apple_ads_report
Apple Ads performance \u2014 impressions, taps, installs, spend, TTR, CPT, CPA. level is campaign / adgroup / ad / keyword / searchterm; promotedObjectType is apps (App Store, the default) or business-brands (Ads on Apple Maps). startTime and endTime are REQUIRED, as YYYY-MM-DD. campaignId is REQ...
This record as markdown: /tools/hermoso/apple-ads-report.md
What apple_ads_report does on Hermoso
AI agents invoke apple_ads_report to trigger actions in Hermoso. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call: builds kicked off, notifications sent, workflows started.
Why apple_ads_report is rated High
apple_ads_report triggers real processes with real consequences. An agent gone sideways doesn't fire it once. It starts dozens of builds, sends mass notifications, or burns through compute before anyone looks up.
Attacks that exploit this kind of access
The rule that runs apple_ads_report safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Hermoso, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For apple_ads_report, this is the rule to start with:
apple_ads_report stays usable, but rate-capped: a runaway agent can't fire it dozens of times a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Hermoso, apply this rule, and every apple_ads_report call is checked against it from then on.
Questions about apple_ads_report
Apple Ads performance \u2014 impressions, taps, installs, spend, TTR, CPT, CPA. level is campaign / adgroup / ad / keyword / searchterm; promotedObjectType is apps (App Store, the default) or business-brands (Ads on Apple Maps). startTime and endTime are REQUIRED, as YYYY-MM-DD. campaignId is REQUIRED for every level except campaign \u2014 it moved from the URL into a filter, but Apple still enforces it (measured: \u201ccampaignId filter is required for AD_GROUP reports when promotedObjectType is APPS\u201d), so only a campaign-level report may be account-wide. adGroupId narrows it further. groupBy is restricted PER LEVEL and an unsupported dimension is refused by name, never dropped: campaign and adgroup take deviceClass/ageRange/gender/countryCode/adminArea/locality/storefront/countryOrRegion, keyword and searchterm take only deviceClass/storefront/countryOrRegion, and ad takes only storefront/countryOrRegion. granularity is optional and carries Apple\u2019s own date rules (HOURLY reaches back 7 days and is unavailable on ad and searchterm reports; DAILY 90 days and needs a range longer than one day; WEEKLY 365 days with an end date at least 14 days ago; MONTHLY needs an end date at least 90 days ago). FOR A SINGLE DAY, OMIT granularity \u2014 the totals come back in each row\u2019s totalMetrics. Search-term reports are ORTZ-only. grandTotals adds a summary row; emptyMetrics includes entities with no delivery \u2014 App Store reports only, never together with groupBy, and never on a search-term report. A report with NO rows genuinely means there was NO delivery in that window and scope: say exactly that, and never present zeros as measured performance. Read-only and free, so run it first after connecting \u2014 it proves the credentials work with zero spend risk. It is categorised as a Execute tool in the Hermoso MCP Server, which means it can trigger actions or run processes. Use rate limits and argument validation.
Register the Hermoso MCP server in PolicyLayer and add a rule for apple_ads_report: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Hermoso. Nothing to install.
apple_ads_report is a Execute tool with high risk. Execute tools should be rate-limited and have argument validation enabled.
Yes. Add a rate_limit block to the apple_ads_report rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for apple_ads_report. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
apple_ads_report is provided by the Hermoso MCP server (https://app.hermoso.ai/mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Hermoso, and thousands of servers like it.
Across the catalogue