Skip to main content
Use this guide for production Meta Ads delivery. FloKit uses a dedicated Meta Business system user so automated campaign operations do not depend on a person’s Facebook session.
Production supports the Business system-user path only. Facebook Login is not a production credential. Connecting Meta does not authorize spend, and this setup currently supports only campaigns where no Meta special or restricted ad category applies. Stop if any category applies.

Who completes each part

Never ask a client administrator to create a system user inside FloKit’s Business Portfolio. Never ask them to send a token through email, chat, a ticket, or a document.

Before you start

You need:
  • administrator access to the client’s Meta Business Portfolio;
  • the exact production ad account;
  • the Facebook Page that will represent the ads;
  • an Instagram Professional account linked to that Page if Instagram delivery is required;
  • the Instagram account asset itself shared to FloKit when Instagram is required;
  • the pixel or dataset only when the intended objective requires it;
  • the existing FloKit Production Meta App. Do not create another Meta Developer App.

FloKit Production Meta App preflight

A FloKit operator confirms:
  1. The existing App has the Marketing API product or use case enabled.
  2. The App has the access level required to manage client-owned ad accounts, including Advanced Access for ads_read and ads_management where Meta requires it.
  3. The App is owned by FloKit’s expected Business Portfolio.
  4. The dedicated system user is assigned the existing App with the appropriate App role, shown as Develop App where Meta displays that option.
  5. FloKit’s production credential vault and App Secret Proof signing are deployed and healthy.
  6. FloKit uses one explicitly pinned Graph API version. The Ready screen shows the actual pin; do not infer it from the newest Meta SDK. As of August 12, 2026, the expected production value is v24.0. A version upgrade requires a separate compatibility test and release.

Meta-side configuration

1

Client administrator: confirm the assets

In Meta Business Settings, select the client’s Business Portfolio and confirm:
  • the production ad account is active, funded, and uses the expected currency;
  • the Facebook Page is owned by or assigned to that Business;
  • no unresolved Account Quality, identity-confirmation, or authentication restriction exists;
  • the Instagram account is Professional and linked to the Page when Instagram delivery is needed;
  • the pixel or dataset is available when the selected objective requires it.
If Meta requests a password, 2FA, email, phone, identity, or business-authenticity check, the authorized client administrator completes it directly in Meta. FloKit must not bypass it.
2

Client administrator: share the exact assets with FloKit

  1. Go to Users → Partners.
  2. Choose the option to give a partner access to assets.
  3. Enter FloKit.AI’s Business Portfolio ID:
  4. Share only the exact production ad account and Facebook Page needed by the selected FloKit App.
  5. If Instagram delivery is required, also share the Instagram account asset itself. Sharing only its linked Page is not sufficient proof of Instagram access.
  6. Share a pixel or dataset only when the selected objective requires it.
  7. Grant the minimum advertiser/manage permissions required for those assets.
Do not share unrelated client assets.
3

FloKit operator: create the dedicated production system user

In the FloKit.AI Business Portfolio:
  1. Go to Users → System users → Add.
  2. Use a client-, App-, and environment-specific name, such as <client>-<app>-prod.
  3. Assign only the client’s shared production ad account and Page.
  4. Assign the Instagram account asset when Instagram delivery is required.
  5. Assign the optional pixel or dataset only when required.
  6. Assign the existing FloKit Production Meta App with the appropriate App role.
Never reuse one client’s system user or credential for another client.
4

FloKit operator: generate the system-user token

  1. Select the dedicated system user.
  2. Select Generate token.
  3. Choose the existing FloKit Production Meta App.
  4. Grant all five production permissions:
  5. When Instagram delivery is required, select any additional Instagram permission Meta makes available for the existing App and that FloKit operations has approved. FloKit does not rely on a permission name alone; it performs a live read-only probe of the exact Instagram account.
  6. Choose the approved expiry policy and record the expiry as non-secret evidence.
  7. Generate and copy the token once.
Treat the token as a password. Do not put it in chat, email, tickets, screenshots, documents, terminal commands, clipboard history, source control, or agent prompts. Enter it only in FloKit’s password-masked connection form.
5

Get the numeric system-user ID

FloKit requires the token’s numeric Graph subject ID, not an email address.
  1. Open Meta’s Access Token Debugger.
  2. Inspect the generated system-user token.
  3. Copy User ID.
If Meta does not display it clearly, open Graph API Explorer, use the generated token, and request:
Copy the numeric id returned by /me.
Do not enter an email address, Meta App ID, ad account ID, Facebook Page ID, FloKit Company ID, or an unrelated Business Settings row ID in FloKit’s System user ID field.

Values for the FloKit connection form

The three values must describe the same credential. FloKit rejects a token issued by another App, an email in the System user ID field, a system user that does not belong to the declared Business Portfolio, or a different Business Portfolio ID.

What FloKit validates before storage

FloKit proves all of the following before encrypting and activating the credential:
  • Meta reports the token as valid;
  • all five required production permissions are present;
  • the issuing App ID matches the configured FloKit Production Meta App;
  • /me.id matches the entered numeric System user ID;
  • the declared Business Portfolio is readable;
  • the declared system user appears in that Business Portfolio’s system_users relationship.
FloKit then validates assets independently:
  • the exact ad account is accessible, eligible, and in the expected currency;
  • the selected Page is accessible and carries an advertising-capable task, including supported classic and New Pages Experience task forms;
  • a selected Instagram ID is linked to that Page and directly readable with the same production credential;
  • a selected pixel or dataset belongs to the selected ad account.
Accessibility of one object never substitutes for proof of another.

Connect Meta in FloKit.AI

1

Open the correct FloKit App

  1. Sign in to the FloKit.AI dashboard.
  2. Select the exact App that will use the Meta assets.
  3. Go to Governance → Integrations.
  4. On Meta Ads, select Use this provider or Manage.
2

Validate the production system-user credential

  1. Enter the system-user access token.
  2. Enter the numeric Graph System user ID.
  3. Enter Business Portfolio ID 1029935126415408.
  4. Select Validate & connect once.
Production does not offer Facebook Login as a fallback. If validation fails, correct the App, scope, subject, Business membership, or asset assignment before retrying. Do not repeatedly regenerate tokens or retry a Meta security checkpoint.
3

Select the ad account

Select the exact production ad account. Check its name, ID, currency, status, and advertiser/manage access before importing existing ads for the selected FloKit App.
4

Select the ad identity

Select the exact Facebook Page. FloKit disables or rejects a Page when the production system user lacks an advertising-capable Page task.If the Page exposes a linked Instagram Professional account, verify its ID or username. FloKit performs a direct read-only Graph request for that Instagram ID before saving it.
5

Confirm the category limitation

Confirm the checkbox only when no Meta special or restricted ad category applies to the campaigns being configured.If any category applies, stop and contact FloKit. Do not check the box merely to finish setup.
6

Choose delivery channels

Choose Facebook only, Instagram only, or Facebook + Instagram.Instagram choices remain unavailable until a linked Instagram Professional account is selected. FloKit rechecks direct access to that account before saving an Instagram channel choice.
7

Confirm Ready

Confirm that Meta Ads shows Ready, Manage opens on the Ready step, and the displayed values are exact:
  • ad account and currency;
  • Facebook Page;
  • optional Instagram identity;
  • enabled delivery channels;
  • pinned Graph API version;
  • credential expiry, or an explicit statement that Meta did not report one.

Production verification

Before allowing any activation:
  • import or read existing ads without creating new provider objects;
  • verify the credential belongs to the dedicated Business system user and declared Business Portfolio;
  • verify the exact ad account, Page task, Instagram identity, and Graph API version;
  • create a canary only with explicit approval;
  • keep the Campaign, Ad Set, Creative, and Ad paused;
  • read back every Meta object status;
  • confirm no duplicate hierarchy exists and amount spent is unchanged.
Activation is a separate approved action and is not part of connection or qualification.

Token expiry, rotation, and offboarding

  • Record the expiry shown on the Ready screen.
  • FloKit warns when an expiry is within 14 days. Rotate early enough to qualify the replacement before interruption.
  • Rotation creates and qualifies a new immutable credential version before making it active. Do not overwrite a token in place or revoke the active token first.
  • Keep the previous qualified version only for the approved rollback window, then revoke it in Meta.
  • Even when Meta reports no expiry, rotate according to FloKit’s security policy.
  • During offboarding, disable FloKit writes, revoke the active token, remove client assets from the system user, remove partner access when appropriate, and retain only non-secret audit evidence.

Troubleshooting

Validate & connect is disabled

All three fields are required and both IDs must be numeric. Remove password-manager autofill, then enter the full token, numeric Graph System user ID, and 1029935126415408.

The token belongs to a different Meta App

Regenerate the token for the existing FloKit Production Meta App. Do not create a replacement App.

Required permissions are missing

Regenerate the token with all five production permissions selected. FloKit validates all five before storage; Page permissions are not advisory.

The token does not resolve to the entered system user

Replace the value with the numeric User ID from Meta’s Access Token Debugger or /me.id. Do not use an email address or assume another Business Settings ID is equivalent.

The system user does not belong to the Business Portfolio

Confirm that the system user was created inside the FloKit.AI Business Portfolio and that the form uses 1029935126415408. Accessibility to an asset does not prove Business membership.

No ad accounts or Pages appear

Return to the client Business Portfolio and share the exact assets with FloKit Business Portfolio 1029935126415408. Then assign them to the dedicated system user.

The Page cannot be selected

Grant the dedicated system user an advertising-capable task for that Page. Read-only analysis or content-only Page tasks are insufficient for production ad delivery.

Instagram delivery is unavailable

Confirm all four conditions:
  1. the account is Instagram Professional;
  2. it is linked to the selected Facebook Page;
  3. the Instagram account asset itself is shared with FloKit and assigned to the dedicated system user;
  4. the production token can directly read the exact Instagram ID.
Correct any permission Meta reports as missing, then reconnect and select the Page again.

A special or restricted category applies

Stop. The current FloKit setup cannot qualify that campaign. Do not confirm the no-category checkbox.

The Graph API version differs from the expected release

Do not change Meta settings or the FloKit environment ad hoc. Record the version shown on Ready and escalate it to FloKit operations. Graph version upgrades require a reviewed compatibility release.

Meta requests authentication or identity confirmation

The authorized client Business administrator must complete Meta’s password, 2FA, email, phone, identity, or business-authenticity confirmation in Meta. Do not replace a password or create a new token to bypass an account-level security restriction.