Who completes each part
Never ask a client administrator to create a system user inside FloKit’s Business Portfolio. Never ask
them to send a token through email, chat, a ticket, or a document.
Before you start
You need:- administrator access to the client’s Meta Business Portfolio;
- the exact production ad account;
- the Facebook Page that will represent the ads;
- an Instagram Professional account linked to that Page if Instagram delivery is required;
- the Instagram account asset itself shared to FloKit when Instagram is required;
- the pixel or dataset only when the intended objective requires it;
- the existing FloKit Production Meta App. Do not create another Meta Developer App.
FloKit Production Meta App preflight
A FloKit operator confirms:- The existing App has the Marketing API product or use case enabled.
- The App has the access level required to manage client-owned ad accounts, including Advanced
Access for
ads_readandads_managementwhere Meta requires it. - The App is owned by FloKit’s expected Business Portfolio.
- The dedicated system user is assigned the existing App with the appropriate App role, shown as Develop App where Meta displays that option.
- FloKit’s production credential vault and App Secret Proof signing are deployed and healthy.
- FloKit uses one explicitly pinned Graph API version. The Ready screen shows the actual pin; do not
infer it from the newest Meta SDK. As of August 12, 2026, the expected production value is
v24.0. A version upgrade requires a separate compatibility test and release.
Meta-side configuration
1
Client administrator: confirm the assets
In Meta Business Settings, select the client’s Business
Portfolio and confirm:
- the production ad account is active, funded, and uses the expected currency;
- the Facebook Page is owned by or assigned to that Business;
- no unresolved Account Quality, identity-confirmation, or authentication restriction exists;
- the Instagram account is Professional and linked to the Page when Instagram delivery is needed;
- the pixel or dataset is available when the selected objective requires it.
2
Client administrator: share the exact assets with FloKit
- Go to Users → Partners.
- Choose the option to give a partner access to assets.
-
Enter FloKit.AI’s Business Portfolio ID:
- Share only the exact production ad account and Facebook Page needed by the selected FloKit App.
- If Instagram delivery is required, also share the Instagram account asset itself. Sharing only its linked Page is not sufficient proof of Instagram access.
- Share a pixel or dataset only when the selected objective requires it.
- Grant the minimum advertiser/manage permissions required for those assets.
3
FloKit operator: create the dedicated production system user
In the FloKit.AI Business Portfolio:
- Go to Users → System users → Add.
- Use a client-, App-, and environment-specific name, such as
<client>-<app>-prod. - Assign only the client’s shared production ad account and Page.
- Assign the Instagram account asset when Instagram delivery is required.
- Assign the optional pixel or dataset only when required.
- Assign the existing FloKit Production Meta App with the appropriate App role.
4
FloKit operator: generate the system-user token
- Select the dedicated system user.
- Select Generate token.
- Choose the existing FloKit Production Meta App.
-
Grant all five production permissions:
- When Instagram delivery is required, select any additional Instagram permission Meta makes available for the existing App and that FloKit operations has approved. FloKit does not rely on a permission name alone; it performs a live read-only probe of the exact Instagram account.
- Choose the approved expiry policy and record the expiry as non-secret evidence.
- Generate and copy the token once.
5
Get the numeric system-user ID
FloKit requires the token’s numeric Graph subject ID, not an email address.Copy the numeric
- Open Meta’s Access Token Debugger.
- Inspect the generated system-user token.
- Copy User ID.
id returned by /me.Values for the FloKit connection form
The three values must describe the same credential. FloKit rejects a token issued by another App, an
email in the System user ID field, a system user that does not belong to the declared Business
Portfolio, or a different Business Portfolio ID.
What FloKit validates before storage
FloKit proves all of the following before encrypting and activating the credential:- Meta reports the token as valid;
- all five required production permissions are present;
- the issuing App ID matches the configured FloKit Production Meta App;
/me.idmatches the entered numeric System user ID;- the declared Business Portfolio is readable;
- the declared system user appears in that Business Portfolio’s
system_usersrelationship.
- the exact ad account is accessible, eligible, and in the expected currency;
- the selected Page is accessible and carries an advertising-capable task, including supported classic and New Pages Experience task forms;
- a selected Instagram ID is linked to that Page and directly readable with the same production credential;
- a selected pixel or dataset belongs to the selected ad account.
Connect Meta in FloKit.AI
1
Open the correct FloKit App
- Sign in to the FloKit.AI dashboard.
- Select the exact App that will use the Meta assets.
- Go to Governance → Integrations.
- On Meta Ads, select Use this provider or Manage.
2
Validate the production system-user credential
- Enter the system-user access token.
- Enter the numeric Graph System user ID.
- Enter Business Portfolio ID
1029935126415408. - Select Validate & connect once.
3
Select the ad account
Select the exact production ad account. Check its name, ID, currency, status, and advertiser/manage
access before importing existing ads for the selected FloKit App.
4
Select the ad identity
Select the exact Facebook Page. FloKit disables or rejects a Page when the production system user
lacks an advertising-capable Page task.If the Page exposes a linked Instagram Professional account, verify its ID or username. FloKit
performs a direct read-only Graph request for that Instagram ID before saving it.
5
Confirm the category limitation
Confirm the checkbox only when no Meta special or restricted ad category applies to the
campaigns being configured.If any category applies, stop and contact FloKit. Do not check the box merely to finish setup.
6
Choose delivery channels
Choose Facebook only, Instagram only, or Facebook + Instagram.Instagram choices remain unavailable until a linked Instagram Professional account is selected.
FloKit rechecks direct access to that account before saving an Instagram channel choice.
7
Confirm Ready
Confirm that Meta Ads shows Ready, Manage opens on the Ready step, and the displayed values
are exact:
- ad account and currency;
- Facebook Page;
- optional Instagram identity;
- enabled delivery channels;
- pinned Graph API version;
- credential expiry, or an explicit statement that Meta did not report one.
Production verification
Before allowing any activation:- import or read existing ads without creating new provider objects;
- verify the credential belongs to the dedicated Business system user and declared Business Portfolio;
- verify the exact ad account, Page task, Instagram identity, and Graph API version;
- create a canary only with explicit approval;
- keep the Campaign, Ad Set, Creative, and Ad paused;
- read back every Meta object status;
- confirm no duplicate hierarchy exists and amount spent is unchanged.
Token expiry, rotation, and offboarding
- Record the expiry shown on the Ready screen.
- FloKit warns when an expiry is within 14 days. Rotate early enough to qualify the replacement before interruption.
- Rotation creates and qualifies a new immutable credential version before making it active. Do not overwrite a token in place or revoke the active token first.
- Keep the previous qualified version only for the approved rollback window, then revoke it in Meta.
- Even when Meta reports no expiry, rotate according to FloKit’s security policy.
- During offboarding, disable FloKit writes, revoke the active token, remove client assets from the system user, remove partner access when appropriate, and retain only non-secret audit evidence.
Troubleshooting
Validate & connect is disabled
All three fields are required and both IDs must be numeric. Remove password-manager autofill, then enter the full token, numeric Graph System user ID, and1029935126415408.
The token belongs to a different Meta App
Regenerate the token for the existing FloKit Production Meta App. Do not create a replacement App.Required permissions are missing
Regenerate the token with all five production permissions selected. FloKit validates all five before storage; Page permissions are not advisory.The token does not resolve to the entered system user
Replace the value with the numeric User ID from Meta’s Access Token Debugger or/me.id. Do not
use an email address or assume another Business Settings ID is equivalent.
The system user does not belong to the Business Portfolio
Confirm that the system user was created inside the FloKit.AI Business Portfolio and that the form uses1029935126415408. Accessibility to an asset does not prove Business membership.
No ad accounts or Pages appear
Return to the client Business Portfolio and share the exact assets with FloKit Business Portfolio1029935126415408. Then assign them to the dedicated system user.
The Page cannot be selected
Grant the dedicated system user an advertising-capable task for that Page. Read-only analysis or content-only Page tasks are insufficient for production ad delivery.Instagram delivery is unavailable
Confirm all four conditions:- the account is Instagram Professional;
- it is linked to the selected Facebook Page;
- the Instagram account asset itself is shared with FloKit and assigned to the dedicated system user;
- the production token can directly read the exact Instagram ID.