Skip to main content
Connecting your Meta (Facebook/Instagram) ad account lets Goose pull a daily performance report, review the ads you’re actually running, and learn what works for your brand — so the creatives it makes for you keep getting sharper. The connection is per brand: you paste a System User access token from your Meta Business account into that brand’s Settings in Goose. It sounds technical, but it’s a handful of clicks in Meta Business Settings. This page walks you through it.
There are two choices, and they do different things.
  • ads_read — reporting and creative analysis only. Goose can look at your account and cannot create, change, pause or spend anything in it.
  • ads_read + ads_management — everything above, plus Goose can put your creatives into your ad account as paused ads for you to review.
Pick ads_read if you only want reporting. Read About write access before choosing ads_management — it explains exactly what changes.
Enter the token only in your brand’s Settings — never paste it into a chat with your Goose coworker. The agent will never ask you for a token; anything pasted in chat lives in the transcript, so if that happens, rotate the token in Meta and enter the fresh one in Settings.

Before you start

You’ll need:
  • A Meta Business (Business Manager) that owns — or has partner access to — your ad account.
  • A Meta App in that business. If you don’t have one: go to developers.facebook.com → My Apps → Create App → choose Business, then add it to your business under Business settings → Accounts → Apps.
  • Admin access to the business (only a business admin can create a system user and generate a token).

Connect (read‑only)

1

Open System Users in Business Settings

Go to business.facebook.com/settings → Users → System users.
2

Add a system user

Click Add, give it a name like Goose Growth, set the role to Employee, and create it.
3

Give it access to your app

Select the new system user → Assign assets → Apps → pick your Meta app → turn on Manage app (full control) → Save changes.
4

Give it access to your ad account

Still on the system user → Assign assets → Ad accounts → pick your ad account → turn on View performance → Save changes.
This is the step people skip — and it’s the one that breaks things. If you generate a token without assigning the ad account here, the token looks valid but can’t actually read your data, and the connection fails with “no ad accounts found.” Don’t skip it.
5

Generate the token

Click Generate new token → choose your app → set Token expiration to Never → check ads_read (and ads_management too, if you want Goose to be able to push creatives into the account as paused ads) → Generate token.
6

Copy it and paste it into Goose

Copy the token (Meta only shows it once). In Goose, open the brand you want to connect and go to its Settings (Meta connection, in the Performance section), paste the token, and select the ad account. Goose validates the token — and records the permissions it carries — before storing it encrypted, then begins the import. One Meta ad account connects to one brand.

What happens after connection

The first import brings in the previous 90 days of campaigns, ad sets, ads, daily delivery metrics, and discoverable creative media. Performance data becomes usable before every image or video finishes copying; a media warning does not block the metrics view. After that, Goose refreshes the most recent 28 days once per day so late conversion attribution and corrected delivery data can settle. You can also choose Refresh in the Performance tab at any time. Creative files are copied into private Goose storage so the evidence does not disappear when Meta’s temporary preview links expire. Images are limited to 25 MB and videos to 500 MB. Files that exceed those limits are reported as partial media rather than failing the account sync.

About write access

This changed. Goose used to be read‑only on Meta and could never create anything. With an ads_management token it can now push the creatives it makes into your ad account. Here is precisely what that does and does not mean. What Goose can do with ads_management:
  • Create ads, ad creatives, and (if you ask it to) a campaign and ad set, in the ad account you connected.
  • Upload the creative images and videos it made for you.
Everything Goose creates is PAUSED. A paused ad shows to nobody and spends nothing. There is no code path in Goose that creates an unpaused ad. Before anything goes live:
  • A person has to approve the push in Goose. Nothing reaches Meta until someone reads the plan — which creatives, which ad set, what copy — and approves it. Your Goose coworker can prepare a push; it cannot approve one.
  • Making those paused ads live is a second, separate step, and you have to type a confirmation phrase to do it. There is no button that does it in one click, and no agent can do it for you.
What Goose will not do, with any token:
  • Change budgets or bids on anything you already have running.
  • Touch campaigns, ad sets or ads it did not create.
  • Turn an ad live without an explicit, typed confirmation from a person.
Limits and undo:
  • There is a hard cap on how many ads Goose can create per ad account per day.
  • Every push is logged, shows who approved it, and can be reverted — ads that never went live are deleted, and ads that did are paused (so their history survives for reporting).
If you would rather not grant it: stay on ads_read and use Export creatives instead. You get every creative at the right size for its placement, plus a copy sheet, and you or your agency upload them by hand. Reporting still works for those creatives as long as the suggested ad name is kept.

What Goose can see

With a read‑only token, Goose can read:
  • Delivery metrics — spend, impressions, reach, frequency, clicks, CTR, CPC, CPM. These work for every account, no extra setup.
  • Your ad structure — campaigns, ad sets, and the creatives that are running.
  • Your creative images (and, where available, videos) so it can review what’s actually in your ads.
Conversions, cost‑per‑lead, cost‑per‑purchase, and ROAS only show up if your account has the Meta Pixel or Conversions API set up with conversion tracking. Without it, Goose will tell you tracking isn’t configured rather than guess — it never makes up numbers.

Your access is safe

  • A read‑only (ads_read) token can only read — it can’t spend, launch, pause, or edit anything.
  • An ads_management token lets Goose create paused ads after a person approves the push. Paused ads spend nothing, and going live needs a separate typed confirmation. See About write access.
  • The token is encrypted at rest and only used server‑side to sync your data. Your Goose coworker reads the synced data — it can never see, log, or repeat the token itself.
  • You can revoke it anytime from Business Settings → System users → Generate new token (regenerating invalidates the old one), or disconnect it in Goose.
  • Disconnecting in Goose removes the stored credential and stops future refreshes. Imported data and media remain visible as a stale historical snapshot; revoking the token inside Meta is a separate action.

Troubleshooting

The ad‑account assignment (step 4) was almost certainly skipped or saved without a permission. Go back to your system user → Assign assets → Ad accounts, make sure your account is listed with View performance turned on, then generate a fresh token and paste it again.
Only a business admin can generate a system‑user token, and the system user needs your app assigned first (step 3). If you’re not an admin, ask whoever owns the Business Manager to run these steps or make you an admin.
Tokens are shown only once. Just generate a new one (Generate new token) — this replaces the old token — and paste the new one into Goose.
That’s expected if your account doesn’t have the Meta Pixel / Conversions API tracking conversions. Delivery metrics (spend, clicks, CTR, etc.) still work; conversion metrics (CPA, ROAS) need tracking set up on your side.

Next steps

Brands & brand kit

A sharp brand kit makes sharper, on‑brand ads.

Autopilot

Get a fresh batch of on‑brand ads generated on a schedule.