Testing Senditor — for a Meta App Review reviewer

What this product does. An advertiser prepares ad creatives here, the person responsible approves them, and the approved ones are published into an ad account the advertiser already owns. Every ad we create is created PAUSED. We never write a budget, a bid, a schedule or audience targeting, and we never set an ad to active.

The five steps, in order.

1. Connect Meta. The operator presses one button. Their browser goes to Meta's consent dialog for exactly four permissions — ads_management, ads_read, business_management, pages_show_list — and comes back to https://app.senditor.ad/api/meta/callback. The short-lived token Meta issues is exchanged for the long-lived one in that same request; the short-lived one is never stored.

2. Pick an ad account and a Page. The app reads /me/adaccounts and /me/accounts and shows both lists. An operator whose login manages no ad account, or no Page, is told so in a sentence — never shown an empty dropdown.

3. The dashboard. Performance for the selected ad account — Impressions, Clicks, Spend, CTR, CPM, Frequency and Reach — read from the Ads Insights API.

4. Approve. The creatives go to a client on a link containing an unguessable token with a visible expiry. Each decision is appended to a permanent record; a changed mind appends a second entry and the first stays readable.

5. Publish PAUSED. The approved creatives become ads in the ad set the operator selected, every one of them PAUSED. Nothing delivers and nothing is spent.

Why you cannot drive steps 1–5 from this page. This product binds to the loopback interface of the operator's own machine, and every action that spends money or writes to an ad account requires a per-process operator credential that exists only in the operator's own browser session on that machine. Traffic arriving at this public address can read these pages; it is refused the moment it tries to run, publish or connect. That is the product's security model, not an oversight, and we will not weaken it for a test.

So there are two ways to test it, and we will do whichever you prefer.

(a) Give your test account a role on our app. Meta's own rule is that an app used only by app users with a role on it needs no review at all, and Standard Access "can only be requested from app users who have a role on the requesting app". Send us the account and we will add it immediately; you can then complete steps 1–5 against your own ad account, on your own machine, with our build.

(b) A live session at a time you choose. We drive the five steps above against a real ad account while you watch, and answer anything you want to see again.

Either way, email [email protected] and we will reply the same working day.

Privacy policy: https://app.senditor.ad/privacy · Deleting your data: https://app.senditor.ad/data-deletion


Pricing · Privacy policy · Deleting your data · For a Meta reviewer