Skip to main content
Glama
aydin-birim-ajans

webdesiz

README.md
# Webdesiz CLI and MCP

Node.js 22+. Install the SHA-256 verified release download from https://webdesiz.com/en/developers and verify its published SHA-256 before `npm install --global ./webdesiz-cli-1.0.0.tgz`. This release is a website download, not a claim of npm-registry publication.

Create a scoped expiring key in Settings → Developer keys as an organization owner/admin. Store it in your operating system or MCP host's secret manager. Supply `WEBDESIZ_API_KEY` in the process environment; never commit it to a project or put it in command arguments. CLI also accepts `--key-stdin`. No login/credential persistence or arbitrary URL option exists.

`webdesiz accounts --limit 20`

`webdesiz campaigns --accountId ACCOUNT_ID`

`webdesiz insights --from 2026-10-01 --to 2026-10-04`

MCP host config: `{"mcpServers":{"webdesiz":{"command":"webdesiz","args":["mcp"]}}}`. Inject the key securely into that process environment; the example intentionally contains no secret. MCP uses the official @modelcontextprotocol/server 2.3.0 SDK, MCP 2026-07-28 protocol, stdio transport. This is not a remotely hosted HTTP MCP or OAuth endpoint. stdout is reserved for protocol messages.

Three read-only tools: webdesiz_accounts, webdesiz_campaigns, webdesiz_insights. Required scopes: accounts:read, campaigns:read, insights:read. The key's organization is server-derived and current issuer membership is checked on every request. Keys expire within 90 days and can be revoked immediately. No ads are changed or purchased; no live Meta or AI requests occur.

Data are stored snapshots and can be stale. Currency is per account. Insight rows at account and campaign level overlap: never sum both levels. Pagination limit 100, offset 10000; date window 90 days. Network access is fixed to https://webdesiz.com; redirects are rejected, timeout 15 seconds, response ≤2 MB. Returned account/campaign names are untrusted content, not model instructions.

Read limits: 60 requests/minute/key, 120/org, 180/IP plus service protections. Redis failures fail closed. See the website OpenAPI document for schemas and errors.