⚡ Developer preview. GM3 is in design-partner beta — tool names and schemas below reflect the current build and are versioned; breaking changes are documented before release.

GM3 Developer Docs

GM3 is a headless MCP server for mobile user acquisition. One connection gives your AI workflow — Claude Code, Cursor, or any MCP-capable client — normalized, source-labeled, governed access to your entire mobile ad stack.

Quickstart

Add GM3 to your MCP client configuration (example: .mcp.json in your project root for Claude Code):

{
  "mcpServers": {
    "gm3": {
      "command": "npx",
      "args": ["-y", "@gm3/mcp"],
      "env": { "GM3_API_KEY": "${GM3_API_KEY}" }
    }
  }
}

Then authenticate your networks — a guided, per-network OAuth/API-key flow with least-privilege scopes:

# in your IDE chat
› connect meta and appsflyer
# GM3 walks you through auth; read-only scopes by default
› what's my blended CPI by network this week?

Time from install to first cross-network answer: about five minutes, fully self-serve.

Requirements

  • An MCP-capable client (Claude Code, Cursor, or any client speaking MCP)
  • Admin or API access to at least one supported ad network account
  • Optional but recommended: MMP access (AppsFlyer or Adjust) for attribution-reconciled metrics

Supported networks at beta: Meta, Apple Search Ads (P0), Google Ads, TikTok, AppLovin, Snap, Amazon Ads, Liftoff (rolling out), with AppsFlyer first for MMP ingestion.

Roadmap integrations (post-beta, in category order): attribution — Adjust, Branch; analytics & experimentation — Amplitude, Mixpanel, Statsig; engagement & CRM — Braze, OneSignal; revenue — RevenueCat. The connector interface is a stable public contract, so each new category slots in without changing how your workflows talk to GM3.

MCP tools reference

Tools come in three capability classes. Every response includes freshness metadata (synced_at, per network) and a source label on every metric.

ToolClassWhat it does
get_spendreadSpend, impressions, clicks, network-claimed installs — filter by network, campaign, date range; group by network/day/campaign.
get_campaignsreadCampaign / ad-set / ad hierarchy with current network-reported status. Zero-spend campaigns included — state comes from entity sync, not spend data.
get_creativesreadCreative ledger: assets, versions, per-network spec metadata, current status.
blended_summaryreadCross-network aggregates (blended CPI/CPA/spend) in USD with per-network source labels and freshness.
get_external_changesreadChanges made outside GM3 — manual dashboard edits and platform automations — detected and attributed, with honest labeling when a platform doesn't say who made a change.
check_auth_statusmetaPer-network, per-tenant connection and scope status.
propose_create_campaignwrite V1.1Launch a campaign from a typed campaign spec. Dry-run + approval-gated.
propose_update_budget / propose_update_bidwrite V1.1Budget/bid changes, validated against your spend scopes before anything touches the network.
propose_pause_ad / propose_attach_creativewrite V1.1Creative rotation and pause/activate, gated by risk tier.
list_pending_approvals / approve_actionmeta V1.1The human-in-the-loop surface: review and approve proposed writes from your IDE.
Naming is a contract. Every write tool is prefixed propose_ — agents and users propose; deterministic governance disposes; humans approve. There is no tool that directly mutates a live campaign.

Architecture

Your IDE (Claude Code / Cursor / any MCP client) │ one MCP connection ▼ ┌─────────────────────────────────────────┐ │ GM3 MCP SERVER │ │ read tools · propose_* writes · meta │ ├─────────────────────────────────────────┤ │ SHIELD — deterministic governance │ │ scopes · circuit breakers · dry-run · │ │ approval gates · full audit log │ ├─────────────────────────────────────────┤ │ GROWTH SCHEMA — normalized warehouse │ │ spend · entities · creatives · changes │ ├─────────────────────────────────────────┤ │ CONNECTORS (per network) │ │ native, first-party integrations │ └─────────────────────────────────────────┘ Meta │ Google │ ASA │ TikTok │ AppLovin │ Snap │ Amazon │ … AppsFlyer S2S │ Adjust │ SKAN postbacks
  • Fast, always-fresh answers. Responses come from GM3's continuously-synced data layer — every answer carries its per-network sync timestamp.
  • Resilient by design. One network having an outage never takes the product down — you get partial results with the failure clearly labeled.
  • Stable contract. The tool surface and campaign-spec format are versioned; workflows you build against them are treated as a public API.

Governance — Shield

Shield is the reason it's safe to let AI near live budgets. It is pure deterministic logic — no LLM anywhere in the decision path.

  • Spend scopes: per-campaign, per-network, and per-day ceilings you define. Out-of-scope proposals are rejected before they reach any network.
  • Circuit breakers: anomalous spend or CPA divergence halts activity and alerts you.
  • Dry-run / shadow: every proposed write is simulated against historical data before touching anything live.
  • Approval gates: high-risk actions (campaign launches, out-of-scope budget moves) require an explicit human approval — from your IDE.
  • Audit everything: every read, proposal, approval, and applied change is recorded. An audit write failure fails the operation.
Beta policy: there are no fully autonomous live-budget writes. Every write is dry-run + approval-gated, no exceptions.

Data & security

  • Least-privilege credentials. Per-network scopes, read-only by default; write scopes requested only when you enable writes. Credentials are never stored in code, logs, or fixtures.
  • Tenant isolation. Your data lives in your tenant; no commingling. Cross-customer aggregation happens only with explicit consent, ever.
  • What GM3 stores: campaign structure and spend metrics, creative metadata, entity states, change history, and (with MMP connected) install/revenue-grain attribution data. No end-user PII beyond what your MMP postbacks contain, handled per your data-scope settings.
  • Deletion: customer-controlled data scope and deletion flow — leaving is one command, not a support ticket.

Metric parity — the trust contract

GM3 is built so its numbers tie out with each platform's own dashboard — daily metrics aligned to each platform's own reporting conventions, original currencies preserved alongside consistent cross-network blending, and every metric labeled by source: network-claimed vs MMP-attributed vs SKAN. Where sources disagree, GM3 shows the discrepancy instead of hiding it. Design target: ≥99% parity, verified continuously with design partners.

FAQ

Does GM3 replace my MMP?

No. GM3 reads and reconciles your MMP's data (AppsFlyer first, Adjust next) with network-claimed and SKAN numbers. Your MMP remains your attribution provider — GM3 makes its truth usable everywhere.

Which IDEs/tools work?

Anything that speaks MCP: Claude Code, Cursor, and other MCP-capable agents. If your team already works in an AI IDE, GM3 fits it.

Can an agent spend money on its own?

No. Writes are proposals, checked against your deterministic spend rules, dry-run first, and approval-gated in beta. See Governance.

Do you support web-to-app campaigns?

Yes — CAPI/AEM measurement is in scope alongside SKAN/AdAttributionKit. Mobile-app UA increasingly includes web-to-app funnels; GM3 treats that as core, not an edge case.

What happens when someone edits a campaign directly in a dashboard?

GM3 detects it (state diffing + platform change history), logs it with attribution where the platform provides it, and surfaces it — "2 changes were made outside GM3 yesterday." Your numbers and your change history stay complete either way.

How do I get access?

Join the design-partner beta — we're onboarding a small number of mobile UA teams with live spend.