The dedicated system user needs Full access to the app and View performance on each intended ad account.
Before you start
- A customer-owned Meta app, a dedicated system user, and ad account IDs for this customer.
1. Create a Meta app
In the customer Business Portfolio, open Business Settings → Apps. Select Add → Create a new app ID.
2. Choose Marketing API and check ads_read
Choose Create & manage ads with Marketing API and confirm ads_read is Ready for testing.
3. Create a system user
Under System users, add a dedicated Employee user. Assign the app with Full access.
4. Grant ad account access
Assign each intended ad account with Partial access limited to View performance.
Use a customer-owned Meta app and a dedicated system user for this connection. Give the system user the app and only the ad accounts Permute should read. The setup screen asks for ads_read and View performance rather than ad-management access.
Enter each assigned ad account ID in Permute. An ID can include or omit the act_ prefix. The list is an explicit limit on the accounts you connect.
5. Generate a token
Generate a token for the app with expiration Never and only ads_read. Copy it immediately.
The form needs the Meta App ID, App Secret, system-user access token, and ad account IDs. Copy the ID and secret from the same app that was assigned to the system user. Generate its token with ads_read, then copy it before closing the token dialog.
Treat the App Secret and token as passwords. If the token is exposed, replace it in Meta.
6. Add Meta Ads in Permute
In your workspace, open Connectors, select Add Connector, choose Meta Ads, and name the account.
Under Sync which data?, choose an option:
| Choice | What it does |
|---|---|
| Everything | Selects all discovered data available to this connection. |
| Select manually | Choose the tables Permute syncs. |
Connection details
| Field or access | What to use |
|---|---|
| App ID and App Secret | Copy from the customer-owned Meta app. |
| System user token | Generate for that app with only ads_read. |
| Ad account IDs | Enter the assigned IDs, separated by commas. The act_ prefix is optional. |
- Copy the App ID and App Secret from the app settings.
- Enter the App ID, App Secret, system user token, and assigned ad account IDs. Separate IDs with commas; the act_ prefix is optional.
- Select Connect.
7. Choose tables (manual selection)
If you chose Select manually, open the connector after connecting. Use the checkboxes to select at least one table, then select Save selection.
8. Check the first result
- Check one ad account ID against the assigned IDs in Meta Business Settings.
- Compare an available day of performance for that account after connecting.
Available data
| Data group | What the setup screen covers |
|---|---|
| Campaign structure | Campaign structure named on the setup screen. |
| Performance | Daily ad performance. |
Check the explicit account list
Permute asks for ad account IDs separated by commas. You may include or omit the act_ prefix. Only enter IDs assigned to the dedicated system user. A typo in one ID can leave that account out even if the others connect.
When one advertiser is absent, compare its ID in Meta with the Permute form and check View performance on that account. If all accounts fail, check the app, secret, system-user token, and ads_read setup together.
Troubleshooting
| Problem | What to check |
|---|---|
| No permissions available | Check the Marketing API use case, app assignment, and ad-account assignments. |
| An account is absent | Check its ID and View performance assignment for the system user. |