OAuth only
No passwords, no API keys pasted anywhere. You sign in with MegaMCP, Google and Meta directly, and can revoke any of it in one click.
Security
You're handing an AI the keys to your ad accounts. Here's exactly how MegaMCP keeps those keys safe, and keeps the AI on a leash.
Last updated:
No passwords, no API keys pasted anywhere. You sign in with MegaMCP, Google and Meta directly, and can revoke any of it in one click.
Platform tokens are encrypted with AES-256-GCM, with versioned keys for rotation, and bound to the database row they belong to.
Your AI can only propose. Every change is a plan with a diff that waits for a person, and budget bumpers can block it outright.
Every applied change records how to reverse itself. Undo is its own plan, with its own diff and approval.
Every tool call, plan, approval, connection and billing event is logged with who did it and from which AI app.
We never use your data or your platform data to train AI models. Report data passes through; we don't keep it.
Through each platform's official OAuth flow, protected by a signed, single-use state value (and PKCE where the platform supports it). After you connect, every account starts switched off; your AI only sees the accounts an admin switches on. We request only the scopes MegaMCP's features use:
| Scope | Why |
|---|---|
openid | Identify which Google account you connected. |
email | Show which Google account a connection belongs to. |
adwords | Google Ads API access. Google offers only this one scope; MegaMCP's own approvals decide what actually changes. |
analytics.readonly | Run GA4 reports. |
analytics.edit | Mark events as key events (only after you approve the plan). |
webmasters | Read Search Console performance, inspect URLs, submit sitemaps (after approval). |
tagmanager.readonly | Read and audit Tag Manager containers. |
tagmanager.edit.containers | Create and pause tags in a workspace (after approval). |
tagmanager.edit.containerversions | Create a container version so a workspace can be published. |
tagmanager.publish | Publish a workspace, always as its own approved plan. |
| Permission | Why |
|---|---|
ads_read | Read campaigns, ad sets, ads and insights. |
ads_management | Make the changes you approve (pause, budgets, duplicate, create paused ads). |
business_management | Find ad accounts owned by your Business Manager. |
Google lets you untick individual permissions on its consent screen. MegaMCP tells you which features a partial grant affects.
The flight recorder logs every tool call (with its arguments), plan, approval, rejection, change, undo, connection, team change and billing event, with the person and the AI app behind it. It's searchable in the dashboard and admins can export it as CSV.
HttpOnly, SameSite, Secure cookies.We don't sell your data and we never use it (or data from Google or Meta) to train AI models. Report data your AI requests is passed through and not stored. Google data is handled under Google's API Services User Data Policy, including the Limited Use requirements. The full story is in our Privacy Policy.
| Provider | Purpose |
|---|---|
| Railway | Application hosting and managed Postgres database |
| Stripe | Subscription billing and payments |
| Resend | Transactional email (sign-in links, invitations, workflow emails) |
| Google APIs | Google Ads, Analytics, Search Console and Tag Manager, at the customer's direction |
| Meta Platforms | Meta Marketing API, at the customer's direction |
Found a vulnerability? Email security@megamcp.com with what you found, steps to reproduce, and the impact you think it has. We'll acknowledge your report, keep you updated while we fix it, and credit you if you'd like.
Please test only against your own account and workspace, don't access or modify other people's data, don't degrade the service (no denial-of-service or spam), don't use social engineering, and give us reasonable time to fix the issue before disclosing it. If you follow these guidelines in good faith, we won't pursue legal action against you for your research.
Machine-readable contact details: /.well-known/security.txt.
We don't browse customer accounts. Platform tokens are encrypted and only used to run the tools you and your AI call. We'd only look at your data with your permission (for example, in a support request), for security investigations, or when the law requires it.
It still can't change anything on its own. Write tools only create plans; applying one needs a human approval, budget bumpers still apply, and approvals in chat are off unless an admin turns them on. MegaMCP also tells the AI to treat platform data like search terms and page titles as untrusted, never as instructions.
They're wiped from our database immediately and we ask Google or Meta to revoke them. The accounts are switched off.
Not yet. We're an early-stage company and we'd rather tell you that than wave a badge. Ask us for our security questionnaire answers at security@megamcp.com.
14 days. On the house.
No credit card to start. Every workspace comes with a sandbox ad account, so you can watch the whole ask, diff, approve, undo loop before you connect anything real.
New integrations, platform approvals, the occasional dark joke. One or two emails a month. Unsubscribe anytime.