pixellint

vendor/amplitude · vendor documented

Amplitude time is milliseconds. Seconds land in 1970.

Date.now() is the correct unit here. Meta's event_time is the inverse. A 10-digit Unix timestamp is seconds, and as milliseconds it is January 1970.

user_id and device_id shorter than 5 characters are silently dropped unless min_id_length is set. One of the two is required on every event. Names that start with [Amplitude] are reserved; $identify is allowed. ip may be $remote. Identify is vendor/amplitude-identify. Group identify is vendor/amplitude-group-identify.

time is 13 digits

Milliseconds since epoch. A JavaScript Date.now() is already in the right unit. Do not divide by 1000 because Meta told you to.

Rule: vendor.amplitude.body.time.invalid

Ids shorter than 5 characters are dropped

Amplitude documents this. The pack flags user_id and device_id that fail the length check, and flags an event with neither identifier.

Rule: vendor.amplitude.body.user_id.invalid

What this pack matches

Hosts
amplitude.com
Paths
…/2/httpapi…
Vendor docs
amplitude.com/docs/apis/analytics/http-v2

Rules

Codes are stable. A finding in CI, MCP, or the playground lands on the same id.

Field Required What it checks Rule ids Source
api_key required It is the project API key the upload is attributed to. Fix: Send the API key of the Amplitude project, and keep it server-side. vendor.amplitude.body.api_key.missing
vendor.amplitude.body.api_key.empty
docs
events required Amplitude reads the events to ingest from this array. Fix: Send an `events` array holding at least one event. vendor.amplitude.body.events.missing docs
event_type required Amplitude documents the event type as required on every event. Fix: Name the event, such as `Purchase Completed`. vendor.amplitude.body.event_type.missing
vendor.amplitude.body.event_type.empty
docs
user_id optional Amplitude documents user IDs as strings of 5 characters or more, and silently drops shorter ones unless `min_id_length` is set. Fix: Use an identifier of at least 5 characters, or set the `min_id_length` option. vendor.amplitude.body.user_id.empty
vendor.amplitude.body.user_id.invalid
docs
device_id optional Amplitude documents device IDs as strings of 5 characters or more, and silently drops shorter ones unless `min_id_length` is set. Fix: Use an identifier of at least 5 characters, or set the `min_id_length` option. vendor.amplitude.body.device_id.empty
vendor.amplitude.body.device_id.invalid
docs
time optional Amplitude documents this as milliseconds since epoch. A 10-digit value is seconds and lands in 1970. Fix: Send milliseconds: a JavaScript `Date.now()` is already in the right unit. vendor.amplitude.body.time.empty
vendor.amplitude.body.time.invalid
docs
insert_id optional Amplitude uses it to drop duplicate events on retry. Fix: Send a stable id per event so a retried upload is not counted twice. vendor.amplitude.body.insert_id.empty docs
ip optional It is the user IP, sent unhashed, or `$remote` to use the request address. Fix: Send the raw IP, or `$remote`. vendor.amplitude.body.ip.empty docs
user_agent optional It is the unparsed user agent string from the device, sent unhashed. vendor.amplitude.body.user_agent.empty docs
revenue optional It is the event revenue. Amplitude documents a float and accepts negatives for refunds. Fix: Send a number such as `129.99`, with no currency symbol. vendor.amplitude.body.revenue.empty
vendor.amplitude.body.revenue.invalid
docs
currency optional It is the 3-character uppercase ISO 4217 currency of the purchase. Fix: Use an uppercase code such as `USD`. vendor.amplitude.body.currency.empty
vendor.amplitude.body.currency.invalid
docs
session_id optional It is the session start time in milliseconds since epoch. Amplitude documents `-1` as the same as omitting it. vendor.amplitude.body.session_id.empty
vendor.amplitude.body.session_id.invalid
docs
price optional It is the price of the item purchased. Amplitude documents a float and accepts negatives for refunds. Fix: Send a number such as `4.99`, with no currency symbol. vendor.amplitude.body.price.empty
vendor.amplitude.body.price.invalid
docs
quantity optional It is the quantity of the item purchased. Amplitude documents an integer and defaults to 1 when omitted. Fix: Send a whole number such as `3`. vendor.amplitude.body.quantity.empty
vendor.amplitude.body.quantity.invalid
docs
productId optional It identifies the item purchased. Amplitude documents sending price and quantity, or revenue, with this field. vendor.amplitude.body.productId.empty docs
revenueType optional It is the type of revenue for the item purchased, such as `Refund`. vendor.amplitude.body.revenueType.empty docs
location_lat optional It is the current latitude of the user. Amplitude documents a float. Fix: Send a number such as `37.77`. vendor.amplitude.body.location_lat.empty
vendor.amplitude.body.location_lat.invalid
docs
location_lng optional It is the current longitude of the user. Amplitude documents a float. Fix: Send a number such as `-122.39`. vendor.amplitude.body.location_lng.empty
vendor.amplitude.body.location_lng.invalid
docs
event_id optional It is an incrementing counter Amplitude documents to distinguish events that share a `user_id` and timestamp. Fix: Send a whole number such as `23`. vendor.amplitude.body.event_id.empty
vendor.amplitude.body.event_id.invalid
docs
app_version optional It is the current version of the application. vendor.amplitude.body.app_version.empty docs
platform optional It is the platform of the device, such as `iOS`. vendor.amplitude.body.platform.empty docs
country optional It is the current country of the user. vendor.amplitude.body.country.empty docs
language optional It is the language set by the user. Amplitude stores a language name; a tag such as `en-US` is accepted and rewritten. vendor.amplitude.body.language.empty docs
idfa optional It is the iOS Identifier for Advertiser. Amplitude's HTTP V2 samples send a UUID, and all-zero IDFAs are dropped. Fix: Send `idfa` as a UUID, or omit the field. vendor.amplitude.body.idfa.empty
vendor.amplitude.body.idfa.invalid
docs
idfv optional It is the iOS Identifier for Vendor. Amplitude's HTTP V2 samples send a UUID. Fix: Send `idfv` as a UUID, or omit the field. vendor.amplitude.body.idfv.empty
vendor.amplitude.body.idfv.invalid
docs
adid optional It is the Google Play Services advertising ID. Amplitude's HTTP V2 samples send a UUID. Fix: Send `adid` as a UUID, or omit the field. vendor.amplitude.body.adid.empty
vendor.amplitude.body.adid.invalid
docs
body.event_needs_an_identifier required The event carries neither `user_id` nor `device_id`. Amplitude documents one of the two as required, and rejects the event without them. Fix: Send `user_id` for a known user, or `device_id` for an anonymous one. vendor.amplitude.body.event_needs_an_identifier docs
body.reserved_event_type required `event_type` uses a name Amplitude reserves for internal use, such as `[Amplitude] Start Session`. Fix: Use your own event name. Amplitude reserves names that start with `[Amplitude]`. vendor.amplitude.body.reserved_event_type docs
body.hashed_plaintext_field required This field looks like a SHA-256 digest, but Amplitude documents `ip` and `user_agent` as unhashed. Use `$remote` when the IP should come from the request. Fix: Send the raw IP or user agent, or `$remote` for IP. vendor.amplitude.body.hashed_plaintext_field docs
body.placeholder_identifier required This identifier is on Amplitude's list of values that return 400, such as `anonymous` or an all-zero UUID. Fix: Send a real `user_id` or `device_id` of at least 5 characters. vendor.amplitude.body.placeholder_identifier docs

Validate a payload

pixellint validate json @payload.json --rulepack vendor/amplitude

Try this failing payload in the playground. Amplitude reserved [Amplitude] event name.

{"api_key":"amp-key-abc123","events":[{"user_id":"user-10024","event_type":"[Amplitude] Start Session","time":1770000000000,"insert_id":"evt-9931"}]}

cargo install pixellint · npm install pixellint