Updated 2026-09-20 after filing the request on a live account. Four things in the first version were wrong and are corrected below.

Key takeaways

  • File the request yourself. Certification and authorization are two separate gates, and nothing connects them on your behalf.
  • Name every ad account on the one request. Authorization state is per ad account, but a single filing covers every account you select on screen three, and they come back sharing one authorization ID.
  • Stop looking for an upload button. Meta asks for the certified URL as a string and validates it against LegitScript’s records.
  • Answer the business type honestly. Only Pharmaceutical manufacturer skips LegitScript, and a telehealth brand has no second route.
  • Audit the destination page before you file. It is read alongside the ad, and certification stops at the root domain, so a pages.dev address is not covered.

To run prescription drug ads on Meta you need two things, not one: an active LegitScript certification for the domain, and a separate authorization request filed inside Business Settings for each ad account that will run the ads. The certificate alone does nothing.

You hold a LegitScript certificate. The ads are getting rejected anyway, or the ad account is already disabled under Drugs and Pharmaceuticals, and every piece of advice you can find tells you to upload the certificate to Meta.

There is nowhere to upload it. Meta’s prescription drug authorization form has no attachment field on any of its four screens.

What it has instead is a request that a human has to file, per ad account. On most disabled telehealth accounts that request has never been opened. Not rejected, not pending, never started, with the certificate live the whole time, which is exactly why nobody thinks to check it.

Below is the procedure, in the order the screens come in.

What you are building

Seven steps, about twenty minutes of clicking, and one dependency you do not control.

By the end you have a read of the authorization state on every ad account in the portfolio, three facts taken off the LegitScript record, one submitted request naming every ad account that will run ads, a destination page that survives the reviewer who is also reading the ad, and copy written so it does not depend on the approval at all.

The dependency is whoever bought the certificate. Get them on the phone before step 2, because steps 3 through 5 stall without them.

Why holding the certificate is not enough

Meta’s Drugs and Pharmaceuticals policy stacks two pieces of work on top of each other, and most people read only the first. Online pharmacies and telehealth providers must be actively certified with LegitScript. Then, separately, the advertiser must request authorization from Meta.

Two gates. Certification is a contract with LegitScript about a domain. Authorization is a request inside Meta that names that domain and the ad accounts. LegitScript does not notify Meta on your behalf, and Meta does not go looking. The request is the only thing that joins them, and nobody files it for you.

Hold the first gate open, skip the second, and what Meta’s enforcement sees is a telehealth brand running prescription ads on an account with no authorization. That is the ban, and it does not care how clean the creative was.

Two more rules from the same policy, worth settling before anyone argues about them. The ads have to carry a disclaimer to consult a licensed health professional or obtain a valid prescription. And ads that only educate or advocate about prescription drugs do not need written authorization at all. If you are selling the prescription, you are in the authorization path.

Step 1: read the authorization state on every ad account

Go to Business Settings, then Authorizations and verifications, then Prescription drug ads. The URL carries a verification_type=RXDRUGS parameter, so bookmark it the first time and skip the menu after that.

A locale note that costs people ten minutes: Meta localises the spelling. On a portfolio set to a British locale the menu reads Authorisations and verifications and the panel says authorisations. Same screen.

The Meta Business Settings panel titled Authorisations and verifications with Prescription drug ads selected. A Request authorisation button sits at the top right. Below it, a list of five ad accounts, each with its own line reading You haven't started any authorisations for this ad account yet. Portfolio name, account names and the profile photo are redacted.
Every ad account in the portfolio gets its own line and its own state. Five accounts, five independent answers. Names redacted.

Read the list, not the button. The button tells you an authorization exists as a concept. The list tells you which accounts hold one, and that is the answer you came for.

Write down the exact wording against each account. “Not started” is the state you are most likely to find and it is nothing like “rejected”. Rejected means somebody looked at it. Not started means the ads were built, published and disabled while the request sat unopened.

Meta’s own sentence on that panel is that you need to request authorization for each ad account that will advertise prescription drugs. Practitioner write-ups disagree about this constantly and several will tell you the authorization is business-level. The screen settles it: there is no portfolio-level answer to read, only one line per account.

That does not mean one submission each. Screen three takes a multi-select, and every account you tick comes back authorized off the same filing, sharing one authorization ID. What is per account is the state, not the paperwork. The trap is leaving an account off the list, not failing to file five times.

Step 2: get three facts off the LegitScript record

Every hard part of the form comes from a record that belongs to whoever bought the certificate. Get it in front of you before you open anything. Pull three facts out of it:

  • the exact certified URL string
  • the legal entity name on the certificate
  • the expiry or renewal date

Two sources work. The LegitScript confirmation email is the one everyone names, and it is also the one that went to a client eight months ago and cannot be found. The merchant’s own LegitScript portal is faster and carries the same facts on two tabs: the certification header shows the account name, the contact, the renewal date and the status, and the Certified Services tab lists the certified URL with its approval status. A screenshot of those two tabs is everything the form needs.

There is no field for a certificate number anywhere in Meta’s form. Do not hold up the filing waiting for one.

The certification header in a merchant's LegitScript portal, showing Account Name, Contact Name, a Renewal Date of 8/25/2027 and a Status of Certified. The account name and contact name are replaced with neutral placeholders.The Certified Services tab of the same LegitScript portal, listing one website with its URL, a tick under Is Primary URL, and an Approval Status of Certified. The URL is replaced with a neutral placeholder.
Two tabs in the merchant’s LegitScript portal carry everything Meta’s form asks for: the entity, the renewal date, the status, and the certified URL with its approval state.

Do not substitute the seal on the website. It resolves, it links to LegitScript’s public checker, and it tells you the domain is certified. It does not tell you which legal entity holds the certificate, and that is the fact most likely to cost you the request.

Expect the names not to match. On these brands the website terms name an LLC, the Meta portfolio is named after a holding company, and the brand on the ads is a third thing.

One data point on which of them to type. On the request that went through, the business name field was filled with the legal entity already on the Meta portfolio’s own business verification, and that string was not identical to the account name on the LegitScript record, which carried the same entity without its suffix. It approved anyway. So the match that appears to matter is against Meta’s verified record of you, not against LegitScript’s label for you.

That is one approval, not a documented rule, so treat it as evidence rather than as permission to guess. Use the legal entity name on your business verification, and get the LegitScript record in front of you so you know whether the two disagree by a suffix or by a whole company.

Step 3: fill in advertising habits, and pick the business type carefully

Screen one asks two questions: where the ads will run, and what type of business this is.

The country list has three entries: United States, Canada and New Zealand. That is the whole eligible world for prescription drug ads and it matches the policy text. If your market is not one of the three, the answer is not a workaround, it is a different business model.

The business type dropdown has exactly three options.

The Advertising habits step of Meta's prescription drug authorisation form. A dropdown labelled What type of business is this is open, showing three radio options: Online pharmacy, Pharmaceutical manufacturer, and Telehealth provider. A progress bar sits below at roughly one third. Portfolio name, account names and the profile photo are redacted.
Three options, and the choice decides which review you go into. Pharmaceutical manufacturer is the only one that routes to Meta’s internal review instead of LegitScript.

Online pharmacy and Telehealth provider both land on LegitScript. Pharmaceutical manufacturer is the single route that skips it. If you sell through licensed providers and a compounding pharmacy, pick Telehealth provider, accept that the certification is load-bearing, and stop hunting for an alternative path, because there is not one. Picking manufacturer to dodge it is a misrepresentation to Meta on a form that exists to check exactly this, which is a creative way to lose the portfolio rather than one ad account.

Step 4: paste the certified URL, because there is nothing to upload

Screen two is one free-text box. Meta’s help text on it, verbatim:

Provide the website URL that has been certified by LegitScript. You should be able to find this information in the confirmation email sent by LegitScript. If our certification expires, we may lose authorisation and these ads may be taken down.

The Certified URL step of Meta's prescription drug authorisation form. A single empty text field labelled URL with the placeholder Certified URL, above Back and Next buttons and a progress bar at roughly two thirds. No attachment field or upload control appears anywhere on the screen. Portfolio name, account names and the profile photo are redacted.
One text field, no attachment control, no document upload. Meta validates a string against LegitScript’s records.

Paste the string from the record exactly as it appears, and move on. There is no upload to find, which is why “upload the LegitScript certification” is advice that sends people in circles until they give up and file nothing.

Then act on the second half of that help text. The authorization is tied to a certification that expires, so put the renewal date in a calendar somebody other than the certificate holder can see. The failure mode is an approved account that goes quiet months later for a reason nobody connects back to a lapsed certificate.

Step 5: name the business and select the ad accounts

Screen three asks for a business name as free text, then gives you a multi-select listing every ad account in the portfolio.

Select the accounts that will run the ads. A disabled account can go on the list: on this filing one of the three was disabled and under appeal, and it took the authorization exactly like the other two, same ID, same “Verification successful”.

Whether that helps the appeal is a separate question and I do not have an answer to it yet. What it does remove is the most obvious reason to reject one, because the account is no longer a telehealth brand running prescription ads with no authorization on it. Filing costs nothing and the authorization attaches whatever state the account is in.

Screen three’s Next does not file anything. It opens a fourth screen, Review your information, which lists the country, the certified URL, the business type, the business name and every ad account you selected, with a Back button and a Submit button. Nothing reaches Meta until you press Submit there.

That is worth knowing in both directions. You can walk the whole form to read it without risk, which is how the first version of this article got written. And the review screen is the last place to catch a typo in the certified URL, which is the one field with nothing to fall back on.

Read every line on it before you submit. Meta normalises the URL you typed, so check that what it shows back is the string you meant.

A Meta dialog headed Review your information, above a line telling you to review before submitting your request for authorisation to advertise prescription drugs. It lists Country, United States; Certified URL; Business type, Telehealth provider; Business name; and Ad account(s), three of them. A Back button and a Submit button sit at the bottom right. The URL, the business name and the account names are replaced with neutral placeholders.
Screen three’s Next opens a review page. The submit is here, not there.

What happens when you press Submit

Nothing, for about two seconds, and then it is done.

There is no review queue, no pending state and no email. The dialog returns “Authorisation successful. You are now able to run ads about prescription drugs.” Re-read the panel from step 1 and every account you named has flipped from “You haven’t started any authorisations for this ad account yet” to “1 associated authorisation”, with the certified URL, the country, an authorization ID and “Verification successful”.

A Meta dialog headed Ad account is authorised, showing a gift-box illustration above the words Authorisation successful and the line You are now able to run ads about prescription drugs. A single Done button sits at the bottom right.
Two seconds after Submit. No queue, no pending state, no email.

That tells you what the check actually is. Meta is not reading your site and not assessing your business. It is looking the certified URL up against LegitScript’s records and answering. Which means the thing to get right is the string, and the thing you cannot talk your way through is the certification.

The same Authorisations and verifications panel as earlier, one day later. Of the five ad accounts listed, the first two still read You haven't started any authorisations for this ad account yet. The last three each read 1 associated authorisation and are expanded, and all three show the same certified URL, the same country code US, the same authorisation ID and a green Verification successful tick. Portfolio name, account names, the certified URL, the authorisation ID and the profile photo are replaced with neutral placeholders.
The same panel as step 1, one day later. Three accounts, one filing, one authorization ID.

It also means the delay in this whole process was never Meta. On the account this article came from, the request sat unopened while the ads were built, published and disabled. The form that would have prevented it takes two seconds to answer.

Step 6: strip the claims off the destination page

This is not a gate on the authorization. The request approved on an account whose destination page carried all five of the claims below, because the check never opens the page. It is a gate on every ad you run afterwards, which is the part that actually costs you. The ad is not reviewed alone: the page it points at is read with it, and a clean ad dies on what the page says.

Open the destination page and hunt for these five shapes. On one disabled account, nineteen of the twenty published ads pointed at a homepage carrying all five at once.

what to look for why it goes
a percentage body-weight figure with a compound name and a time window a clinical outcome figure sitting next to a compounded product
a named provider shown replying minutes ago reads as a real message from a real clinician
“physician-prescribed” in the hero says physician where it should say licensed provider
a HIPAA claim in the top bar a compliance assurance, which is not a thing you assert in advertising
a money promise tied to not being prescribed a price promise on a prescription product

The first two are the serious ones. The FDA’s guidance for telehealth companies promoting compounded drugs is a list of prohibitions, not a template: no describing a compounded drug as a generic version or as the same as an approved drug, no claiming FDA approval, no claiming it is clinically proven to produce the same result, no branding that implies the telehealth company is the compounder. In March 2026 the FDA sent 30 warning letters to telehealth companies for exactly those claims.

Fix the page first anyway. LegitScript is reading it too, because its certification review covers affiliates, commonly owned domains, partners and links, so a claim on the destination is exposure on the certificate as well as on the ad account. It is also the cheapest of the three fixes and the only one entirely in your hands.

Step 7: point the ads at the certified root domain

LegitScript’s certification FAQ is explicit: certification applies to the root domain, and subdomains are covered by the same certificate. So put the landing pages on a subdomain of the certified site. No new application, no new fee, one CNAME.

Do not use a pages.dev address. It sits on the Public Suffix List, which makes anything under it a registrable root domain in the eyes of browsers and of every system that reasons about eTLD+1. Your preview URL is a different site, not a subdomain of yours, and the certification does not reach it. The same goes for every other free hosting domain on that list.

I could not find a Meta rule that says an ad pointing at an uncertified domain is auto-rejected, and I am not going to invent one. What is documented is the certification’s scope and LegitScript’s review of linked domains. The inference from those two is that a prescription ad landing on an uncertified domain is exposure on both the ad review and the certificate, and repeated rejections in a restricted category are how accounts get disabled. Keep pages.dev for internal preview.

What the approval does not change

Plan the creative as though the approval buys less than you think, because it does. It opens the vocabulary. It does not touch the rules that come from Meta’s other policies.

The split is clearest on a B2B health infrastructure client that holds authorization on one ad account out of five. Approval unlocked drug class names, compound names, and words like pharmacy, prescription and compounded. It changed nothing about outcome claims, body framing, or ads that assert something about the viewer.

Those come from Personal Attributes and Health and Wellness, which bind everyone regardless of authorization. Meta’s own example of a violation is an ad asking whether the reader has a medical condition. A question about an ordinary experience is allowed. An assertion about the reader’s body is not, and that line is the whole reason question-shaped hooks are usable in this category at all.

So when you borrow a rulebook from another brand in the vertical, take their prohibitions and never their permissions. Prohibitions are platform policy and they transfer. Permissions are an authorization that account holds and yours does not.

One more thing the approval does not cover. Ad review and data source classification are different systems, so an ad can pass review and keep delivering while Meta classifies the destination domain and suppresses conversion events coming off it, with no alert anywhere. Check the data source category separately from the ad status, and read what each funnel stage should actually cost before you set a budget against a lead event.

Hand it to Claude Code

The audit half of this is a reading job, and reading jobs are what I hand over. Point Claude Code at the account and the site:

Audit this telehealth brand's readiness to run prescription drug ads on Meta.

1. In Meta Business Settings > Authorizations and verifications > Prescription drug ads,
   list EVERY ad account in the portfolio and its authorization state verbatim. Do not
   summarise to "authorized" or "not authorized". Screenshot the panel.
2. Open the LegitScript public checker for the brand's root domain. Record what it says
   and what it does NOT say. A seal image on the site is not evidence.
3. Crawl the ad destination page and every page linked from the primary nav. Flag, with
   the exact text and where it sits: outcome or percentage figures, named clinicians shown
   replying, the word physician where it should be licensed provider, HIPAA or
   confidentiality assurances, price promises, urgency, comparisons to a brand-name drug,
   and any claim of FDA approval or sameness.
4. Resolve the eTLD+1 of every ad destination against the Public Suffix List and say
   whether each one falls inside the certified root domain.
5. Output a table: gate, state, evidence, who can fix it. Mark anything you inferred as
   inference. Do not fill a gap with a plausible answer.

The last two lines are the ones that earn their place. Compliance work is where a model most wants to be helpful, and a confident guess about what a policy says is worse than a blank cell. Same principle as everything else in the operating model: the tool’s job is to be sceptical.

When not to do this

Four cases where this procedure is the wrong move.

The certificate is not actually live. The form has nothing to hold. Certification comes first, and it needs real time on the plan, because it is the long pole and nobody inside Meta can accelerate it.

Nobody can tell you which entity holds it. The business name field is free text, and while a filing went through on an entity name that did not exactly match the LegitScript record, one approval is not a rule. Get the record in front of you before you type, so that if it is ever questioned you can say what you based it on.

The ads only educate. Meta’s policy says ads that educate, advocate or run a public service announcement about prescription drugs do not need written authorization. Ads that sell one do. If the campaign genuinely sits on the education side, you are solving a problem you do not have.

You are betting the business on the category staying open. In December 2025 a coalition of 35 state attorneys general asked Meta to limit US prescription drug ads to FDA-approved medications. As of my last read of the policy text, no such rule appears in it. That is a live risk to compounded advertising, not a current rule, and the honest planning position is to keep a non-prescription creative set ready rather than to assume either outcome.

None of this is legal advice and I am not your compliance officer. It is the order the screens come in, which turns out to be the part nobody writes down. If you want the rest of the machine around it, that is what I build, and the case studies show what it looks like on live accounts. For the health vertical specifically, the clinic build is the closest shape, and telehealth founders come in through here.

I run paid acquisition end to end for regulated and expert-led brands: the compliance gates, the creative, the landing pages, and the tracking that proves which ad produced the money. One person, accountable for the number.

Work with me 1-on-1Read the rest of the breakdowns

We already hold LegitScript certification. Why did Meta reject the ads?

Because certification and authorization are two different gates. LegitScript certifies the domain. Meta then needs a separate authorization request, filed inside Business Settings, that names the certified URL and the ad accounts. LegitScript does not notify Meta on your behalf and Meta does not go looking. Until that request is filed and approved, the account is running prescription ads with no authorization on it.

Does one approval cover the whole business portfolio?

No, and it does not cover the accounts you left off the form either. The panel lists every ad account in the portfolio with its own separate state, so a portfolio with five accounts shows five independent lines. But you do not file five times. Screen three is a multi-select: tick every account that will run, submit once, and they all come back authorized against the same authorization ID. An account you did not tick stays unauthorized.

Where do I upload the LegitScript certificate?

Nowhere. The form has no attachment field, no document upload and no certificate PDF anywhere in it. The certified URL screen is a single free-text box, and Meta validates that string against LegitScript’s records. This is why people stall: they go hunting for an upload button that has never existed, and never file the request at all.

Can I pick Pharmaceutical manufacturer and skip LegitScript?

Only if you actually are one. The business type question offers Online pharmacy, Pharmaceutical manufacturer and Telehealth provider, and manufacturer is the one route that goes to Meta’s internal review instead of LegitScript. A telehealth brand has no second route, which makes the certification load-bearing rather than optional. Picking the wrong type to dodge a requirement is a misrepresentation to Meta.

Can the ads point at a Cloudflare Pages or Vercel preview URL?

Not safely. LegitScript certification applies to the root domain and its subdomains, so a subdomain of the certified site is covered with no new application. A pages.dev address is not a subdomain in any way that matters, because pages.dev sits on the Public Suffix List and is therefore its own root domain. Use a subdomain of the certified root instead.