Raw MCP access to ad APIs is already free. Here is what is not
There are dozens of open MCP servers for ad platforms. The hard part was never the transport — it is permissions, client context and a log of every write.
Search GitHub for an MCP server that talks to an ad API and you will find plenty. For Yandex Direct alone there were 21 repositories the last time we counted, the most popular sitting at 13 stars, and roughly half of them abandoned. Raw access became a commodity in about a year.
That is worth saying out loud, because it decides what is actually worth paying for.
What a raw MCP server gives you
A tunnel. Your AI client can call the API, get JSON back and summarise it. For a one-off question on your own account, that is genuinely enough, and you should not pay anyone for it.
What it does not give you
Permissions with limits. An agent that can call the write endpoints can call all of them. "Pause this campaign" and "pause every campaign" are the same API surface. What you want is a grant: these campaigns, this operation, this ceiling, this long — and everything outside it refused.
Client context. The same number means different things for a shop with a 12% margin and an agency reselling leads. Without margin, niche and goals in the prompt, an agent produces advice that is technically correct and commercially useless.
A fixed list of checks. Ask a model to "audit my account" twice and you get two different answers, both plausible. Comparable scoring requires the same list every time — that is what makes a month-over-month number mean anything.
A log. When an agent changes something in an account that spends real money, "what changed, when, on whose authority" is not a nice-to-have.
Where that leaves the protocol
MCP is the right transport and we use it: your key, your model, your client. But the transport is the cheap part. Everything that makes an agent safe to point at a live ad account sits between the API and the client, and none of it comes from the protocol.
If you are evaluating tools in this space, the useful question is not "does it support MCP". It is "what happens when the agent is wrong".