pixellint

What is a conversion API

Short answer

Ad blockers, ITP, and checkouts that finish on another origin mean the thank-you pixel is optional. The order record is not. A conversions API is how you send that record to the ads platform without waiting for a tag.

Validate CAPI JSON Open the rulepack

What conversion API events contain

A conversion API is an HTTPS POST with a JSON body, an access token or API secret, an event name, a time, and identifiers: click id, cookie, hashed email, IP, user-agent. Conversion API events are those rows. Meta Conversions API posts to the Graph API events edge and requires access_token. TikTok Events API posts pixel_code plus event to business-api.tiktok.com. Reddit CAPI v3 posts to ads-api.reddit.com. GA4 Measurement Protocol requires api_secret and exactly one of measurement_id (G- form) or firebase_app_id.

Conversion API and conversions API name the same POST. Meta prints the plural on the product page. Pixellint validates the body the same way it validates a pixel URL: required fields, formats, and the traps the vendor documented. It does not invent a shared schema. There is not one.

Meta CAPI and Facebook CAPI are the same product

Meta CAPI, Facebook CAPI, Facebook Conversions API, and Meta Conversions API are one Graph events POST. A conversion API validator lints that CAPI JSON. CAPI not working is usually HTTP 200 with empty Test Events: 13-digit event_time, a raw email in em, or website without event_source_url.

Conversion API events are the rows. Conversion API and conversions API are the same job. TikTok Events API, Reddit CAPI, and LinkedIn Conversions API are sibling products with different clocks, not aliases of Meta CAPI.

The clocks are incompatible on purpose

Meta CAPI event_time is Unix seconds, exactly 10 digits. Date.now() is 13 digits (milliseconds). A 13-digit value lands tens of thousands of years in the future, outside Meta's window (event_time can be up to 7 days old). vendor.meta-conversions-api.body.event_time.invalid is that miss. Pinterest CAPI uses the same seconds clock. Reddit CAPI v3 event_at is the inverse: exactly 13 digits. LinkedIn conversionHappenedAt is 13 digits. GA4 timestamp_micros is 16 digits (microseconds). TikTok Events API timestamp is ISO 8601; an epoch number is stamped as arrival time.

Copying one helper across vendors is how one pipe attributes and the next one files the purchase in 1970 or in the year 56000. Convert at the edge. The field name is not a hint you can trust across companies.

Identity is hashed on some fields and forbidden on others

Meta user_data.em, ph, fn, ln, ge, db, ct, st, zp, country, and external_id must be SHA-256 hex. Uppercase hex is allowed: Meta lowercases the INPUT, not the digest. The same over-hashing trap exists on Snap and Pinterest. client_ip_address and client_user_agent MUST NOT be hashed; vendor.meta-conversions-api.body.hashed_plaintext_field is that shape. TikTok hashes context.user.email, phone_number, and external_id, and wants context.ip and context.user_agent in the clear. OpenAI Ads wants lowercase hex on emails_sha256 and the hashed lists, and leaves IP, user-agent, geo, and obref in the clear.

Reddit CAPI v3 is the odd one: email and phone MAY be raw or hashed. That is not permission to send a raw address to Meta. LinkedIn requires user.userIds even when the list is empty and matching rides on lead or userInfo instead.

A 200 does not mean the event exists

PostHog documents that a capture missing event or distinct_id still returns HTTP 200 and is not ingested. Segment track returns 200 without checking that the call had an event name. GA4 Measurement Protocol returns 204 on the collect endpoint; that is not schema validation. Meta often returns 200 with per-event errors in the JSON, or accepts a batch and reports later.

Validate the body before you ship. Required fields, timestamp units, hashed versus raw, ISO 4217 currency. That is what the rulepacks encode from vendor docs. Status code is liveness.

What it does not do

It does not replace a click id you never stored. It does not hash an email you never collected. It does not fix a pixel that fires Purchase on the landing page. It does not turn a data-center IP into a shopper. Garbage in, matched garbage out.

It also does not unify the names. Meta Conversions API, TikTok Events API, Snap Conversion API, Pinterest Conversions API, Reddit Conversions API, LinkedIn Conversions API, X conversion API, Google Ads enhanced conversions and UploadClickConversions, GA4 Measurement Protocol: same idea, incompatible payloads. TikTok Events 2.0 at /open_api/v1.3/event/track/ is a different envelope from the pixel track pack. Reddit v2 ISO event_at is a different shape from v3.

Sibling conversion APIs

Reddit CAPI and the Reddit conversion API are one ads-api.reddit.com POST. Pinterest CAPI is the conversions API Pinterest documents on the ad account events path. X conversion API is website conversion events, not a Meta Graph body. TikTok pixel Events API is ISO 8601 on the server; tiktok pixel standard events are the browser pipe. Snap CAPI writes WEB. Microsoft CAPI posts eventType and seconds. OpenAI CAPI is milliseconds. Nextdoor CAPI is seconds plus event_name.

CAPI implementation is pixel plus conversion API events, same event_id. A CAPI tester lints CAPI JSON before Test Events. Meta standard conversion events are PascalCase. Pinterest standard events are lowercase. A website pixel checker lints facebook.com/tr. None of those names share a JSON schema.

CAPI not working

CAPI not working and conversions API not working are the same miss: CAPI 200 and Test Events empty. test_event_code leftover on Meta CAPI is how a conversion API event never trains. A CAPI tester lints CAPI JSON before you rotate the token.

LinkedIn CAPI is milliseconds, not Meta seconds. LinkedIn insight tag documentation covers the image pixel plus that POST. CAPI implementation is still two pipes.

Wrong clock, right status

The usual first bug is Date.now() copied into Meta event_time. The POST succeeds. Events Manager stays empty or the event never attributes. Count the digits before you debug the token.

// Wrong: 13 digits. Meta and Pinterest want seconds (10).
{"event_name":"Purchase","event_time":1770000000000}

// Right for Meta / Pinterest CAPI
{"event_name":"Purchase","event_time":1770000000}

// Right for Reddit CAPI v3 (milliseconds) and LinkedIn (conversionHappenedAt)
{"event_at":1770000000000}

// Right for GA4 MP (microseconds, 16 digits)
{"timestamp_micros":1770000000000000}

// Right for TikTok Events API (ISO 8601). An epoch here is arrival time.
{"timestamp":"2026-08-21T18:04:00Z"}

Questions

What is a conversion API?

A conversion API is a server POST of conversion API events your backend already knows: purchases, leads, app events. Conversion API and conversions API name the same job. Meta prints Conversions API and CAPI.

What is a conversions API?

A conversions API is a conversion API. Meta prints the plural. Meta CAPI and Facebook CAPI are that Graph events POST. conversion API events are the rows.

What are conversion API events?

Conversion API events are the rows on a conversion API: event name, time, match keys, value. Meta CAPI and Facebook CAPI name those rows on the Graph events edge.

What is test_event_code?

test_event_code on Meta CAPI and Facebook CAPI diverts the event into Test Events. Strip it in production. A leftover code is how a conversion API event never trains.

What is Snap CAPI?

Snap CAPI is Snap's conversion API. action_source is WEB, not website. It is not a Meta CAPI body with a Snap host.

What is Microsoft CAPI?

Microsoft CAPI posts to capi.uet.microsoft.com. eventTime is seconds. It is a sibling conversion API, not Meta CAPI.

What is OpenAI CAPI?

OpenAI CAPI is the OpenAI Ads Conversions API. timestamp_ms is milliseconds. It is not a Meta CAPI body on an OpenAI host.

What is Nextdoor CAPI?

Nextdoor CAPI posts event_name, seconds, and a match key. It is a sibling conversion API, not Meta CAPI.

Check the artifact

Paste the pixel URL or JSON body into the playground. Same engine as pixellint validate. Artifacts you test may be stored; see privacy.