Learn · Setup guides
Meta Marketing API App Review: approval checklist
Last updated:
In short
Meta App Review for the Marketing API is where Meta checks your app, business, data handling, and requested permissions against its platform requirements before granting higher Marketing API access. It is separate from connecting a token to Outloop.
Connecting Meta Ads access to Outloop proves the runtime path on your own business assets. App Review proves to Meta that your app settings, data handling, reviewer instructions, and use case follow Meta's rules. Submit a narrow, accurate use case, and never claim approval before Meta grants it.
Approval is separate from connecting a token
Connecting Meta Ads API access to Outloop proves the runtime path. App Review proves to Meta that your app, business, data handling, and requested permissions follow Meta's platform requirements. They are two different jobs, done at different times.
Already setting up the token? Start with the Connect Meta Ads API to Outloop guide for local setup and a safe read-only proof, then come back here for the approval submission.
What this approval is for
Marketing API Access Tier review covers authorized ad account workflows, including:
- ✓Agency or internal business usage
- ✓Reporting
- ✓Campaign structure review
- ✓Budget checks
- ✓Campaign creation or updates, if requested and approved
Use a narrow, accurate use case. Do not describe the app as unrestricted AI ad automation. Describe it as authorized Meta Marketing API access for business and ad accounts the user is permitted to manage.
The app being reviewed is yours
Your agency creates and controls its own Meta Developer account and its own dedicated Meta app, and submits that app under your own legal entity, domain and policy URLs. Outloop does not provide a shared developer account, a shared app, or a shared token, and cannot submit or shorten a review for you. Outloop begins once your own approved credentials are connected — see professional API access readiness.
Before you start
Meta apps start at Standard Access, which only lets you request permissions from people who hold a role on your app. Production scale needs Advanced Access, and that is what this review is for. Business Verification is the long pole — start it first. Meta does not publish a guaranteed review time, so plan around the dependency rather than a date.
Confirm each of these before opening the review submission:
- ✓Your own Meta app created, in your own Meta Developer account
- ✓Business Portfolio connected
- ✓Business verification complete where required — normally required once your app requests advanced-level access to reach data belonging to businesses outside your own
- ✓At least one successful API call made with each permission you are requesting, within the 30 days before you submit — a common rejection cause
- ✓Only the permissions your workflows genuinely need — request write permissions only where the workflow writes
- ✓App icon uploaded
- ✓App domain set to your agency's own domain
- ✓Privacy policy URL exists
- ✓Terms URL exists
- ✓Data deletion URL exists
- ✓Website platform added
- ✓Reviewer instructions prepared
- ✓No raw access tokens in screenshots or videos
App settings
These are your agency's values, for your agency's app. Replace every
[bracketed] placeholder with your own domain
before submitting — never submit another company's domain or policy URLs.
App domains
[your-agency-domain.com]
Privacy Policy URL
https://[your-agency-domain.com]/privacy
Terms of Service URL
https://[your-agency-domain.com]/terms
User Data Deletion
Data deletion instructions URL
Data deletion URL
https://[your-agency-domain.com]/data-deletion
Category
Business and pages
Contact email: prefer a business contact email. If needed, use the account email already accepted by Meta.
DPO: leave blank unless the company has formally appointed a Data Protection Officer. Do not invent a DPO. If Meta requires a contact, use a privacy contact and do not label it as a formal DPO unless that is legally true.
Add platform: Website
Add the Website platform, then set the site URL and add or update website testing instructions.
Site URL
https://[your-agency-domain.com]/
Data handling
If Meta Platform Data may be processed by an AI model provider during an authorized workflow, answer Yes to processors, then declare the processor accurately.
Processor
Anthropic PBC
Processor category
IT solutions and services, including cloud storage and processing
Countries: use the countries shown in the provider's public data processing / server information. Avoid inventing countries.
Data controller / responsible entity
ARGAMAN X MEDIA LTD
Country
Israel
National security requests: if true, select No.
Public authority request policies: select the policies the company actually maintains or is adopting — do not select "None of the above" if these processes exist:
- ✓Required review of the legality of these requests
- ✓Provisions for challenging these requests if they are considered unlawful
- ✓Data minimization policy
- ✓Documentation of these requests, including responses and legal reasoning
Reviewer instructions
Provide separated copy blocks. You are submitting your agency's own app, so every URL,
entity name, and contact below must be yours — your website, your privacy policy, your terms,
your data deletion page. Replace every [bracketed]
placeholder before submitting; do not submit another company's URLs.
Where can we find the app?
[https://your-agency-domain.com]
Provide instructions for accessing the app
[YOUR APP NAME] is used by [YOUR LEGAL ENTITY NAME] for authorized Meta Marketing API workflows on ad accounts we are authorized to manage. Please review these public pages: Website: [https://your-agency-domain.com] Privacy Policy: [https://your-agency-domain.com/privacy] Terms: [https://your-agency-domain.com/terms] Data Deletion Instructions: [https://your-agency-domain.com/data-deletion] The submitted use case is Meta Marketing API access for advertising workflows, including ad account review, reporting, campaign structure review, budget checks, and approved campaign operations. We use Meta/Facebook authorization only for authorized business and advertising account access. We do not use Facebook Login to collect consumer social profile data such as friends, birthday, gender, or similar personal profile information. [YOUR LEGAL ENTITY NAME] does not sell Meta Platform Data, does not use it for data brokerage, and does not use it for unrelated advertising targeting. Meta API access is used only for ad accounts connected to our authorized business or client workflows.
If payment or membership is required
No payment or membership is required to review the public website, privacy policy, terms, and data deletion page. The full runtime product is a controlled local macOS workflow for authorized business users. If Meta requires a guided review or demo access, please contact [your reviewer contact email] and we will provide a reviewer walkthrough or temporary test access.
If payment is required to download this app
No payment is required to access the public website. The app is not distributed through an app store, so gift codes are not applicable.
Geographic restrictions
There are no geographic restrictions or geo-blocking for https://[your-agency-domain.com].
Facebook Login integrated: No — the website does not use Facebook Login.
Supporting documentation
Supporting documentation is optional, but useful if it is clean. A short walkthrough video can:
- ✓Show the public website
- ✓Show the privacy, terms, and data deletion pages
- ✓Show the Meta Ads workflow purpose
- ✓Show Outloop using the Meta Marketing API for an authorized ad account
- ✓Show no token in the UI, no Authorization header, and
secret_exposed:false - ✓Show the audit / result proof if available
Do not show the app secret, access tokens, client secrets, Authorization headers, or private customer data in any screenshot or video.
After you submit
After submitting, status may show Review in progress, and the request may list Marketing API Access Tier. Recommended follow-up:
- ✓Monitor Required actions
- ✓Monitor the Alert Inbox
- ✓Respond quickly to reviewer questions
- ✓Do not change app settings during review unless requested
- ✓Keep the privacy, terms, and data deletion pages live
- ✓Preserve screenshots / video proof in case Meta asks for more detail
What not to do
- ✕Do not show the app secret
- ✕Do not paste access tokens into docs, screenshots, email, or chat
- ✕Do not claim approval before Meta approves
- ✕Do not describe the product as unrestricted AI ad automation
- ✕Do not say Facebook Login is integrated if the website does not use it
- ✕Do not list processors that do not receive Meta Platform Data
- ✕Do not invent a Data Protection Officer
- ✕Do not use a dead data deletion URL
Related: Connect Meta Ads API to Outloop · Data Deletion Request · Privacy Policy · Terms of Service.
Outloop is available with guided onboarding for agency teams. Outloop is an independent tool and is not affiliated with or endorsed by Meta. App Review outcomes are decided by Meta; this guide does not guarantee approval. See the security model.
Run Meta Ads agents without handing over tokens.
Outloop is available with guided onboarding for AI agencies, operators, and dev shops.