pixellint

A tracking pixel sends an event, while a cookie stores a value

Short answer

A pixel is the browser request that reports a page view, impression, or purchase. A cookie is browser storage scoped to a site or host. A pixel can fire without a cookie, and a cookie can exist without a pixel firing. The request tells the collector what happened; an available identifier helps it connect that event to an earlier visit or ad click.

Validate a pixel Open the rulepack

Follow one purchase from page to collector

A checkout page runs a tag after an order succeeds. The tag sends a request to a measurement endpoint with an event name, order value, currency, and perhaps an order ID. That request is the pixel, even if JavaScript used fetch or sendBeacon rather than a one-pixel image. The collector can count the event without a browser cookie. It may have less information for matching that event to a prior ad interaction.

A cookie has a different lifecycle. A response can set it with Set-Cookie, or page JavaScript can write a cookie that it is allowed to access. On a later eligible request, the browser may attach that value in the Cookie header. The cookie is not a conversion event. Leaving a cookie on the shopper's device does not tell an ad platform that a purchase happened.

First-party identifiers are still separate from the event

Meta's _fbp and _fbc are examples of first-party browser values used for matching. _fbp carries a browser identifier; _fbc can preserve a Meta click identifier when fbclid was present on the landing URL. A server event can include those values if your site captured them. Sending an _fbc value is not itself a Purchase event, and a Purchase event without _fbc may still be accepted through other matching signals.

A Google Ads conversion linker likewise helps retain click information in first-party cookies. Its presence does not create a conversion action or fire a purchase tag. Keep the three checks separate: did the click identifier reach the landing page, was it stored where allowed, and did the conversion event leave at the right moment?

Inspect both sides in DevTools

Open Network, preserve the log, and complete a test purchase. Filter for the vendor collector. Inspect the request URL or body for the event name and transaction fields. Then inspect Request Headers for Cookie and the response for Set-Cookie. In the Application storage panel, inspect the cookie under its actual domain, not just the top-level shop domain. A 200 response proves the request reached an endpoint; it does not prove attribution or correct conversion classification.

Repeat with a clean browser profile and with the privacy configuration you need to support. If the request disappears, debug tag loading, consent, CSP, and blocking. If the request remains but its identifier disappears, debug landing click IDs, cookie scope, SameSite, and cross-domain checkout. Pixellint can validate the captured request or CAPI JSON; it cannot infer whether a browser stored a cookie on a visit it never observed.

When a server event helps

A backend can send the confirmed order event even when a thank-you page never loads. It still needs identifiers that were lawfully collected earlier if you expect the vendor to match the order to an ad. A server request does not repair a click ID that was lost before checkout, and moving the request to your backend does not remove consent obligations.

Use the browser event and server event as two transports for the same order only when the vendor's deduplication fields are aligned. For Meta, share the event name and event ID across Pixel and CAPI. That solves duplicate reporting, which is a different problem from cookie storage or matching.

Questions

Can a tracking pixel work without cookies?

Yes. The request can report an event without a cookie. Matching that event to an earlier visit or ad interaction may be weaker.

Is a tracking pixel a cookie?

No. The pixel is an HTTP request. A cookie is a stored value that the browser may attach to a later eligible request.

Sources

Check the artifact

Paste the pixel URL or JSON body into the playground. Same engine as pixellint validate. Artifacts you test may be stored; see privacy.