@ivanbaev/facebook-mcp

MCPattesté
v0.7.0Ivan BaevMITMis à jour il y a 7 jnpmGitHub

Local-first TypeScript MCP server for the Meta Graph API that lets an MCP client publish, read and moderate Facebook Pages through your own Meta developer app, with least-privilege tokens, plan-and-apply write safety and no telemetry.

Fonctionne dans
ClaudeCursorCopilotGemini

Déduit des transports déclarés par cette annonce (stdio). Un client absent de cette liste n’est pas écarté pour autant — c’est simplement quelque chose que Forge ne peut pas confirmer.

Build attesté
Une attestation de provenance vérifiée lie cet artefact au dépôt indiqué. Personne n’a encore revendiqué l’annonce — cela prouve où le code a été construit, pas qui le soutient.
76Téléch./sem.
il y a 7 jDernière mise à jour
Lit ces identifiants
  • FB_SYSTEM_TOKENClé d’APIfacultatif

    System-user access token (Business Manager). Takes precedence over FB_ACCESS_TOKEN and FB_PAGE_TOKEN when several are set.

  • FB_ACCESS_TOKENClé d’APIfacultatif

    Primary user access token. At least one of FB_SYSTEM_TOKEN, FB_ACCESS_TOKEN or FB_PAGE_TOKEN must be set.

  • FB_PAGE_TOKENClé d’APIfacultatif

    Long-lived Page access token used as a fallback credential when no user or system-user token is configured.

  • FB_APP_SECRETClé d’APIfacultatif

    Meta app secret. When set, appsecret_proof is attached to every call so a stolen bare token cannot be used on its own.

  • FB_CONFIRM_TOKENClé d’APIfacultatif

    Operator confirmation token for out-of-band approval of irreversible or spend actions. The server prompts through MCP elicitation where the client supports it; otherwise the caller passes this value…

  • FB_HTTP_TOKENClé d’APIfacultatif

    Bearer token guarding the HTTP transport; required when FB_TRANSPORT=http (the server refuses to start without it).

Déclaré par l’auteur dans le registre MCP officiel. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Paquet
AuteurIvan Baev
LicenceMIT
Version0.7.0
Sourcenpm+mcp-registry
Statut de confiance
A
85/100Fiable
Listé dans l’index Forge+10/10
Identité vérifiée · build attesté+20/20
Signature de publication Ed25519+0/5
Incluse automatiquement quand l’éditeur exécute `forge publish`
Vérification de domaine+0/5
Éditeur : hébergez /.well-known/forge.json sur la page d’accueil du paquet avec { "publisher": "<github-login>" }
npm Trusted Publishing (Sigstore)+5/5
Correspondance de mainteneur npm+0/5
Éditeur : ajoutez le login GitHub vérifié aux mainteneurs du paquet npm (npm owner add <login>)
Analyse CVE · propre+30/30
Analyse statique · propre+20/20
Collez-le dans Claude Code, Cursor ou tout assistant d’IA pour combler toutes les lacunes
StatutIdentité vérifiée
ÉditeurNon vérifié
SignatureNon signé
Domaine
Provenance✓ Vérifié par Sigstore · 759675c
Dépendances✓ 60 résolues+ · aucune vulnérable
Surface d’outils39 outils · 2 privilégiés
Analyse de sécurité✓ Proprev0.7.0 · il y a 4 jQuelle est l’efficacité de cette analyse ?
ÉvaluationsAucune
Indexé28 août 2026

La vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.

Outils

39 outils · 2 privilégiés
Extrait statiquement du paquet publiév0.7.0 · 4d ago

Lu dans le code que npm livre réellement, au moment de l’analyse. Le paquet n’a jamais été exécuté. Les outils enregistrés dynamiquement à l’exécution, ou cachés dans du code empaqueté ou minifié, peuvent passer inaperçus — c’est donc un plancher de la surface d’outils, pas un recensement complet.

facebook_list_campaignsList campaigns under one ad account, a cursor page at a time. Each record

List campaigns under one ad account, a cursor page at a time. Each record

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_list_adsetsList ad sets under one ad account, a cursor page at a time. Ad sets are

List ad sets under one ad account, a cursor page at a time. Ad sets are

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_list_adsList individual ads under one ad account, a cursor page at a time. This is

List individual ads under one ad account, a cursor page at a time. This is

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_get_ad_objectRead one campaign, ad set or ad by id. Pass `level` when you know it — the

Read one campaign, ad set or ad by id. Pass `level` when you know it — the

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_ads_insightsRead performance numbers (impressions, clicks, spend, reach, cpc, ctr) for

Read performance numbers (impressions, clicks, spend, reach, cpc, ctr) for

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_ads_report_statusProbe one async insights report run and, with fetch_results:true, read its

Probe one async insights report run and, with fetch_results:true, read its

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_update_ad_objectPause or resume an ads object, or change its budget. Plan-first: without

Pause or resume an ads object, or change its budget. Plan-first: without

Aucun schéma d’entrée n’a été publié pour cet outil.

adsMarketing API access: campaign / ad-set / ad listings with delivery truth,

Marketing API access: campaign / ad-set / ad listings with delivery truth,

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_whoamiReport the identity behind the configured token (type, validity, granted

Report the identity behind the configured token (type, validity, granted

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_list_pagesList the Facebook Pages the operator administers (via /me/accounts): id,

List the Facebook Pages the operator administers (via /me/accounts): id,

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_get_pageFetch metadata for one Page — name, category, follower/fan counts,

Fetch metadata for one Page — name, category, follower/fan counts,

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_usageReport the most recent Graph rate-limit signals (X-App-Usage,

Report the most recent Graph rate-limit signals (X-App-Usage,

Aucun schéma d’entrée n’a été publié pour cet outil.

coreAlways-on identity, Page discovery and rate-limit diagnostics (read-only).

Always-on identity, Page discovery and rate-limit diagnostics (read-only).

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_page_insightsRead Graph insights for one Page in a compact flat shape: one row per

Read Graph insights for one Page in a compact flat shape: one row per

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_post_insightsRead Graph insights for one published post (post_media_view, post_clicks,

Read Graph insights for one published post (post_media_view, post_clicks,

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_reel_insightsRead Graph insights for one Reel from /{video-id}/video_insights — the

Read Graph insights for one Reel from /{video-id}/video_insights — the

Aucun schéma d’entrée n’a été publié pour cet outil.

insightsPage, post and Reel insights: compact reshaped metric series, aggregate

Page, post and Reel insights: compact reshaped metric series, aggregate

Aucun schéma d’entrée n’a été publié pour cet outil.

messagesMessenger conversations for a Page: poll the inbox, read a thread (untrusted

Messenger conversations for a Page: poll the inbox, read a thread (untrusted

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_list_commentsList the comments on a post, photo, video or another comment, newest-first

List the comments on a post, photo, video or another comment, newest-first

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_get_commentRead one comment by ID, optionally with its replies, and report whether a

Read one comment by ID, optionally with its replies, and report whether a

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_reply_to_commentPost a PUBLIC reply under a comment — visible to everyone who can see the

Post a PUBLIC reply under a comment — visible to everyone who can see the

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_hide_commentHide or unhide up to 50 comments in one call (`hidden:true` hides,

Hide or unhide up to 50 comments in one call (`hidden:true` hides,

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_delete_commentprivilégiéPERMANENTLY delete up to 50 comments. This cannot be undone — prefer

PERMANENTLY delete up to 50 comments. This cannot be undone — prefer

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_private_replySend a private message to the author of a comment. TWO hard limits, both

Send a private message to the author of a comment. TWO hard limits, both

Aucun schéma d’entrée n’a été publié pour cet outil.

moderationRead and moderate comments on Page content (list, reply, hide, delete,

Read and moderate comments on Page content (list, reply, hide, delete,

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_create_postCreate a Page post: plain text, a link, a multi-link card carousel, or a

Create a Page post: plain text, a link, a multi-link card carousel, or a

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_create_photo_postPublish ONE photo to a Page, optionally with a caption, as a draft, or

Publish ONE photo to a Page, optionally with a caption, as a draft, or

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_create_video_postUpload a video to a Page. A local path inside FB_MEDIA_DIR is streamed

Upload a video to a Page. A local path inside FB_MEDIA_DIR is streamed

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_create_reelPublish a Facebook Reel through the three-phase upload (start → transfer

Publish a Facebook Reel through the three-phase upload (start → transfer

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_update_postEdit a Page post the app itself created, or move it through the scheduled-post

Edit a Page post the app itself created, or move it through the scheduled-post

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_delete_postprivilégiéPermanently delete a Page post the app itself created — including a

Permanently delete a Page post the app itself created — including a

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_list_scheduled_postsList the Page posts that are queued to publish later, each with its publish

List the Page posts that are queued to publish later, each with its publish

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_get_video_statusPoll where one video stands in Meta's pipeline: uploading, processing,

Poll where one video stands in Meta's pipeline: uploading, processing,

Aucun schéma d’entrée n’a été publié pour cet outil.

postsPublish, schedule, edit and delete Page posts, photos, videos and Reels

Publish, schedule, edit and delete Page posts, photos, videos and Reels

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_list_postsList a Page's posts, one cursor page at a time. `edge` selects WHICH posts:

List a Page's posts, one cursor page at a time. `edge` selects WHICH posts:

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_get_postFetch ONE post by its composite id ("{page-id}_{post-id}" as returned by

Fetch ONE post by its composite id ("{page-id}_{post-id}" as returned by

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_list_reelsList a Page's Reels via the /video_reels edge — the ONLY place Reels are

List a Page's Reels via the /video_reels edge — the ONLY place Reels are

Aucun schéma d’entrée n’a été publié pour cet outil.

facebook_get_reactionsRead the reactions on one post: a `totals` map per reaction type

Read the reactions on one post: a `totals` map per reaction type

Aucun schéma d’entrée n’a été publié pour cet outil.

readerRead-only access to a Page's own content: posts (four edges), single posts,

Read-only access to a Page's own content: posts (four edges), single posts,

Aucun schéma d’entrée n’a été publié pour cet outil.

39 outils sur 39 ont publié une description.

Les noms et descriptions d’outils sont écrits par l’éditeur et affichés tels quels, comme du texte inerte. Ce sont les chaînes qu’un client MCP transmet à un modèle, alors Forge y recherche des motifs d’injection de prompt — tout constat apparaît avec l’analyse de sécurité ci-dessus. « Privilégié » est une correspondance de mot-clé sur le nom de l’outil, pas un audit de ce qu’il fait : un nom anodin peut tout de même tout faire.

À propos

Local-first TypeScript MCP server for the Meta Graph API that lets an MCP client publish, read and moderate Facebook Pages through your own Meta developer app, with least-privilege tokens, plan-and-apply write safety and no telemetry.

Mots-clés
mcpmodel-context-protocolfacebookmetagraph-apipagesllmai
Alternatives
Comparaison des surfaces d’outils…

Arbre de dépendances

Ce qu'une analyse Forge a résolu à partir des métadonnées npm le 2026-08-30 — résolution observée, et non une déclaration de l'éditeur.

60 paquets résolus · 3 directs · aucun porteur d'avis de sécurité La résolution s'arrête à la profondeur 4 et à 60 paquets.

L'exploration s'est arrêtée à la limite de profondeur 4. Tout ce qui se trouve en dessous n'a jamais été résolu.

L'exploration s'est arrêtée à la limite de 60 paquets. Le reste de l'arbre n'a jamais été résolu.

36 autres paquets résolus ne sont pas dessinés ici (limite d'affichage : 24). Toute dépendance porteuse d'un avis de sécurité est dessinée quelle que soit la limite. Inventaire complet (SBOM CycloneDX)

Déclarées mais non résolues

55 dépendances déclarées ne sont jamais arrivées dans l'arbre. Elles manquent à la résolution de Forge, pas au paquet.

+43 de plus non listées. Les comptes par motif ci-dessus les couvrent toutes.

Non suivies : peerDependencies. Cet arbre ne couvre que les dépendances d'exécution ; ce qu'elles entraînent n'a jamais été résolu.