# REPORT — spike: can Claude Code run the Felhom.eu Facebook Page? (2026-10-08) Own file, not `REPORT.md`: parallel sessions share this clone (`CLAUDE.md` workflow rule). ## For the operator - Yes. Claude can make posts on the Felhom.eu Page. - The key works. It never runs out. - Test: one scheduled text post and one scheduled photo. The Hungarian accents came back exact. Both are deleted. - **Later, before real public posts:** switch the Meta app to „Live". It needs a Terms of Service web address. If you do nothing: only people with a role on the app see the posts. - Optional check: Meta Business Suite → Planner should show no scheduled post. ## Results | Scenario | Result | Evidence | |---|---|---| | A — key | PASS: `SYSTEM_USER`, app 2273465403490709, valid, `expires_at 0` | `A1-debug-token.json` | | B — Page | first run FAIL (no Page assigned); after the operator's click PASS: Felhom.eu `1360018983863273`, `CREATE_CONTENT` + `MODERATE` + `ANALYZE`; Page token `PAGE`, `expires_at 0` | `B2`, `B3` | | C — reads | PASS: Page fields, feed (1 post), 3 insights metrics alive on v26.0 | `C1`–`C3` | | D — text post | PASS: unpublished, schedule equal, hex equal, deleted, gone | `write-test/D*` | | E — photo | PASS: only a photo `id` returned (no `post_id`); caption hex equal; DELETE on the photo id; gone. **Gap:** its publish state could not be read | `write-test/E*` | | F — mode | no refusal in development mode (measured); dev-mode posts seen only by role users (read); Live needs ToS URL etc. (read) | spike doc | - **Secret scan:** with the planted `EAAfakeprobe` control: 1 hit; after removing it: 0. No `access_token` key, no `access_token=` URL in the evidence. Staged-diff scan: the one hit is the test file's fake token. - **Accent round-trip:** D yes (message hex equal). E yes (photo caption hex equal). - **Teardown — Facebook:** created and deleted: text `1360018983863273_122096071749511222` (run 1), text `1360018983863273_122096072277511222` and photo `122096072325511222` (run 2). The GET after each DELETE: text posts (#10) „Object does not exist, cannot be loaded due to missing permission…"; photo (#100/33) „Unsupported get request. Object with ID '122096072325511222' does not exist…". **Host:** nothing provisioned. **Hub:** nothing created. - **Register:** 136 → 138; opened R-914 (CC, READY), R-915 (operator, Live mode). Closed 0. - `unproven.py --summary`: not walked 35 of 55 (unchanged). ## Fixed without a row - The probe proved removal on code 100 only; Meta answers a deleted post with code 10. Run 1 stopped (exit 7) on a post that was in fact gone (same token read it 200 just before). `gone_error()` + 4 tests; run 2 passed. ## Observations - The photo endpoint returned no `post_id` and the photo has no `is_published` — FILED: R-914 (gap the skill closes). - The first Page miss was a Page-assignment gap (the app was assigned, the Page was not); the same key worked after the click, no regeneration — NOT-A-FINDING: recorded in the spike doc. - The logo: `website/assets/logo.png` (Facebook photos take no SVG) — NOT-A-FINDING. - No `Co-Authored-By` line on the commits: the brief forbids it (§12).