pixellint

vendor/appsflyer · vendor documented

AppsFlyer S2S in-app events

Posted to api3.appsflyer.com/inappevent. The JSON body is the contract. eventValue is required even when it is empty. att is 0 through 3. advertising_id and idfa are UUIDs. OneLink impression URLs on impressions.onelink.me are vendor/appsflyer-onelink-impression.

What this pack matches

Hosts
api3.appsflyer.com
Paths
…/inappevent/…
Vendor docs
dev.appsflyer.com/hc/reference/s2s-events-api3-overview

Rules

Codes are stable. A finding in CI, MCP, or the playground lands on the same id.

Field Required What it checks Rule ids Source
app_id required It is the app identifier from the AppsFlyer dashboard, and it travels in the path. iOS apps must be prefixed with `id`. Fix: Put the dashboard app ID in the path after `/inappevent/`. Prefix iOS IDs with `id`. vendor.appsflyer.param.app_id.missing
vendor.appsflyer.param.app_id.empty
docs
ios_app_id_unprefixed recommended This app ID is digits only. AppsFlyer documents that iOS IDs must be prefixed with `id`; without it the call still returns 200 and the event is not recorded. Fix: Prefix the iOS app ID with `id`, such as `id123456789`. vendor.appsflyer.ios_app_id_unprefixed docs
appsflyer_id required It is the AppsFlyer device identifier generated on first launch, and the endpoint requires it. Fix: Send the `appsflyer_id` the SDK generated for this install. vendor.appsflyer.body.appsflyer_id.missing
vendor.appsflyer.body.appsflyer_id.empty
docs
eventName required It is the in-app event name, and the endpoint requires it. Fix: Set `eventName` to the event the marketer expects, such as `af_purchase`. vendor.appsflyer.body.eventName.missing
vendor.appsflyer.body.eventName.empty
docs
eventValue required AppsFlyer documents `eventValue` as required. Send an empty string when the event has no value. Fix: Send a JSON object string, or `""` when there is no value. vendor.appsflyer.body.eventValue.missing docs
att optional It is the iOS ATTrackingManager status. AppsFlyer documents 0 not determined, 1 restricted, 2 denied, 3 authorized. Fix: Send `0`, `1`, `2`, or `3`. vendor.appsflyer.body.att.empty
vendor.appsflyer.body.att.invalid
docs
advertising_id optional It is the Android GAID. AppsFlyer documents a UUID. Fix: Send the GAID as a UUID. vendor.appsflyer.body.advertising_id.empty
vendor.appsflyer.body.advertising_id.invalid
docs
idfa optional It is the iOS IDFA. AppsFlyer documents a UUID. Fix: Send the IDFA as a UUID. vendor.appsflyer.body.idfa.empty
vendor.appsflyer.body.idfa.invalid
docs
idfv optional It is the iOS IDFV. AppsFlyer documents a UUID. Fix: Send the IDFV as a UUID. vendor.appsflyer.body.idfv.empty
vendor.appsflyer.body.idfv.invalid
docs
oaid optional It is the Android OAID, used when GAID is not available. AppsFlyer's sample is a UUID. Fix: Send the OAID as a UUID. vendor.appsflyer.body.oaid.empty
vendor.appsflyer.body.oaid.invalid
docs
customer_user_id optional It is the advertiser's user id. AppsFlyer documents `customer_user_id` as a unique user identifier set by the app owner. Fix: Send `customer_user_id`, or drop the empty pair. vendor.appsflyer.body.customer_user_id.empty docs
fb_login_id optional It is the Facebook Login ID. AppsFlyer documents a numeric string. Fix: Send `fb_login_id` as digits only, such as `10293847561029384`. vendor.appsflyer.body.fb_login_id.empty
vendor.appsflyer.body.fb_login_id.invalid
docs
bundleIdentifier optional It is the app bundle id. AppsFlyer documents it as best practice for campaign optimization. Fix: Send the bundle id, such as `com.example.myapp`, or drop the empty pair. vendor.appsflyer.body.bundleIdentifier.empty docs
app_version_name optional It is the public app version name. AppsFlyer documents `app_version_name` on both Android and iOS payloads. Fix: Send `app_version_name`, or drop the empty pair. vendor.appsflyer.body.app_version_name.empty docs
consent_data.manual.gdpr_applies optional It is whether GDPR applies. AppsFlyer documents a boolean on the manual consent object. Fix: Send `true` or `false` in `consent_data.manual.gdpr_applies`. vendor.appsflyer.body.consent_data.manual.gdpr_applies.empty
vendor.appsflyer.body.consent_data.manual.gdpr_applies.invalid
docs
consent_data.manual.ad_user_data_enabled optional It is the ad-user-data consent flag. AppsFlyer documents a boolean on the manual consent object. Fix: Send `true` or `false` in `consent_data.manual.ad_user_data_enabled`. vendor.appsflyer.body.consent_data.manual.ad_user_data_enabled.empty
vendor.appsflyer.body.consent_data.manual.ad_user_data_enabled.invalid
docs
consent_data.manual.ad_personalization_enabled optional It is the ad-personalization consent flag. AppsFlyer documents a boolean on the manual consent object. Fix: Send `true` or `false` in `consent_data.manual.ad_personalization_enabled`. vendor.appsflyer.body.consent_data.manual.ad_personalization_enabled.empty
vendor.appsflyer.body.consent_data.manual.ad_personalization_enabled.invalid
docs
aie optional AppsFlyer documents `aie` as a boolean. `true` means the user agreed to share the advertiser ID. vendor.appsflyer.body.aie.empty
vendor.appsflyer.body.aie.invalid
docs
app_type optional AppsFlyer documents `app_clip` when the event happened in an app clip. Omit the field otherwise. vendor.appsflyer.body.app_type.empty
vendor.appsflyer.body.app_type.invalid
docs
os optional It is the device OS version. AppsFlyer documents it as required for correct processing, and assumes iOS 14.5 when it is omitted on iOS. vendor.appsflyer.body.os.empty docs
eventTime optional AppsFlyer documents UTC as `yyyy-mm-dd hh:mm:ss.sss`. An epoch number is stamped as the arrival time instead. Fix: Send UTC as `2019-05-15 12:17:01.123`, with a space, not `T`. vendor.appsflyer.body.eventTime.empty
vendor.appsflyer.body.eventTime.invalid
docs
eventCurrency optional It is an ISO 4217 currency code. Fix: Use the three-letter code, such as `USD`. vendor.appsflyer.body.eventCurrency.empty
vendor.appsflyer.body.eventCurrency.invalid
docs
email_hashed optional Email must be trimmed, lowercased, and SHA-256 hashed before it is sent. Fix: Trim and lowercase the address, hash it with SHA-256, and send the hex digest. vendor.appsflyer.body.email_hashed.empty
vendor.appsflyer.body.email_hashed.invalid
docs
phone_number_hashed optional Phone must be normalized and SHA-256 hashed before it is sent. Fix: Strip symbols and leading zeros, keep the country code, hash with SHA-256, and send the hex digest. vendor.appsflyer.body.phone_number_hashed.empty
vendor.appsflyer.body.phone_number_hashed.invalid
docs
phone_number_e164_hashed optional An E.164 phone number must be SHA-256 hashed before it is sent. Fix: Normalize to E.164, hash with SHA-256, and send the hex digest. vendor.appsflyer.body.phone_number_e164_hashed.empty
vendor.appsflyer.body.phone_number_e164_hashed.invalid
docs
first_name_hashed optional First name must be lowercased and SHA-256 hashed before it is sent. Fix: Lowercase the name, hash it with SHA-256, and send the hex digest. vendor.appsflyer.body.first_name_hashed.empty
vendor.appsflyer.body.first_name_hashed.invalid
docs
last_name_hashed optional Last name must be lowercased and SHA-256 hashed before it is sent. Fix: Lowercase the name, hash it with SHA-256, and send the hex digest. vendor.appsflyer.body.last_name_hashed.empty
vendor.appsflyer.body.last_name_hashed.invalid
docs
ip optional It is the device IP address during the event, sent unhashed. Fix: Send the device IP, not a SHA-256 digest. vendor.appsflyer.body.ip.empty docs
body.unhashed_email required A field carries what looks like a raw email address. AppsFlyer documents email as `email_hashed`, SHA-256 hashed on the client side. Fix: Trim the address, lowercase it, hash it with SHA-256, and send it as `email_hashed`. vendor.appsflyer.body.unhashed_email docs
body.hashed_plaintext_field required `ip` looks like a SHA-256 digest, but AppsFlyer documents it as the device IP address, unhashed. Fix: Send the raw IP address. Hashing it makes geo matching fail. vendor.appsflyer.body.hashed_plaintext_field docs

Validate a payload

pixellint validate json @payload.json --rulepack vendor/appsflyer

Try this failing payload in the playground. AppsFlyer event without eventValue.

{"appsflyer_id":"1234567890123-1234567","eventName":"af_purchase","eventTime":"2019-05-15 12:17:01.123"}

cargo install pixellint · npm install pixellint