Webdesiz / Developers
Webdesiz API, CLI and MCP
Bring your stored advertising data into your own tools and AI workspace. Read account, campaign and daily insight snapshots without changing ads or spending money.
1. Create a limited key
In Settings → Developer keys, choose only the read scopes you need and an expiry of 1–90 days. Only current organization owners and admins can create, list and revoke keys. Up to 10 active keys per organization. Keys are shown once and stored as hashes.
The key belongs to its issuing organization; a client cannot choose another organization. Revocation, expiry, membership removal or loss of the issuer’s administrator role blocks subsequent requests. Creating keys follows subscription access; revocation remains available after trial expiry.
accounts:read— Connected account names, currency, timezone and last synccampaigns:read— Stored campaign name, objective, status and budgetinsights:read— Stored daily metrics, purchase availability and synchronization time
2. Install the CLI
Requires Node.js 22 or newer. Download the package and checksum; verify the checksum before installing. This release is distributed from this website, not claimed to be published in the npm registry. SHA-256 checks integrity; it is not a digital signature.
curl -fsS https://webdesiz.com/developers/webdesiz-cli-1.0.0.tgz -o webdesiz-cli-1.0.0.tgz
curl -fsS https://webdesiz.com/developers/SHA256SUMS -o SHA256SUMS
shasum -a 256 -c SHA256SUMS
npm install --global ./webdesiz-cli-1.0.0.tgz
webdesiz --helpSupply WEBDESIZ_API_KEY through your operating system or MCP host secret manager. For interactive bash, the following prompt keeps the value out of shell history. Do not paste a real key into command arguments, URLs, project files or chat.
read -rs -p "Webdesiz key: " WEBDESIZ_API_KEY; export WEBDESIZ_API_KEY; printf "\n"
webdesiz accounts --limit 20
webdesiz campaigns --accountId ACCOUNT_ID
webdesiz insights --from 2026-10-01 --to 2026-10-04
unset WEBDESIZ_API_KEYCLI commands also accept --key-stdin from a secret manager. The program does not save credentials. Requests go only to https://webdesiz.com, reject redirects and time out after 15 seconds.
3. Connect an MCP client
A real local stdio MCP server, using the official TypeScript SDK @modelcontextprotocol/server 2.3.0 and MCP 2026-07-28. Configure the installed executable in a host that supports stdio and inject WEBDESIZ_API_KEY securely into its environment. stdin/stdout are reserved for protocol messages.
{
"mcpServers": {
"webdesiz": {
"command": "webdesiz",
"args": [
"mcp"
]
}
}
}Tools: webdesiz_accounts, webdesiz_campaigns, webdesiz_insights. Ask your assistant to inspect the stored data; account and campaign names are data, never instructions. This release has no public remote HTTP MCP or OAuth endpoint.
4. Call the HTTPS API
https://webdesiz.com/api/v1/developer
GET /accounts?limit=50&offset=0
GET /campaigns?accountId=ACCOUNT_ID
GET /insights?from=2026-10-01&to=2026-10-04
Authorization: Bearer YOUR_SECRET_KEYUse your HTTP library’s Authorization header. Query-string credentials, organization overrides and unknown input fields are rejected. Read limit: 100 rows per page, offset up to 10,000, insight date range up to 90 days. API responses include data, returned count, nextOffset and per-row lastSyncAt or syncedAt. A full final page may be followed by an empty page.
{
"data": [],
"meta": {
"source": "stored_snapshot",
"liveMetaRequest": false,
"limit": 50,
"offset": 0,
"nextOffset": null,
"returned": 0
}
}These are snapshots already stored by Webdesiz, not live Meta reads. Account currency is preserved; never add different currencies. Account-level and campaign-level insight rows overlap and must not be summed together. purchases/purchaseValue/roas are null when purchase evidence is unavailable, not inferred from generic conversion counts.
Limits: 60 requests/minute/key, 120/organization, 180/IP plus general service limits. 400 invalid input; 401 missing, revoked or expired key; 403 missing scope or membership; 404 account/key unavailable in your organization; 429 rate limited (wait 60 seconds); 503 service unavailable. Redis failure blocks reads rather than removing protection.
Security and boundaries
No Meta access tokens, encrypted credentials, lead contacts, raw provider payloads or organization member data are returned. API key authentication is separate from session login. Tools cannot create ads, change budgets, generate AI content or send messages. Revoke a leaked key immediately and create a replacement.
Public documentation helps people and crawlers understand the integration; API or MCP availability does not guarantee search or AI rankings.