@ivanbaev/facebook-mcp

MCPattestato
v0.7.0Ivan BaevMITAggiornato 6 g fanpmGitHub

Local-first TypeScript MCP server for the Meta Graph API that lets an MCP client publish, read and moderate Facebook Pages through your own Meta developer app, with least-privilege tokens, plan-and-apply write safety and no telemetry.

Funziona in
ClaudeCursorCopilotGemini

Dedotto dai trasporti dichiarati da questo annuncio (stdio). Un client che non compare qui non è escluso — semplicemente Forge non è in grado di confermarlo.

Build attestato
Un’attestation di provenienza verificata lega questo artefatto al repository indicato. Nessuno ha ancora rivendicato l’annuncio — questo dimostra dove è stato costruito il codice, non chi lo sostiene.
76Download/sett.
6 g faUltimo aggiornamento
Legge queste credenziali
  • FB_SYSTEM_TOKENChiave APIfacoltativa

    System-user access token (Business Manager). Takes precedence over FB_ACCESS_TOKEN and FB_PAGE_TOKEN when several are set.

  • FB_ACCESS_TOKENChiave APIfacoltativa

    Primary user access token. At least one of FB_SYSTEM_TOKEN, FB_ACCESS_TOKEN or FB_PAGE_TOKEN must be set.

  • FB_PAGE_TOKENChiave APIfacoltativa

    Long-lived Page access token used as a fallback credential when no user or system-user token is configured.

  • FB_APP_SECRETChiave APIfacoltativa

    Meta app secret. When set, appsecret_proof is attached to every call so a stolen bare token cannot be used on its own.

  • FB_CONFIRM_TOKENChiave APIfacoltativa

    Operator confirmation token for out-of-band approval of irreversible or spend actions. The server prompts through MCP elicitation where the client supports it; otherwise the caller passes this value…

  • FB_HTTP_TOKENChiave APIfacoltativa

    Bearer token guarding the HTTP transport; required when FB_TRANSPORT=http (the server refuses to start without it).

Dichiarato dall’autore nel registro MCP ufficiale. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Pacchetto
AutoreIvan Baev
LicenzaMIT
Versione0.7.0
Fontenpm+mcp-registry
Stato di fiducia
A
85/100Affidabile
Presente nell’indice di Forge+10/10
Identità verificata · build attestato+20/20
Firma di pubblicazione Ed25519+0/5
Inclusa automaticamente quando il publisher esegue `forge publish`
Verifica del dominio+0/5
Publisher: ospita /.well-known/forge.json sulla homepage del pacchetto con { "publisher": "<github-login>" }
npm Trusted Publishing (Sigstore)+5/5
Corrispondenza del maintainer npm+0/5
Publisher: aggiungi il login GitHub verificato ai maintainer del pacchetto npm (npm owner add <login>)
Analisi CVE · pulita+30/30
Analisi statica · pulita+20/20
Incollalo in Claude Code, Cursor o qualsiasi assistente di IA per colmare tutte le lacune
StatoIdentità verificata
PublisherNon verificato
FirmaNon firmato
Dominio
Provenienza✓ Verificato con Sigstore · 759675c
Dipendenze✓ 60 risolte+ · nessuna vulnerabile
Superficie di strumenti39 strumenti · 2 privilegiati
Analisi di sicurezza✓ Pulitov0.7.0 · 3 g faQuanto è efficace questa analisi?
ValutazioniNessuna
Indicizzato28 ago 2026

La verifica conferma l’identità del publisher (la proprietà del repo), non la sicurezza del codice. L’analisi di sicurezza copre i CVE noti e gli script di installazione sospetti.

Strumenti

39 strumenti · 2 privilegiati
Estratto staticamente dal pacchetto pubblicatov0.7.0 · 3d ago

Letto dal codice che npm distribuisce davvero, al momento dell’analisi. Il pacchetto non è mai stato eseguito. Gli strumenti registrati dinamicamente a runtime, o nascosti in codice impacchettato o minificato, possono sfuggire — quindi questo è un limite inferiore della superficie di strumenti, non un censimento completo.

facebook_list_campaignsList campaigns under one ad account, a cursor page at a time. Each record

List campaigns under one ad account, a cursor page at a time. Each record

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_list_adsetsList ad sets under one ad account, a cursor page at a time. Ad sets are

List ad sets under one ad account, a cursor page at a time. Ad sets are

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_list_adsList individual ads under one ad account, a cursor page at a time. This is

List individual ads under one ad account, a cursor page at a time. This is

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_get_ad_objectRead one campaign, ad set or ad by id. Pass `level` when you know it — the

Read one campaign, ad set or ad by id. Pass `level` when you know it — the

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_ads_insightsRead performance numbers (impressions, clicks, spend, reach, cpc, ctr) for

Read performance numbers (impressions, clicks, spend, reach, cpc, ctr) for

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_ads_report_statusProbe one async insights report run and, with fetch_results:true, read its

Probe one async insights report run and, with fetch_results:true, read its

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_update_ad_objectPause or resume an ads object, or change its budget. Plan-first: without

Pause or resume an ads object, or change its budget. Plan-first: without

Per questo strumento non è stato pubblicato alcuno schema di input.

adsMarketing API access: campaign / ad-set / ad listings with delivery truth,

Marketing API access: campaign / ad-set / ad listings with delivery truth,

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_whoamiReport the identity behind the configured token (type, validity, granted

Report the identity behind the configured token (type, validity, granted

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_list_pagesList the Facebook Pages the operator administers (via /me/accounts): id,

List the Facebook Pages the operator administers (via /me/accounts): id,

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_get_pageFetch metadata for one Page — name, category, follower/fan counts,

Fetch metadata for one Page — name, category, follower/fan counts,

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_usageReport the most recent Graph rate-limit signals (X-App-Usage,

Report the most recent Graph rate-limit signals (X-App-Usage,

Per questo strumento non è stato pubblicato alcuno schema di input.

coreAlways-on identity, Page discovery and rate-limit diagnostics (read-only).

Always-on identity, Page discovery and rate-limit diagnostics (read-only).

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_page_insightsRead Graph insights for one Page in a compact flat shape: one row per

Read Graph insights for one Page in a compact flat shape: one row per

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_post_insightsRead Graph insights for one published post (post_media_view, post_clicks,

Read Graph insights for one published post (post_media_view, post_clicks,

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_reel_insightsRead Graph insights for one Reel from /{video-id}/video_insights — the

Read Graph insights for one Reel from /{video-id}/video_insights — the

Per questo strumento non è stato pubblicato alcuno schema di input.

insightsPage, post and Reel insights: compact reshaped metric series, aggregate

Page, post and Reel insights: compact reshaped metric series, aggregate

Per questo strumento non è stato pubblicato alcuno schema di input.

messagesMessenger conversations for a Page: poll the inbox, read a thread (untrusted

Messenger conversations for a Page: poll the inbox, read a thread (untrusted

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_list_commentsList the comments on a post, photo, video or another comment, newest-first

List the comments on a post, photo, video or another comment, newest-first

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_get_commentRead one comment by ID, optionally with its replies, and report whether a

Read one comment by ID, optionally with its replies, and report whether a

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_reply_to_commentPost a PUBLIC reply under a comment — visible to everyone who can see the

Post a PUBLIC reply under a comment — visible to everyone who can see the

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_hide_commentHide or unhide up to 50 comments in one call (`hidden:true` hides,

Hide or unhide up to 50 comments in one call (`hidden:true` hides,

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_delete_commentprivilegiatoPERMANENTLY delete up to 50 comments. This cannot be undone — prefer

PERMANENTLY delete up to 50 comments. This cannot be undone — prefer

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_private_replySend a private message to the author of a comment. TWO hard limits, both

Send a private message to the author of a comment. TWO hard limits, both

Per questo strumento non è stato pubblicato alcuno schema di input.

moderationRead and moderate comments on Page content (list, reply, hide, delete,

Read and moderate comments on Page content (list, reply, hide, delete,

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_create_postCreate a Page post: plain text, a link, a multi-link card carousel, or a

Create a Page post: plain text, a link, a multi-link card carousel, or a

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_create_photo_postPublish ONE photo to a Page, optionally with a caption, as a draft, or

Publish ONE photo to a Page, optionally with a caption, as a draft, or

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_create_video_postUpload a video to a Page. A local path inside FB_MEDIA_DIR is streamed

Upload a video to a Page. A local path inside FB_MEDIA_DIR is streamed

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_create_reelPublish a Facebook Reel through the three-phase upload (start → transfer

Publish a Facebook Reel through the three-phase upload (start → transfer

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_update_postEdit a Page post the app itself created, or move it through the scheduled-post

Edit a Page post the app itself created, or move it through the scheduled-post

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_delete_postprivilegiatoPermanently delete a Page post the app itself created — including a

Permanently delete a Page post the app itself created — including a

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_list_scheduled_postsList the Page posts that are queued to publish later, each with its publish

List the Page posts that are queued to publish later, each with its publish

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_get_video_statusPoll where one video stands in Meta's pipeline: uploading, processing,

Poll where one video stands in Meta's pipeline: uploading, processing,

Per questo strumento non è stato pubblicato alcuno schema di input.

postsPublish, schedule, edit and delete Page posts, photos, videos and Reels

Publish, schedule, edit and delete Page posts, photos, videos and Reels

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_list_postsList a Page's posts, one cursor page at a time. `edge` selects WHICH posts:

List a Page's posts, one cursor page at a time. `edge` selects WHICH posts:

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_get_postFetch ONE post by its composite id ("{page-id}_{post-id}" as returned by

Fetch ONE post by its composite id ("{page-id}_{post-id}" as returned by

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_list_reelsList a Page's Reels via the /video_reels edge — the ONLY place Reels are

List a Page's Reels via the /video_reels edge — the ONLY place Reels are

Per questo strumento non è stato pubblicato alcuno schema di input.

facebook_get_reactionsRead the reactions on one post: a `totals` map per reaction type

Read the reactions on one post: a `totals` map per reaction type

Per questo strumento non è stato pubblicato alcuno schema di input.

readerRead-only access to a Page's own content: posts (four edges), single posts,

Read-only access to a Page's own content: posts (four edges), single posts,

Per questo strumento non è stato pubblicato alcuno schema di input.

39 strumenti su 39 hanno pubblicato una descrizione.

I nomi e le descrizioni degli strumenti sono scritti dal publisher e mostrati alla lettera come testo inerte. Sono le stringhe che un client MCP passa a un modello, quindi Forge vi cerca schemi di prompt injection — ogni rilievo compare insieme all’analisi di sicurezza qui sopra. «Privilegiato» è una corrispondenza di parola chiave sul nome dello strumento, non una verifica di ciò che fa: un nome innocuo può comunque fare qualsiasi cosa.

Descrizione

Local-first TypeScript MCP server for the Meta Graph API that lets an MCP client publish, read and moderate Facebook Pages through your own Meta developer app, with least-privilege tokens, plan-and-apply write safety and no telemetry.

Parole chiave
mcpmodel-context-protocolfacebookmetagraph-apipagesllmai
Alternative
Confronto delle superfici di strumenti…

Albero delle dipendenze

Ciò che una scansione di Forge ha risolto dai metadati npm il 2026-08-30: risoluzione osservata, non una dichiarazione dell'editore.

60 pacchetti risolti · 3 diretti · nessuno con avvisi di sicurezza La risoluzione si ferma alla profondità 4 e a 60 pacchetti.

La scansione si è fermata al limite di profondità 4. Tutto ciò che sta sotto quel livello non è mai stato risolto.

La scansione si è fermata al limite di 60 pacchetti. Il resto dell'albero non è mai stato risolto.

Altri 36 pacchetti risolti non vengono disegnati qui (limite di visualizzazione: 24). Ogni dipendenza con un avviso di sicurezza viene disegnata comunque. Inventario completo (SBOM CycloneDX)

Dichiarate ma non risolte

55 dipendenze dichiarate non sono mai arrivate nell'albero. Mancano dalla risoluzione di Forge, non dal pacchetto.

+43 altre non elencate. I conteggi per motivo qui sopra le comprendono tutte.

Non seguite: peerDependencies. Questo albero copre solo le dipendenze di runtime, quindi ciò che queste comportano non è mai stato risolto.