Meta Tech Provider & Access Verification

Meta Access Verification (Tech Provider): Why Business Verification Alone Isn't Enough

You passed App Review. You completed Business Verification. Your integration works perfectly for your own team. Then a client tries to connect their Facebook Page, Instagram account or ad account through your app — and it silently fails. The reason usually isn't another permission or another review. It's a separate gate called Access Verification, and it decides whether Meta recognises your business as a Tech Provider allowed to touch other businesses' data.

What Access Verification actually is

Access Verification is the process Meta uses to determine whether your business operates as a Tech Provider — a business that has a legitimate need to access data owned by other businesses in order to provide them a service. If your app is built to be used by other businesses (a SaaS scheduler, a chatbot platform, an ad-management dashboard, a CRM integration), Meta needs to confirm you are who you say you are and that you have a genuine reason to handle their data before those businesses can grant your app advanced permissions.

It is not the same thing as getting a permission approved, and it is not the same thing as verifying your company exists. It sits on top of both.

Access Verification vs Business Verification — the two-gate confusion

Most teams assume “verified” means one thing. On Meta's platform there are two distinct verifications, and clearing one does not clear the other.

Business Verification

Confirms the legal existence and identity of the business entity that owns your portfolio — using documents like registration papers, a business address and a verifiable phone or domain.

It answers: “Is this a real, legitimate company?”

Access Verification

Confirms your business operates as a Tech Provider that can safely access other businesses' data to deliver a service to them.

It answers: “Should this company be allowed to handle its clients' data?”

Business Verification is actually a prerequisite for Access Verification — you cannot begin the Access Verification process until Business Verification is complete and your account has no restrictions on it. That dependency is exactly why so many projects get stuck: the business is “verified,” the app is approved, and yet client onboarding still fails because the second gate was never cleared. Our Meta Business Verification guide covers that first gate in detail.

What triggers the Access Verification requirement

Access Verification isn't something every app faces. It is triggered on a per-permission basis when your app — one created or claimed by a business — requests Advanced Access to certain gated permissions, and that permission is then granted by a user who does not have a role on your app (in other words, a real external client, not your own developer account).

Key point: Access Verification is independent of App Review and independent of access levels. App Review approves the permission. Access Verification approves the business behind the app. A permission still has to be approved for Advanced Access separately — both gates have to be cleared before an outside business can use your app with those permissions.

The gated permissions span Facebook Pages, Ads and Business (for example pages_manage_posts, pages_read_engagement, ads_management, ads_read, business_management, catalog_management, leads_retrieval), Instagram (such as instagram_business_basic and content-publishing permissions), Threads, and WhatsApp business management. If your app requests Advanced Access to any of them for use by other businesses, expect the Access Verification gate to appear. Several of these permissions also carry their own dependency and review requirements on top.

What the process asks — and where it gets slow

To complete Access Verification, someone with Admin access on the business has to categorise and describe how the business uses other businesses' data to provide a service for those businesses. Meta then makes a decision in roughly a handful of business days. On approval, business admins get a confirmation email and app admins get a developer alert. If your app was already claimed before this requirement applied, Meta typically emails you and gives a grace window before enforcement begins.

That sounds simple. In practice it stalls for reasons that have nothing to do with the description you write:

  • Business Verification is not fully complete — so the Access Verification process cannot even start.
  • There is a restriction or flag on the business account, which blocks the process until it is resolved.
  • The person completing it doesn't have Admin access on the correct business portfolio.
  • The use case is described in a way that doesn't clearly match how the app actually accesses client data.

Getting the sequence right — entity structure, portfolio ownership, Business Verification, permission-level Advanced Access, and then Access Verification — is where most of the real difficulty lives. Doing them in the wrong order means redoing work and waiting through another review cycle.

Why this matters for your business

Until Access Verification is cleared, your app works for you but not for your customers. Every external client who tries to grant an advanced permission hits a wall, calls fail for non-role users, and onboarding grinds to a halt. For a SaaS or agency whose whole model depends on connecting many client accounts, that is the difference between a product you can sell and one that only demos.

2 gatesBusiness Verification AND Access Verification — both required
Per-permissionTriggered by Advanced Access on gated permissions
Client-facingBlocks external onboarding until cleared

We handle Meta Tech Provider / Access Verification as part of our app-review and business-verification support — getting the portfolio, verifications and permissions lined up in the right order so client onboarding actually works. You can see how this played out in a real project in our Access Verification (Tech Provider) case study, and if your product connects many client numbers, the related WhatsApp Embedded Signup & Tech Provider onboarding track is worth reading too.

This article is general guidance based on Meta's published developer documentation, which can change. It is not affiliated with or endorsed by Meta. Verification outcomes are decided solely by Meta, and no specific outcome or timeline can be guaranteed.