create_tiktok_ads_ad
Create the ad itself — the creative that runs under an existing TikTok ad group. CREATED PAUSED with no override (TikTok’s own default is ENABLED); it spends nothing until set_tiktok_ads_status(confirm:true), and TikTok additionally reviews it before it can ever show. WHERE THE CREATIVE COMES FRO...
This record as markdown: /tools/hermoso/create-tiktok-ads-ad.md
What create_tiktok_ads_ad does on Hermoso
AI agents use create_tiktok_ads_ad to create or update resources in Hermoso, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Hermoso environment.
Why create_tiktok_ads_ad is rated Medium
An AI agent can call create_tiktok_ads_ad faster than any human can review: one bad instruction and it creates or modifies resources in Hermoso by the hundred, each call as confident as the last.
Attacks that exploit this kind of access
The rule that runs create_tiktok_ads_ad safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Hermoso, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For create_tiktok_ads_ad, this is the rule to start with:
create_tiktok_ads_ad stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Hermoso, apply this rule, and every create_tiktok_ads_ad call is checked against it from then on.
Questions about create_tiktok_ads_ad
Create the ad itself — the creative that runs under an existing TikTok ad group. CREATED PAUSED with no override (TikTok’s own default is ENABLED); it spends nothing until set_tiktok_ads_status(confirm:true), and TikTok additionally reviews it before it can ever show. WHERE THE CREATIVE COMES FROM: run upload_tiktok_ads_creative on a finished Hermoso render (or any public https video) and pass back the videoId AND the coverImageId it returns as imageIds — a TikTok video ad needs BOTH, and TikTok rejects any cover whose dimensions differ from the video, so the video’s own cover is the only one that reliably fits. A videoId with no imageIds is refused here, for free. AN IDENTITY IS MANDATORY AND HAS NO DEFAULT: identityId AND identityType both come from list_tiktok_ads_identities and the ad appears publicly as that TikTok account, so let the USER pick and never guess — the call is refused outright without either. SPARK ADS — RUN A REAL ORGANIC POST INSTEAD: pass tiktokItemId (from list_tiktok_ads_identity_posts or list_tiktok_ads_spark_posts) INSTEAD OF videoId, and the ad IS that TikTok post, keeping its own comments, likes and shares under the account that made it. Spark needs an identityType of TT_USER, BC_AUTH_TT or AUTH_CODE — never CUSTOMIZED_USER, which is a Custom Identity and cannot carry one. THIS MATTERS BEYOND STYLE: TikTok is phasing Custom Identity out — ad accounts created on or after January 15, 2026 cannot create non-Spark ads at all, and existing accounts can no longer create them either, for any ad group delivering to Automatic or Select Placement with TikTok included (only Pangle / Global App Bundle campaigns are unaffected). Defaults: adFormat SINGLE_VIDEO, callToAction LEARN_MORE. THE STATUS IS READ BACK FROM TIKTOK’S OWN STORED ROW, never assumed: if it comes back anything other than DISABLE the note is a Warning: warning that the ad would serve the moment its campaign is enabled — print that verbatim and act on it before touching anything above it. It is categorised as a Write tool in the Hermoso MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
Register the Hermoso MCP server in PolicyLayer and add a rule for create_tiktok_ads_ad: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Hermoso. Nothing to install.
create_tiktok_ads_ad is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the create_tiktok_ads_ad rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for create_tiktok_ads_ad. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
create_tiktok_ads_ad is provided by the Hermoso MCP server (https://app.hermoso.ai/mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Hermoso, and thousands of servers like it.
This server
Across the catalogue