pixellint

vendor/kochava · vendor documented

Kochava S2S events need an app id, device IP, and user agent

JSON to /track/json. kochava_app_id, action, kochava_device_id, and data.event_name are required. origination_ip, device_ua, and device_ver may sit at the root or inside data. An empty device_ver is valid. A hashed IP or user agent is an error.

What this pack matches

Hosts
control.kochava.com
Paths
…/track/json…
Vendor docs
support.kochava.com/articles/server-to-server-integration/185-post-install-event-setup/

Rules

Codes are stable. A finding in CI, MCP, or the playground lands on the same id.

Field Required What it checks Rule ids Source
kochava_app_id required It is the Kochava app GUID, and the S2S event article requires it on every post-install payload. Fix: Set `kochava_app_id` to the app GUID from the Kochava dashboard. vendor.kochava.body.kochava_app_id.missing
vendor.kochava.body.kochava_app_id.empty
docs
action required It names the S2S call. The post-install event article's sample sends `event`. Fix: Set `action` to `event` for a post-install event. vendor.kochava.body.action.missing
vendor.kochava.body.action.empty
vendor.kochava.body.action.invalid
docs
kochava_device_id required The article requires the `kochava_device_id` key on every post-install payload. The value may be empty when `device_ids` carries an ID instead. Fix: Send `kochava_device_id` as a stable per-install string, or send it empty and put an ID in `device_ids`. vendor.kochava.body.kochava_device_id.missing docs
data required Kochava documents a `data` object on every post-install event payload. Fix: Add a `data` object with `event_name`. vendor.kochava.body.data.missing docs
data.event_name required It is the event name. The article places `event_name` inside `data`. Fix: Set `data.event_name` to the event the marketer expects. vendor.kochava.body.data.event_name.missing
vendor.kochava.body.data.event_name.empty
docs
origination_ip optional It is the device IP. Kochava documents `origination_ip` as required; the field table puts it at the root and the samples put it inside `data`. Fix: Send the device IP as `origination_ip` or `data.origination_ip`. vendor.kochava.body.origination_ip.empty docs
data.origination_ip optional It is the device IP inside `data`, which is where Kochava's JSON samples put `origination_ip`. Fix: Send the device IP as `data.origination_ip` or `origination_ip`. vendor.kochava.body.data.origination_ip.empty docs
device_ua optional It is the device user agent. Kochava documents `device_ua` as required so it can parse the OS version. Fix: Send the client user agent as `device_ua` or `data.device_ua`. vendor.kochava.body.device_ua.empty docs
data.device_ua optional It is the device user agent inside `data`, which is where Kochava's JSON samples put `device_ua`. Fix: Send the client user agent as `data.device_ua` or `device_ua`. vendor.kochava.body.data.device_ua.empty docs
device_ver optional It is the device version string. Kochava documents the key as required and allows an empty value when `device_ua` is sent instead. Fix: Send `device_ver` or `data.device_ver`. An empty string is valid. docs
data.device_ver optional It is the device version string inside `data`. Kochava's samples send `device_ver` as an empty string. Fix: Send `data.device_ver` or `device_ver`. An empty string is valid. docs
currency optional It is an ISO 4217 currency code on revenue events. Kochava's samples send `USD`. Fix: Send a three-letter code such as `USD`. vendor.kochava.body.currency.empty
vendor.kochava.body.currency.invalid
docs
data.currency optional It is an ISO 4217 currency code inside `data`. Kochava's samples send `USD`. Fix: Send a three-letter code such as `USD`. vendor.kochava.body.data.currency.empty
vendor.kochava.body.data.currency.invalid
docs
usertime optional It is the time the user completed the event, as Unix seconds. Fix: Send `usertime` as seconds since epoch. vendor.kochava.body.usertime.empty
vendor.kochava.body.usertime.invalid
docs
data.usertime optional It is the time the user completed the event, as Unix seconds inside `data`. Fix: Send `data.usertime` as seconds since epoch. vendor.kochava.body.data.usertime.empty
vendor.kochava.body.data.usertime.invalid
docs
data.app_version optional It is the app version string. Kochava documents `app_version` as optional. Fix: Send `data.app_version` as a version string such as `1.0.0`, or drop the pair. vendor.kochava.body.data.app_version.empty docs
data.device_ids.idfa optional It is the iOS advertising ID inside `device_ids`. Kochava requires at least one identifier in that object. Fix: Send `data.device_ids.idfa`, or another documented identifier such as `adid` or `android_id`. vendor.kochava.body.data.device_ids.idfa.empty docs
data.device_ids.idfv optional It is the iOS vendor ID inside `device_ids`. Kochava allows more than one identifier. Fix: Send `data.device_ids.idfv` when it is available. vendor.kochava.body.data.device_ids.idfv.empty docs
data.device_ids.adid optional It is the Android advertising ID inside `device_ids`. Kochava requires at least one identifier in that object. Fix: Send `data.device_ids.adid`, or another documented identifier such as `idfa` or `android_id`. vendor.kochava.body.data.device_ids.adid.empty docs
data.device_ids.android_id optional It is the Android ID inside `device_ids`. Kochava requires at least one identifier in that object. Fix: Send `data.device_ids.android_id`, or another documented identifier such as `idfa` or `adid`. vendor.kochava.body.data.device_ids.android_id.empty docs
device_ids.idfa optional It is the iOS advertising ID when `device_ids` sits at the root. Kochava's table lists the object alongside other required keys. Fix: Send `device_ids.idfa`, or put the object inside `data`. vendor.kochava.body.device_ids.idfa.empty docs
device_ids.idfv optional It is the iOS vendor ID when `device_ids` sits at the root. Fix: Send `device_ids.idfv` when it is available. vendor.kochava.body.device_ids.idfv.empty docs
device_ids.adid optional It is the Android advertising ID when `device_ids` sits at the root. Fix: Send `device_ids.adid`, or put the object inside `data`. vendor.kochava.body.device_ids.adid.empty docs
device_ids.android_id optional It is the Android ID when `device_ids` sits at the root. Fix: Send `device_ids.android_id`, or put the object inside `data`. vendor.kochava.body.device_ids.android_id.empty docs
data.event_data.id optional It is the item id inside `event_data`. Kochava's post-install sample sends it. Fix: Send `data.event_data.id`, or drop the empty pair. vendor.kochava.body.data.event_data.id.empty docs
data.event_data.name optional It is the item name inside `event_data`. Kochava's post-install sample sends it. Fix: Send `data.event_data.name`, or drop the empty pair. vendor.kochava.body.data.event_data.name.empty docs
data.event_data.sum optional It is the monetary value inside `event_data`. Kochava's post-install sample sends a number such as `150`. Fix: Send `data.event_data.sum` as a number, with no currency symbol. vendor.kochava.body.data.event_data.sum.empty
vendor.kochava.body.data.event_data.sum.invalid
docs
data.att optional It is the iOS App Tracking Transparency result. Kochava documents `true` when tracking is authorized and `false` when it is not, on iOS 14+ events. Fix: Send `data.att` as `true` or `false`. vendor.kochava.body.data.att.empty
vendor.kochava.body.data.att.invalid
docs
data.att_detail optional It is the ATTrackingManager.AuthorizationStatus. Kochava documents `authorized`, `denied`, `notDetermined`, and `restricted`. Fix: Send `authorized`, `denied`, `notDetermined`, or `restricted`. vendor.kochava.body.data.att_detail.empty
vendor.kochava.body.data.att_detail.invalid
docs
data.app_tracking_transparency.att optional It is the ATT result inside Kochava's iOS 14+ `app_tracking_transparency` object. Fix: Send `data.app_tracking_transparency.att` as `true` or `false`. vendor.kochava.body.data.app_tracking_transparency.att.empty
vendor.kochava.body.data.app_tracking_transparency.att.invalid
docs
data.app_tracking_transparency.att_detail optional It is the ATTrackingManager.AuthorizationStatus inside `app_tracking_transparency`. Fix: Send `authorized`, `denied`, `notDetermined`, or `restricted`. vendor.kochava.body.data.app_tracking_transparency.att_detail.empty
vendor.kochava.body.data.app_tracking_transparency.att_detail.invalid
docs
data.app_tracking_transparency.att_time optional It is the ATT authorization time. Kochava documents `att_time` as optional on iOS 14+ events. Fix: Send `att_time` as Unix seconds. vendor.kochava.body.data.app_tracking_transparency.att_time.empty
vendor.kochava.body.data.app_tracking_transparency.att_time.invalid
docs
data.app_tracking_transparency.att_duration optional It is how long the user took to answer the ATT prompt, in seconds. Fix: Send `att_duration` as an integer number of seconds. vendor.kochava.body.data.app_tracking_transparency.att_duration.empty
vendor.kochava.body.data.app_tracking_transparency.att_duration.invalid
docs
body.origination_ip_required required The payload has no device IP. Kochava documents `origination_ip` as required on every post-install event. Fix: Send `origination_ip` at the root or inside `data`. vendor.kochava.body.origination_ip_required docs
body.device_ua_required required The payload has no device user agent. Kochava documents `device_ua` as required so it can parse the OS version. Fix: Send `device_ua` at the root or inside `data`. vendor.kochava.body.device_ua_required docs
body.device_ver_required required The payload has no `device_ver` key. Kochava documents the key as required and allows an empty value. Fix: Send `device_ver` at the root or inside `data`. An empty string is valid. vendor.kochava.body.device_ver_required docs
body.device_ids_required required The payload has no identifier in `device_ids`. Kochava requires at least one of IDFA, IDFV, ADID, or Android ID. Fix: Send `data.device_ids` with `idfa`, `idfv`, `adid`, or `android_id`. vendor.kochava.body.device_ids_required docs
body.hashed_plaintext_field required This field looks like a SHA-256 digest, but Kochava documents `origination_ip` and `device_ua` as unhashed device values. Fix: Send the raw IP address or user agent. Hashing it makes the event unmatchable. vendor.kochava.body.hashed_plaintext_field docs

Validate a payload

pixellint validate json @payload.json --rulepack vendor/kochava

Try this failing payload in the playground. Kochava event without a device IP.

{"action":"event","kochava_app_id":"kokochava-example","kochava_device_id":"kodevice-example","data":{"event_name":"Purchase","device_ua":"Mozilla/5.0","device_ver":""}}

cargo install pixellint · npm install pixellint