changelog
What changed in AdBuyMCP, week by week
A short application: five questions, no card. Approved accounts get the whole loop in their own sandbox, up to a monthly cap. Live spend is open to paid design partners.
- changes listed
- 40
- weeks covered
- 5
Everything below runs in the deterministic sandbox. No rail has activated a campaign or spent money, so where a connector is described as reading a live API, the access was read-only. The rail grades are on the supply page.
Week of
Committed
Paid search and paid social joined the plan.
Search and social now sit beside CTV, audio, addressable TV, cinema and DOOH, each with its own compiler, policy baseline, plan floor and structured creative.
ChannelsEach clause of your sentence gets a verdict.
Every requirement in the brief is marked either represented, with the kind of evidence behind it (semantic, modelled or supplier catalogue), or unsupported, with the reason. You can see what reached a channel's targeting and what did not.
Plans keep what is unknown marked as unknown.
Plans carry a forecast-uncertainty block. Audience size stays unknown instead of being guessed, reach without a population figure behind it is labelled as an upper bound, and a place the product does not recognise never widens to the whole UK.
Campaigns are staged with spending switched off.
On the API rails the product builds each campaign paused or disabled, reads it back exactly and reports it as pending approval. Switching spend on is a separate step that a person approves.
A campaign that never ran can be cancelled cleanly.
A campaign that was staged but never switched on is cancelled through a zero-delivery route, which needs the supplier's stopped status and a zero-delivery report as its evidence.
Invoice reconciliation takes two people.
Before funds are released against a supplier invoice or export, it is reviewed by a different person from the one who uploaded it.
Supplier money figures are range-checked.
Every pounds-to-pence conversion from a supplier report is checked before it reaches your fee or statement. An out-of-range figure is rejected instead of being rounded, and a build check fails if an unchecked conversion comes back.
Six connectors were added.
Google Ads, Microsoft Ads, Meta, TikTok, Plausible and Google Data Manager joined the platform. The ad platforms stage a campaign paused and report it as pending approval, and none of them reports that spend began.
Supply statusBookings wait for a person to record the supplier's answer.
A booking request is queued, and a named person records what the supplier actually said within a 12-hour confirmation window. An overdue booking is never treated as accepted.
Clients for brand lift, identity cohorts and postcode classification are built, and none is contracted yet.
The product has clients for Cint brand-lift studies, EUID identity cohorts, Customer Match for DV360 and CACI Acorn postcode classification, each with a way out to a person. Acorn still needs its licence, and Cint needs a quote and account terms.
Every figure is labelled observed or modelled.
The dashboard became a brand workbench that shows the label on every figure, and the public tracking pixel refuses events shaped like conversions.
MeasurementDOOHMCP and CTVMCP are scoped versions of the same platform.
DOOHMCP covers DOOH only and CTVMCP covers CTV only, with their authority fixed by configuration and signed claims. The product's working name, Chorus, became AdBuyMCP on every screen.
MCP serverThe API and MCP reference is written and waits for the product web app to deploy.
The product's web app now carries an API reference for every operation, an MCP reference for every tool, OpenAPI 3.1 downloads and a runnable sandbox example. They go live when the web app is deployed, which has not happened yet.
Week of
Committed
Agents work inside a mandate you grant.
Missions, versioned and revocable mandates (allowed actions, currency, a money ceiling and an expiry), single-use approvals bound to one exact action, and a record of decisions, evidence and exceptions all run from an operator console.
MCP serverA payment reversal or an overspend locks the account.
New launches stop, API lines are paused, stop tasks go to the manual rails, and only a person can clear the lock.
Plans and creative say when fallback code wrote them.
When the deterministic fallback produced a plan or a piece of creative instead of a model, the output says so.
Live buying on an unproven rail needs two things a person grants.
The first is a verified supplier dossier. The second is a single-use grant for that exact campaign and supplier, capped in pounds and with an expiry. This replaced a process-wide allowlist.
Supply statusAgents can see supplier authority and cannot change it.
The dashboard and the MCP server show dossiers and grants read-only. Verifying, issuing and revoking stay with signed-in people.
The MCP server moved to the 2026-07-28 protocol.
Older clients still work, and tests pin the older handshakes.
MCP serverAgent sign-in got stricter.
Every delegated agent grant is checked against the API's verified identity on every call, so one shared credential cannot stand in for another. An identity-provider outage returns an error the agent can retry instead of a wrong answer.
Week of
Nothing a buyer would notice this week. The work went into tests, linting and the coverage gate.
Week of
One screen lists everything blocking a launch.
Before launch the product lists creative, wallet cover, supplier evidence, and whether a lift test could be powered on your data.
You can say what counts as a result.
A commercial brief takes the product, the KPI and the conversion definition. Conversions upload in batches that are safe to retry, and response is tracked with a cookieless pixel, vanity URLs and promo codes.
MeasurementEvery connector is graded on an evidence ledger.
Each rail is graded from sandbox-only up to report-verified, and credentials alone never promote a rail.
Supply statusTwo copies of the server cannot charge you twice.
A database lease with fencing stops two API copies processing the same delivery, fee or wallet debit.
A long reporting outage still reconciles.
Report cursors reach back to the last day that actually reconciled, and a line whose reports keep failing is parked with its funds held.
Cinema, AdSmart and host-read audio move only when a person acknowledges a step.
Steps move in order, carry the sales house's reference and never advance on a timer.
CinemaA crash mid-launch cannot create a duplicate campaign.
Every outbound call is recorded with a stable idempotency key before it is made. If the outcome is unclear, the funds are held and the attempt waits for a person.
Approval follows the exact creative.
A supplier approval is tied to a fingerprint of the approved file, so an edited creative goes back for approval instead of inheriting the old one.
Creative studioThe Insights tab shows pacing and any refused lift test.
It shows pacing against the flighting plan, CPM and cost per acquisition by channel, whether a mix model is ready and what blocks it, and any lift test the product refused, with the reason.
MeasurementDelivery is reported per board, show or app.
Where the supplier reports it, each unit shows days run, spend and a stated coverage percentage, and per-unit spend adds back to the line total to the penny.
The mix model refuses to fit on thin history.
The small mix model waits for about 26 weeks of varying history and tells you what to run in the meantime.
MeasurementYou can pick DOOH screens on a map.
Drag over a UK region to select the screens in it.
Digital out-of-homeEach AI model's licence shows beside its price.
The default image model moved to an Apache-2.0 licence, and asset pricing shows each model's position on commercial use. A model not on the list reads unverified.
Creative studioReports and exports arrived.
The product added a printable campaign report, CSV exports of delivery and statements, DOOH creative revision in your own words and an audit trail. The same change removed an unsourced per-asset production-cost range.
Responses that reported success over a failure were fixed.
Unknown fields are rejected, where a pause for one channel used to pause all five. A retried top-up no longer credits twice, rates are averaged instead of summed, a persona behind a running campaign cannot be deleted, and a lift test refuses control markets that received delivery.
The Spotify Ads client was corrected against the real API.
Every endpoint path and scope was checked against Spotify's API. All probing was read-only, and no campaign was created.
The Vibe connector reads a US catalogue and cannot serve a UK campaign.
A credentialed read-only session read Vibe's catalogue, which is US inventory only. Activation has never run.
Supply statusLegal lines survive every format.
Legal lines are no longer dropped or recased on DOOH, CTV, cinema or TV, and copy that cannot fit is rejected at the brief instead of being cut short.
Creative studio
Week of
Committed
The first version turned one sentence about your customer into targeting for five channels.
One sentence about your customer compiled into targeting for CTV, audio, addressable TV, cinema and DOOH, with fidelity scores and lawful-basis manifests. It shipped with sandbox connectors, geo-lift with power gating, the fee with its scale tier, AI asset production and an MCP server.
Launch and production checks were hardened.
Launch checks creative readiness and wallet cover. Production refuses to start without authentication, a strong key, PostgreSQL and HTTPS, and sandbox top-ups are labelled as unbacked demo credit.
next step
Try the product these notes describe.
Bring a real brief to a 45-minute session and we’ll plan it live. You describe one audience and watch it turn into native targeting on 7 channels, with the fidelity score and the lawful-basis manifest on screen. It runs in the deterministic sandbox, so it needs no vendor credentials and no card.