โ† Back to guides

Connect Meta with a token (System User)

One token to import spend and ROI from Facebook/Instagram and launch campaigns from RoyLead.

Updated on August 8, 2026


With a System User token from your Business Manager, RoyLead does two things:

  • imports spend, clicks and impressions from your Facebook/Instagram ad accounts, to compute ROI and ROAS alongside your leads;
  • creates and launches Meta campaigns straight from the dashboard, without going through Ads Manager.

You generate the token yourself in your Business Manager, with your own app: it works right away, with no need to wait for any Meta app approval.

๐Ÿ“Œ In short: you need one thing from Meta โ€” a System User token with the ads_management permission โ€” to paste into RoyLead at Advertising โ†’ Connect account โ†’ "Meta ยท connect the whole Business Manager". No ad account ID needed: RoyLead discovers and connects every ad account you assigned to the token.

โš ๏ธ Read access is not enough to launch. You need all three: the ad account assigned with write access, the pixel (dataset) assigned, and the Facebook Page assigned. If one is missing the connection still succeeds, but the campaign won't launch.

๐Ÿ’ก Time needed: ~15 minutes. You must be an admin of the Business Manager that owns the ad account.

๐Ÿ”’ The token is like a password. RoyLead stores it encrypted and never shows it again after saving. Don't share it in chats, screenshots or email.

1

Open Business Settings

Go to Meta Business Manager and sign in with an admin account.

Open Meta Business Settings

โ„น๏ธ If you manage multiple businesses, check the selector at the top left and pick the right one โ€” the business that owns the ad account.

2

Create a system user

A System User is a "technical user" of the business, designed specifically for integrations.

  1. In the left menu, go to Users โ†’ System users.
  2. Click Add.
  3. Give it a recognizable name, e.g. RoyLead Sync.
  4. Role: Employee โ€” you don't need Admin. Write access comes from the assets you assign in steps 3-5, not from the role. Click Create system user.

Creating the system user
Creating the system user

3

Assign the ad accounts (with write access)

The token only sees the assets you explicitly assign to this user.

  1. With the system user selected, click Assign assets.
  2. Asset type: Ad accounts โ†’ select the accounts you want to connect. If you have more than one to use, select them all now: RoyLead connects them in one go.
  3. In the permissions, under Partial access, turn on "Manage campaigns": that's ads_management, the permission that allows creating and launching. ("View performance" turns on by itself โ€” it's included.)
  4. Leave "Manage ad accounts" (Full control) off: it would also grant control over the account's payments and settings, which RoyLead doesn't need.
  5. Click Assign assets.

The ad account assigned with "Manage campaigns", full control off
The ad account assigned with "Manage campaigns", full control off

โš ๏ธ With "View performance" only, the account connects and spend flows in, but launching won't work: Meta rejects the campaign creation with a permissions error.

4

Assign the pixel

At launch, the ad set declares the pixel as its conversion objective, and that call is made with the token: if the token can't see the pixel, Meta answers with a permissions error.

  1. Still under Assign assets, pick the asset type Datasets (older businesses call it Pixels).
  2. Select the pixel you use for these campaigns.
  3. Permissions: turn on "Use events dataset" (Partial access) โ€” it explicitly says "create ads for conversions with this dataset". Leave "Manage events dataset" off.
  4. Click Assign assets.

The dataset assigned with "Use events dataset"
The dataset assigned with "Use events dataset"

โ„น๏ธ This is different from the CAPI token RoyLead uses to send events to Meta. Here it's only so the campaign can point at that pixel.

5

Assign the Facebook Page

Every Meta ad has a Page as its sender. Pages are assigned from a different section, not from the "Assign assets" dialog.

  1. Left menu: Accounts โ†’ Pages.
  2. Select the Page you'll use in your ads.
  3. Click Assign people and pick the RoyLead Sync system user.
  4. Turn on "Ads" (create and manage the Page's ads) and "Insights", then click Assign.

The Page assigned with the "Ads" and "Insights" tasks
The Page assigned with the "Ads" and "Insights" tasks

โš ๏ธ If you hit a Page permissions error at launch, come back here and raise it to Full control: linking the Instagram account sometimes requires it.

6

Set up the app

The token is generated through an app owned by the business, and the system user must have a role on that app. If you already have an app linked to the system user, skip to Step 7.

Create the app (if you don't have one)

No Meta approval needed: the app is just the technical "container" for the token, and any business app with the Marketing API will do.

  1. Go to Business settings โ†’ Accounts โ†’ Apps โ†’ Add โ†’ "Create a new app ID".

The "What do you want to do?" menu โ†’ Create a new app ID
The "What do you want to do?" menu โ†’ Create a new app ID

  1. App name: e.g. RoyLead Sync (the contact email is already yours).

App details: name and email
App details: name and email

  1. Use cases: leave "Create and manage ads with the Marketing API" selected (it's the first option, checked by default).

Selecting the "Create and manage ads with the Marketing API" use case
Selecting the "Create and manage ads with the Marketing API" use case

  1. Business: link the app to your business portfolio, so it belongs to the right business.
  2. Review the Overview and click Create app. The Marketing API is already included thanks to the use case you picked.

The app overview before creating it
The app overview before creating it

Link the app to the system user

Creating the app isn't enough: the system user must have a role on the app, otherwise the token's "Assign permissions" step comes up empty.

  1. Go to Accounts โ†’ Apps and select your app.
  2. Click Assign people.

The "Assign people" button on the app
The "Assign people" button on the app

  1. Select the system user (e.g. RoyLead Sync), turn on the "Develop app" toggle and click Assign. Leave "Manage app" off.

Assigning the system user with the "Develop app" role
Assigning the system user with the "Develop app" role

Publish the app (required to launch)

A freshly created app is in development mode: it reads data but can't create ads. The launch stops halfway, on the creative, with "The ad creative was created by an app that is in development mode" (1885183).

  1. On developers.facebook.com/apps open your app.
  2. App settings โ†’ Basic, fill in the two fields Meta requires to publish: Privacy Policy URL and Category. Save.
  3. In the left menu, Publish: switch the app from "Unpublished" to published.

The "Publish" section with the app published
The "Publish" section with the app published

โ„น๏ธ This is not Meta's App Review, which you don't need: it's only the switch that takes the app out of development mode.

7

Generate the token

  1. Go back to Users โ†’ System users, select your user and click Generate new token.
  2. Select your app from the list (the one from Step 6).
  3. Token expiration: Never, for a permanent connection.
  4. Check these permissions:
PermissionWhat it's for
ads_managementcreate campaigns, ad sets, creatives and ads (includes reading costs)
ads_readspend, clicks and impressions for ROI and ROAS
pages_show_listsee the Page that sends the ads
pages_read_engagementread the Page's data (without it the launch fails with error #100)
pages_manage_adspublish ads on behalf of the Page and link the Instagram account
business_managementdiscover which ad accounts are assigned to the token
  1. Click Generate token and copy it right away.

The "Generate token" dialog โ€” selecting the app
The "Generate token" dialog โ€” selecting the app

Token expiration set to "Never"
Token expiration set to "Never"

The six permissions checked in the "Assign permissions" step
The six permissions checked in the "Assign permissions" step

The "Token created" dialog โ€” copy the token
The "Token created" dialog โ€” copy the token

โš ๏ธ If the "Assign permissions" step shows "No permissions available", the app isn't linked to the system user: complete Step 6 and try again.

๐Ÿ”’ Meta shows the token only once. Losing it is no problem: generate another one and paste it into RoyLead again.

8

Paste the token into RoyLead

  1. Open your team's Ad Accounts tab in RoyLead.
  2. Click Connect account and choose "Meta ยท connect the whole Business Manager".
  3. Paste the token and confirm.

The "Connect a Business Manager with a token" dialog in RoyLead
The "Connect a Business Manager with a token" dialog in RoyLead

Go to Ad Accounts โ†—

RoyLead verifies the token with Meta right away, discovers every ad account assigned to that token, pulls each account's name and currency automatically and connects them. At the end it tells you how many accounts are new and how many were updated.

โ„น๏ธ You're never asked for an account ID: if an account doesn't show up, it isn't assigned to the system user (back to Step 3).

9

Import your pixels into the registry

In the campaign screen, the Pixel dropdown only lists pixels tied to that ad account. A pixel added by hand in the registry isn't tied to any account, so the dropdown stays empty and the launch is blocked.

  1. Open the Pixels section of RoyLead.
  2. Click Import from Meta.
  3. Pick the ad account you just connected and confirm.

The "Import pixels from Meta" dialog with the account picker
The "Import pixels from Meta" dialog with the account picker

Go to Pixels โ†—

RoyLead imports that account's pixels and ties them to the connection. A manual pixel with the same ID is overwritten, not duplicated, and its CAPI token switches to the System User one.

10

Verify

On the connection:

  • the account shows up in the list with the Connected status;
  • the automatic sync runs every few hours; you can force it with the Sync button;
  • after the first sync, spend and ROI appear in Analytics alongside your leads.

On the launch, in the campaign screen โ†’ Target accounts, for each account you must be able to pick:

  • the sender Facebook Page (from Step 5);
  • the Pixel (from Step 9), required for conversion objectives;
  • the Beneficiary (EU/DSA).

Then Validate and Launch on Meta.

โš ๏ธ From the dashboard the campaign is published active (or scheduled for the date and time you picked, in the ad account's timezone): it starts spending from launch. Only launches triggered by an agent over MCP are published paused.

Only the token can launch, "Log in with Facebook" can't

An account connected with "Log in with Facebook" (OAuth) stays read-only: it imports spend and ROI, but never shows up among a campaign's target accounts. The reason: RoyLead's app only holds cost-read permissions, not ads_management.

If you try anyway, you get the error "Invalid or non-launchable ad account (a System User token is required)". The fix is to connect the same account with the token: the connection is updated in place, without losing spend history.

โ„น๏ธ One thing to keep in mind: the token is tied to the Meta app used to generate it. If Meta suspends that app, both the token and OAuth stop working. The token protects you from login-flow problems, not from an app suspension.

If the token expires or stops working

If you generate a token with an expiration and it expires, or you revoke it from Business Manager, RoyLead flags the account with an error status.

To fix it: reconnect the Business Manager with the new token from the same dialog as Step 8 (existing accounts are updated, not duplicated), or use the โ‹ฏ โ†’ Edit credentials menu on the account card. No need to redo any Meta setup.

Troubleshooting

What you seeCauseFix
Invalid tokenWrong, expired or revoked tokenGenerate a new token, Step 7
No account connected, or one missingThe account isn't assigned to the system userStep 3
Permissions error (#200) at launchads_management missing, or the account is assigned read-onlyStep 3 and Step 7
Pixel permissions error at launchThe dataset isn't assigned to the system userStep 4
Page permissions error at launchPage not assigned, or the "Ads" task missingStep 5 (if it persists, Full control on the Page)
Empty Pixel dropdown in the campaignThe pixels aren't tied to that ad accountStep 9: Import from Meta
"Invalid or non-launchable ad account"The account is connected via OAuth, not with the tokenReconnect it with the token, Step 8
"No permissions available"The app isn't linked to the system userStep 6
"created by an app that is in development mode" (1885183)The app isn't publishedStep 6: publish the app
"Account already connected"The account is already connected to the teamIt's already there: no need to reconnect it
Wrong currencyโ€”The currency comes from Meta automatically and can't be edited

๐Ÿ’ก Generate the token with Never as expiration to avoid interruptions: it's the most convenient choice for continuous syncing.

Best practices

  • ๐Ÿ”‘ A system user dedicated to RoyLead: revoking the token only breaks that one integration.
  • ๐Ÿ”’ Assign the system user only the ad accounts, pixels and Pages you actually want to use.
  • ๐Ÿงฑ Least privilege: "Manage campaigns" rather than "Manage ad accounts", "Use events dataset" rather than "Manage events dataset".
  • ๐Ÿšจ Treat the token like a password: if you think it leaked, regenerate it in Business Manager and paste the new one.

Ready to put this into practice?

Create your RoyLead account and start in minutes.

Get started free โ†—