Security

Paranoid by design.

You're handing an AI the keys to your ad accounts. Here's exactly how MegaMCP keeps those keys safe, and keeps the AI on a leash.

Last updated:

OAuth only

No passwords, no API keys pasted anywhere. You sign in with MegaMCP, Google and Meta directly, and can revoke any of it in one click.

Encrypted tokens

Platform tokens are encrypted with AES-256-GCM, with versioned keys for rotation, and bound to the database row they belong to.

Humans approve

Your AI can only propose. Every change is a plan with a diff that waits for a person, and budget bumpers can block it outright.

Undo

Every applied change records how to reverse itself. Undo is its own plan, with its own diff and approval.

Flight recorder

Every tool call, plan, approval, connection and billing event is logged with who did it and from which AI app.

No training

We never use your data or your platform data to train AI models. Report data passes through; we don't keep it.

14 days. On the house.

Put Mega to work.
Your soul stays yours. So does your ad budget.

No credit card to start. Every workspace comes with a sandbox ad account, so you can watch the whole ask, diff, approve, undo loop before you connect anything real.

Get launch updates

New integrations, platform approvals, the occasional dark joke. One or two emails a month. Unsubscribe anytime.