curl --request POST \
--url https://app.goosybear.ai/api/v1/tools/connections.request_ad_account_access \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"external_account_id": "<string>",
"external_business_id": "<string>",
"confirmation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"workspace": "<string>"
}
'import requests
url = "https://app.goosybear.ai/api/v1/tools/connections.request_ad_account_access"
payload = {
"external_account_id": "<string>",
"external_business_id": "<string>",
"confirmation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"workspace": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
external_account_id: '<string>',
external_business_id: '<string>',
confirmation_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
workspace: '<string>'
})
};
fetch('https://app.goosybear.ai/api/v1/tools/connections.request_ad_account_access', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.goosybear.ai/api/v1/tools/connections.request_ad_account_access",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'external_account_id' => '<string>',
'external_business_id' => '<string>',
'confirmation_id' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'workspace' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.goosybear.ai/api/v1/tools/connections.request_ad_account_access"
payload := strings.NewReader("{\n \"external_account_id\": \"<string>\",\n \"external_business_id\": \"<string>\",\n \"confirmation_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"workspace\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.goosybear.ai/api/v1/tools/connections.request_ad_account_access")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"external_account_id\": \"<string>\",\n \"external_business_id\": \"<string>\",\n \"confirmation_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"workspace\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.goosybear.ai/api/v1/tools/connections.request_ad_account_access")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"external_account_id\": \"<string>\",\n \"external_business_id\": \"<string>\",\n \"confirmation_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"workspace\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"ok": true,
"workspace": "<string>",
"working_in": {
"label": "<string>",
"note": "<string>",
"workspace": "<string>",
"source": "call-override"
},
"state": "confirmation_required",
"confirmation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"expires_in_seconds": 123,
"request_summary": "<string>",
"platform": "meta",
"grant_state": "not_started",
"status_sentence": "<string>",
"external_account_id": "<string>",
"next_step_key": "<string>",
"next_step_title": "<string>",
"steps": [
{
"step_key": "<string>",
"title": "<string>",
"state": "pending"
}
]
}{
"ok": false,
"code": "<string>",
"message": "<string>",
"error": {
"code": "<string>",
"message": "<string>",
"retry_after_seconds": 123
},
"retry_after_seconds": 123
}{
"ok": false,
"code": "<string>",
"message": "<string>",
"error": {
"code": "<string>",
"message": "<string>",
"retry_after_seconds": 123
},
"retry_after_seconds": 123
}{
"ok": false,
"code": "<string>",
"message": "<string>",
"error": {
"code": "<string>",
"message": "<string>",
"retry_after_seconds": 123
},
"retry_after_seconds": 123
}{
"ok": false,
"code": "<string>",
"message": "<string>",
"error": {
"code": "<string>",
"message": "<string>",
"retry_after_seconds": 123
},
"retry_after_seconds": 123
}{
"ok": false,
"code": "<string>",
"message": "<string>",
"error": {
"code": "<string>",
"message": "<string>",
"retry_after_seconds": 123
},
"retry_after_seconds": 123
}Call connections.request_ad_account_access
Ask the ad platform for access to the operator’s own ad account — ‘request access to our ad account’, ‘ask for access to this ad account id’. Ask the platform for permission to work on the operator’s OWN ad account, naming the account id they gave you. This sends a real request that lands in their own business settings for approval, so pass the account id the operator gave you, never one you guessed. It requires a signed authorization to act on their behalf; calling it raises the approval card naming the account and the platform, which is the operator’s confirmation, and only their approve sends it. It never moves money and never touches their card. Not for checking access we already asked for — that is connections.check_ad_account_access. Over the API it answers in two calls: without confirmation_id it proposes — says what would happen, returns a confirmation_id and changes, spends and sends nothing; the same arguments again with that confirmation_id, on a member’s own API key, do it.
Every result names the workspace it ran in. Say which workspace the answer is about. When the account has more than one workspace and none is selected, this tool refuses with workspace_ambiguous and lists the choices — offer them, never pick one.
curl --request POST \
--url https://app.goosybear.ai/api/v1/tools/connections.request_ad_account_access \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"external_account_id": "<string>",
"external_business_id": "<string>",
"confirmation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"workspace": "<string>"
}
'import requests
url = "https://app.goosybear.ai/api/v1/tools/connections.request_ad_account_access"
payload = {
"external_account_id": "<string>",
"external_business_id": "<string>",
"confirmation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"workspace": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
external_account_id: '<string>',
external_business_id: '<string>',
confirmation_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
workspace: '<string>'
})
};
fetch('https://app.goosybear.ai/api/v1/tools/connections.request_ad_account_access', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.goosybear.ai/api/v1/tools/connections.request_ad_account_access",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'external_account_id' => '<string>',
'external_business_id' => '<string>',
'confirmation_id' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'workspace' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.goosybear.ai/api/v1/tools/connections.request_ad_account_access"
payload := strings.NewReader("{\n \"external_account_id\": \"<string>\",\n \"external_business_id\": \"<string>\",\n \"confirmation_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"workspace\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.goosybear.ai/api/v1/tools/connections.request_ad_account_access")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"external_account_id\": \"<string>\",\n \"external_business_id\": \"<string>\",\n \"confirmation_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"workspace\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.goosybear.ai/api/v1/tools/connections.request_ad_account_access")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"external_account_id\": \"<string>\",\n \"external_business_id\": \"<string>\",\n \"confirmation_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"workspace\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"ok": true,
"workspace": "<string>",
"working_in": {
"label": "<string>",
"note": "<string>",
"workspace": "<string>",
"source": "call-override"
},
"state": "confirmation_required",
"confirmation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"expires_in_seconds": 123,
"request_summary": "<string>",
"platform": "meta",
"grant_state": "not_started",
"status_sentence": "<string>",
"external_account_id": "<string>",
"next_step_key": "<string>",
"next_step_title": "<string>",
"steps": [
{
"step_key": "<string>",
"title": "<string>",
"state": "pending"
}
]
}{
"ok": false,
"code": "<string>",
"message": "<string>",
"error": {
"code": "<string>",
"message": "<string>",
"retry_after_seconds": 123
},
"retry_after_seconds": 123
}{
"ok": false,
"code": "<string>",
"message": "<string>",
"error": {
"code": "<string>",
"message": "<string>",
"retry_after_seconds": 123
},
"retry_after_seconds": 123
}{
"ok": false,
"code": "<string>",
"message": "<string>",
"error": {
"code": "<string>",
"message": "<string>",
"retry_after_seconds": 123
},
"retry_after_seconds": 123
}{
"ok": false,
"code": "<string>",
"message": "<string>",
"error": {
"code": "<string>",
"message": "<string>",
"retry_after_seconds": 123
},
"retry_after_seconds": 123
}{
"ok": false,
"code": "<string>",
"message": "<string>",
"error": {
"code": "<string>",
"message": "<string>",
"retry_after_seconds": 123
},
"retry_after_seconds": 123
}Authorizations
An API key minted at Settings › API & MCP. Send it as Authorization: Bearer <key>. A key carries its holder's own permissions, resolved on every call — revoking a membership closes the key's reach immediately. Keep it in an environment variable (GOOSY_API_KEY), never in a committed file.
Headers
Your own id for this request, echoed back and recorded on the audit trail. 1–128 characters from A–Z a–z 0–9 . _ : -, starting with a letter or digit; anything else is replaced by a generated id.
128Body
Which advertising platform's ad account to set up on that platform's own account — the customer owns the account and grants us access to it. The allowed values are the enum's; do not offer a platform outside it.
meta, google, tiktok, linkedin The operator's OWN ad account id, exactly as the platform writes it (Meta: act_1234567890). This names WHICH account we ask about — it is an account identifier and grants nothing by itself. NEVER pass a password, token or API key here.
1Their business portfolio / Business Center id, where the platform has one. Omit unless the operator gave you one.
Omit to propose: the first call says what would happen, returns a confirmation_id and changes nothing. To go ahead, send the same arguments again with that confirmation_id, on a member's own API key; a service account's key can propose but never confirm.
Which workspace to run in — its slug. Omit to use your default. With more than one reachable workspace and no default, the call is refused and the choices are listed.
1Response
The call was admitted and dispatched. ok says whether the tool succeeded — a refusal the tool itself produced is still a 200, exactly as it is a successful JSON-RPC result over MCP.
- Option 1
- Option 2
The tool ran and answered.
The slug of the workspace this call ran in.
Which workspace this call ran in, and how that was decided. Present on every workspace-scoped result.
Show child attributes
Show child attributes
"confirmation_required"What will happen, in one sentence, for a person to approve before confirming.
meta, google, tiktok, linkedin not_started, awaiting_customer_creation, awaiting_authorization, awaiting_platform_access, request_issued, awaiting_customer_accept, active, revoked, failed Show child attributes
Show child attributes