pixellint

The _fbc cookie is the click, not the raw fbclid

Short answer

The pixel writes these cookies on your domain; CAPI cannot see document.cookie. If the server event omits them, you are matching on email and IP alone, which is how hybrid setups underperform the pixel.

Validate a pixel Open the rulepack

Do not mint a fake _fbp

If the pixel never ran, you can still build _fbc from the landing fbclid in that format. You cannot invent an honest _fbp. That random is the browser id the pixel minted. A server-generated random that changes per event is a new person on every Purchase. A reused constant is one fake browser for the whole shop.

Omit fbp when you do not have the cookie. Do not generate fb.1.Date.now().Math.random() to satisfy a linter you wrote. Pixellint will accept any last segment that matches the regex. Matching the regex is not the same as matching a real browser Meta already saw.

Where they die

ITP, consent wipes, subdomain mismatches, and HttpOnly cookies the tag cannot read. A checkout host that is not the landing host will not have _fbp unless you copied it. That is a cross-domain problem that shows up as empty fbp on Purchase.

Safari will expire JS-set tracker-like cookies in days, not in the two-year max-age the pixel set. Returning Safari users look like new _fbp values and still look like themselves if you have email or fbc from a stored fbclid. Design for the cookie to be missing. Persist fbclid server-side so you can rebuild fbc after the cookie dies.

Read them from the request you stored

CAPI workers do not see document.cookie. The page must POST _fbp and _fbc with the event, or the edge must copy Cookie headers from the browser hit into the queue. sGTM can read the first-party cookies on the collector host if Domain was set so the collector actually receives them.

Pixellint is not affiliated with Meta. The fb.N.timestamp.value shape is Meta's documented cookie format. Run pixellint validate json on a payload whose fbc is the raw fbclid and you should see user_data.fbc.invalid.

// WRONG: raw fbclid in fbc
user_data.fbc = 'IwAR0abc';
user_data.fbp = sha256hex(cookie); // hashed, also wrong

// WRONG: minted fbp
user_data.fbp = 'fb.1.' + Date.now() + '.' + Math.random();

// RIGHT: cookie verbatim, or rebuild fbc only
user_data.fbp = cookies._fbp; // omit if missing
user_data.fbc = cookies._fbc || ('fb.1.' + landedAtMs + '.' + fbclid);

Questions

What is the _fbc cookie?

The _fbc cookie is Meta's click cookie, fb.1.timestamp.fbclid. Send it on Meta CAPI and Facebook CAPI as user_data.fbc. Do not paste the raw fbclid.

What is the fbc cookie on Facebook CAPI?

The fbc cookie is the _fbc cookie. Facebook CAPI wants user_data.fbc in fb.N.timestamp.value shape, plaintext. Hashing it is a matching miss.

What is the _fbp cookie description?

The _fbp cookie description is Meta's browser id cookie, fb.1.timestamp.random. Send it on Meta CAPI as user_data.fbp. Do not mint a fake _fbp.

Check the artifact

Paste the pixel URL or JSON body into the playground. Same engine as pixellint validate. Artifacts you test may be stored; see privacy.