Skip to content
Cerebr-IA

MARKETIA integration

MARKETIA and Meta: Facebook, Instagram, WhatsApp and Threads

Each business connects its own Facebook Pages, Instagram professional accounts, WhatsApp Business numbers, Threads accounts and ad accounts through Meta's official login.

What MARKETIA does

  • Facebook: AI comment moderation and the Activity Quality Index (ICA) per post, reactions, Messenger in the unified inbox, publishing and scheduling, live videos, the Page action button and Page insights.
  • Instagram (professional accounts linked to a Page): comments and mentions, direct messages in the inbox, publishing and insights.
  • WhatsApp Business (Cloud API): customer conversations in the unified inbox, with the AI sales agent that replies and creates cash-on-delivery orders following the business's rules; Meta-approved templates and campaigns.
  • Threads (Threads' own OAuth): publishing, reading and moderating replies, mentions and insights.
  • Meta Ads: dashboards of campaigns, ad sets and ads with aggregated metrics, automation rules, AI analysis, custom audiences and the business's own lead forms (Lead Ads).

What it does not do

  • It does not read personal profiles or Pages the business does not manage.
  • Outside WhatsApp's 24-hour window, messages are only sent with Meta-approved templates, as the platform requires; MARKETIA's terms forbid unsolicited advertising.
  • It does not sell data, use it for third-party advertising or to train AI models.

How authorization works

  1. An administrator of the business opens MARKETIA → Connections and clicks "Connect with Facebook" (Pages, Instagram and ads), "Connect WhatsApp" (Meta's WhatsApp Business Embedded Signup) or "Connect Threads".
  2. Meta's official dialog opens. The person chooses which Pages, Instagram accounts, ad accounts and WhatsApp accounts to share, and which permissions to grant.
  3. Meta returns the code to the callback URL; the server exchanges it, encrypts the tokens and records the granted permissions per asset.
  4. Every MARKETIA feature checks that the required permission is granted for that specific asset before running; otherwise it is shown as disabled with an explanation.

Permissions and what they are used for

Facebook Pages

PermissionUsed for
pages_show_listList the Pages the person manages so they can choose which to connect.
pages_read_engagementRead posts, followers and the Page action button.
pages_read_user_contentRead visitor comments and posts to moderate them.
pages_manage_metadataSubscribe the Page to webhooks to receive comments and messages in real time.
pages_manage_engagementReply to, hide or delete comments and like them as the Page.
pages_manage_postsPublish, schedule, edit and delete Page posts.
pages_messagingReply to Messenger conversations from the inbox.
read_insightsPage and Reels insights.
publish_videoGo live on the Page (only if the business uses live videos).
pages_manage_ctaChange the Page action button.
pages_manage_ads and leads_retrievalThe business's lead forms (Lead Ads) and sending leads to its CRM.

Instagram

PermissionUsed for
instagram_basicProfile and content of the connected professional account.
instagram_manage_commentsRead, reply to and hide comments and mentions.
instagram_manage_messagesInstagram direct messages in the inbox.
instagram_content_publishPublish and schedule to Instagram.
instagram_manage_insightsAccount and media insights.

Ads and business

PermissionUsed for
ads_readSee ad accounts and their aggregated results.
ads_managementManage campaigns, ads, rules and audiences when the business asks for it.
business_managementRead the business portfolio to list the assets the business shares.
catalog_managementManage product catalogs (if the business enables it).

WhatsApp Business

PermissionUsed for
whatsapp_business_managementManage the WhatsApp Business account, its numbers and templates.
whatsapp_business_messagingSend and receive WhatsApp messages from the inbox.
whatsapp_business_manage_eventsSend WhatsApp conversions back to Meta (identifiers hashed with SHA-256).

Threads (Threads' own app, not the Facebook dialog)

Callback: https://fapi.marketia.cerebria.co/api/v1/threads/oauth/callback

PermissionUsed for
threads_basicSee the connected account's profile and threads.
threads_content_publish and threads_deletePublish and delete Threads posts.
threads_read_replies and threads_manage_repliesRead, reply to and moderate replies.
threads_manage_insightsThreads insights.
threads_manage_mentionsMentions of the account.
threads_keyword_search and threads_location_taggingSearch Threads and tag locations when posting.

What data is stored

  • Comments and reactions on the business's posts, with the commenter's public name.
  • Messenger, Instagram and WhatsApp messages, with name and profile picture when Meta provides them (the picture is copied to our storage because Meta's link expires). On Instagram, also username, follower count, whether they follow the business and whether they are verified.
  • Aggregated ad account metrics (spend, impressions, clicks, conversions), which do not identify individuals, and the click-to-message ad ID each conversation came from.
  • What people submit in the business's instant forms (Lead Ads).
  • Access tokens, always encrypted, and the permissions granted per asset.

Encryption and security

  • Meta tokens are encrypted at rest with authenticated encryption (Fernet: AES-128-CBC + HMAC-SHA256); they are never returned to the interface or the API.
  • Facebook, Instagram, WhatsApp and Threads webhooks are verified with Meta's signature (X-Hub-Signature-256).
  • Tenant isolation and roles: only the business's administrators connect or disconnect accounts; an ad account can only belong to one organization.
  • All traffic is encrypted with TLS (HTTPS).

Disconnection, retention and deletion

  • From MARKETIA: disconnecting an ad account deletes its metrics, campaigns and ads; disconnecting a Page stops new data (what was already received stays in the business's inbox until deletion is requested or the organization is deleted), and that Page's Lead Ads data is deleted.
  • From Facebook (Settings → Apps and websites → MARKETIA → Remove): Meta calls our deauthorize callback (https://fapi.marketia.cerebria.co/legal/meta/deauthorize) and we disconnect that person's Pages and ad accounts.
  • If deletion is also requested, Meta calls https://fapi.marketia.cerebria.co/legal/meta/data-deletion: we delete the tokens, the Facebook ID and permission data, and return a confirmation code that can be checked on the data deletion page.
  • Threads has its own deauthorize and deletion URLs (below). Deletion on request is also available by email, within 30 days at most.

Related documents: privacy · data deletion · terms · security

Callback and webhook URLs

PurposeURL
Facebook Login OAuth callback (ads)https://fapi.marketia.cerebria.co/api/v1/connections/meta/oauth/callback
Facebook Login OAuth callback (Pages)https://fapi.marketia.cerebria.co/api/v1/connections/meta/pages/oauth/callback
Threads OAuth callbackhttps://fapi.marketia.cerebria.co/api/v1/threads/oauth/callback
Deauthorize callback (Facebook)https://fapi.marketia.cerebria.co/legal/meta/deauthorize
Data deletion request callback (Facebook)https://fapi.marketia.cerebria.co/legal/meta/data-deletion
Deauthorize callback (Threads)https://fapi.marketia.cerebria.co/api/v1/threads/oauth/deauthorize
Data deletion callback (Threads)https://fapi.marketia.cerebria.co/api/v1/threads/oauth/data-deletion
Facebook and Instagram webhookshttps://fapi.marketia.cerebria.co/api/v1/webhooks/facebook
WhatsApp webhookhttps://fapi.marketia.cerebria.co/api/v1/webhooks/whatsapp
Threads webhookhttps://fapi.marketia.cerebria.co/api/v1/webhooks/threads
Data deletion instructions (MARKETIA, Spanish)https://fapi.marketia.cerebria.co/legal/eliminar-datos
MARKETIA privacy policy (Spanish)https://fapi.marketia.cerebria.co/legal/privacidad

Contact

For any question about the Meta integration, test accounts or data requests: developer@cerebria.co

Privacy and deletion requests: developer@cerebria.co

Screens

Screenshots of the real application with fictitious sample data. The interface is in Spanish.

  • Messages (unified inbox)Desktop

    WhatsApp, Messenger and Instagram inbox with funnel stages, AI agent and human handover.

  • Comments per post (ICA)Desktop

    Toxicity analysis per post and the Activity Quality Index with and without MARKETIA, with its estimated CPM impact.

  • ModerationDesktop

    Facebook, Instagram, Threads and TikTok activity: AI-classified comments, removed or hidden ones and the reactions breakdown.

  • InstagramDesktop

    Profile, content, comments, mentions and insights of the connected Instagram account.

  • ThreadsDesktop

    Profile, content, replies and mentions, insights and automation for the Threads account.

  • WhatsApp accountDesktop

    How Meta sees the number: quality, limits, display name and permissions.

  • AdsDesktop

    Meta Ads: campaigns, trends and AI optimization; ad account health and ads with delivery issues.

  • Facebook PagesDesktop

    The Pages MARKETIA moderates and publishes from: role, permissions and profile.

  • Meta data requestsDesktop

    Access removals and data deletion requests Meta sends when someone removes MARKETIA from their Facebook.

Other integrations