one post: a `totals` map per reaction type

Read the reactions on one post: a `totals` map per reaction type

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

readerRead-only access to a Page's own content: posts (four edges), single posts,

Read-only access to a Page's own content: posts (four edges), single posts,

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

39 von 39 Tools haben eine Beschreibung veröffentlicht.

Tool-Namen und -Beschreibungen stammen vom Publisher und werden wortgetreu als inerter Text angezeigt. Es sind die Zeichenketten, die ein MCP-Client an ein Modell übergibt, deshalb prüft Forge sie auf Prompt-Injection-Muster — jeder Befund erscheint oben beim Sicherheits-Scan. „Privilegiert“ ist ein Schlagwort-Treffer im Tool-Namen, keine Prüfung dessen, was das Tool tut: ein harmlos klingender Name kann trotzdem alles tun.

Über

Local-first TypeScript MCP server for the Meta Graph API that lets an MCP client publish, read and moderate Facebook Pages through your own Meta developer app, with least-privilege tokens, plan-and-apply write safety and no telemetry.

Schlagwörter
mcpmodel-context-protocolfacebookmetagraph-apipagesllmai
Alternativen
Tool-Oberflächen werden verglichen…

Abhängigkeitsbaum

Was ein Forge-Scan am 2026-08-30 aus den npm-Metadaten aufgelöst hat — beobachtete Auflösung, keine Angabe des Herausgebers.

60 Pakete aufgelöst · 3 direkt · keines mit Sicherheitshinweisen Die Auflösung endet bei Tiefe 4 und 60 Paketen.

Der Durchlauf endete an der Tiefengrenze 4. Alles unterhalb dieser Ebene wurde nie aufgelöst.

Der Durchlauf endete an der Grenze von 60 Paketen. Der Rest des Baums wurde nie aufgelöst.

36 weitere aufgelöste Pakete werden hier nicht gezeichnet (Anzeigegrenze: 24). Jede Abhängigkeit mit einem Sicherheitshinweis wird unabhängig von der Grenze gezeichnet. Vollständiges Inventar (CycloneDX-SBOM)

Deklariert, aber nicht aufgelöst

55 deklarierte Abhängigkeiten sind nie im Baum gelandet. Sie fehlen in Forges Auflösung, nicht im Paket.

+43 weitere nicht aufgeführt. Die Zählungen nach Grund oben erfassen sie alle.

Nicht verfolgt: peerDependencies. Dieser Baum erfasst nur Laufzeitabhängigkeiten; was jene mitbringen, wurde nie aufgelöst.