vendor/meta · vendor documented
Meta Pixel and Facebook CAPI need a Pixel ID
The browser pixel is a GET to facebook.com/tr. Without id, Meta has nothing to attribute. ev is required; an unrecognized value warns because custom events are legal, which is how Purchse (a typo) ships as a custom event. Facebook CAPI is the server pipe on the same Pixel ID.
Advanced Matching hashes em, ph, fn, ln, external_id, ge, db, ct, st, zp, and country as SHA-256 hex. fbc and fbp follow fb.N.timestamp.value. A raw email or country on the query string is a privacy incident and a matching miss.
Facebook CAPI is the server pipe
meta pixel and CAPI share one Pixel ID. The browser hit is facebook.com/tr. Facebook CAPI is the Graph events POST. CAPI implementation uses the same event_id on both pipes.
id is the numeric Pixel ID
It comes from Events Manager. A missing or empty id is an error. The pack does not invent a format beyond numeric.
Unhashed email on the query string
Normalize, SHA-256, send the hex. The same rule exists on the Conversions API pack for the JSON body.
What this pack matches
Rules
Codes are stable. A finding in CI, MCP, or the playground lands on the same id.
| Field | Required | What it checks | Rule ids | Source |
|---|---|---|---|---|
id |
required | It is the numeric Pixel ID from Events Manager. Fix: Set `id` to the numeric Pixel ID shown in Events Manager. | vendor.meta.param.id.missingvendor.meta.param.id.emptyvendor.meta.param.id.invalid |
docs |
ev |
required | Custom event names are allowed, so check that this is a deliberate custom event and not a misspelled standard one. Fix: Use a standard event name, or confirm the custom event is registered in Events Manager. | vendor.meta.param.ev.missingvendor.meta.param.ev.emptyvendor.meta.param.ev.invalid |
docs |
noscript |
optional | The base code sends `noscript=1` from the img fallback. | vendor.meta.param.noscript.emptyvendor.meta.param.noscript.invalid |
docs |
dpo |
optional | Limited Data Use is enabled by sending `dpo=LDU`. | vendor.meta.param.dpo.emptyvendor.meta.param.dpo.invalid |
docs |
dpoco |
optional | It is the country for Limited Data Use: `1` for the United States, `0` to let Meta geolocate. | vendor.meta.param.dpoco.emptyvendor.meta.param.dpoco.invalid |
docs |
dpost |
optional | It is the state code for Limited Data Use, or `0` to let Meta geolocate. | vendor.meta.param.dpost.emptyvendor.meta.param.dpost.invalid |
docs |
cd[value] |
optional | It is the monetary value of the conversion. Meta documents `value` as required for Purchase events. Fix: Send the value as a number, without a currency symbol. | vendor.meta.param.cd[value].emptyvendor.meta.param.cd[value].invalid |
docs |
cd[currency] |
optional | It is the ISO 4217 currency code of the conversion value. Meta documents `currency` as required for Purchase events. Fix: Send the three-letter code, such as `USD`. | vendor.meta.param.cd[currency].emptyvendor.meta.param.cd[currency].invalid |
docs |
cd[content_name] |
optional | It is the page or product name on the image pixel. Meta documents `content_name` as a string. Fix: Send the name in `cd[content_name]`, or drop the empty pair. | vendor.meta.param.cd[content_name].empty |
docs |
cd[content_category] |
optional | It is the page or product category on the image pixel. Meta documents `content_category` as a string. Fix: Send the category in `cd[content_category]`, or drop the empty pair. | vendor.meta.param.cd[content_category].empty |
docs |
cd[content_ids] |
optional | It is a product id on the image pixel. Meta documents `content_ids` and shows `cd[content_ids]` on the img tag. Fix: Send catalog IDs in `cd[content_ids]`, or drop the empty pair. | vendor.meta.param.cd[content_ids].empty |
docs |
cd[content_type] |
optional | It says whether `content_ids` are products or product groups. Meta documents `product` or `product_group`. Fix: Set `cd[content_type]` to `product` or `product_group`. | vendor.meta.param.cd[content_type].emptyvendor.meta.param.cd[content_type].invalid |
docs |
cd[num_items] |
optional | It is the item count on the image pixel. Meta documents `num_items` as an integer for InitiateCheckout. Fix: Send a whole number in `cd[num_items]`, such as `2`. | vendor.meta.param.cd[num_items].emptyvendor.meta.param.cd[num_items].invalid |
docs |
cd[search_string] |
optional | It is the search query on the image pixel. Meta documents `search_string` for Search events. Fix: Send the query in `cd[search_string]`, or drop the empty pair. | vendor.meta.param.cd[search_string].empty |
docs |
cd[predicted_ltv] |
optional | It is predicted lifetime value on the image pixel. Meta documents `predicted_ltv` as a number. Fix: Send `cd[predicted_ltv]` as a number, such as `250.00`. | vendor.meta.param.cd[predicted_ltv].emptyvendor.meta.param.cd[predicted_ltv].invalid |
docs |
eid |
optional | It is the event id on the image pixel. Meta documents `eid` for deduplication against Conversions API `event_id`. Fix: Send the same id the Conversions API fired in `eid`, or drop the empty pair. | vendor.meta.param.eid.empty |
docs |
em |
optional | It is the hashed email for Advanced Matching. Meta requires customer emails to be normalized and SHA-256 hashed. Fix: Trim and lowercase the address, hash it with SHA-256, and send the hex digest in `em`. | vendor.meta.param.em.emptyvendor.meta.param.em.invalid |
docs |
ph |
optional | It is the hashed phone number for Advanced Matching. Fix: Normalize the number, hash it with SHA-256, and send the hex digest in `ph`. | vendor.meta.param.ph.emptyvendor.meta.param.ph.invalid |
docs |
fn |
optional | It is the hashed first name for Advanced Matching. | vendor.meta.param.fn.emptyvendor.meta.param.fn.invalid |
docs |
ln |
optional | It is the hashed last name for Advanced Matching. | vendor.meta.param.ln.emptyvendor.meta.param.ln.invalid |
docs |
ge |
optional | It is the hashed gender for Advanced Matching. Fix: Normalize gender, hash it with SHA-256, and send the hex digest in `ge`. | vendor.meta.param.ge.emptyvendor.meta.param.ge.invalid |
docs |
db |
optional | It is the hashed date of birth for Advanced Matching. Fix: Normalize the date of birth, hash it with SHA-256, and send the hex digest in `db`. | vendor.meta.param.db.emptyvendor.meta.param.db.invalid |
docs |
ct |
optional | It is the hashed city for Advanced Matching. Fix: Lowercase and trim the city, hash it with SHA-256, and send the hex digest in `ct`. | vendor.meta.param.ct.emptyvendor.meta.param.ct.invalid |
docs |
st |
optional | It is the hashed state for Advanced Matching. Fix: Normalize the state, hash it with SHA-256, and send the hex digest in `st`. | vendor.meta.param.st.emptyvendor.meta.param.st.invalid |
docs |
zp |
optional | It is the hashed zip code for Advanced Matching. Fix: Normalize the zip, hash it with SHA-256, and send the hex digest in `zp`. | vendor.meta.param.zp.emptyvendor.meta.param.zp.invalid |
docs |
country |
optional | It is the hashed country for Advanced Matching. Fix: Normalize the two-letter country code, hash it with SHA-256, and send the hex digest in `country`. | vendor.meta.param.country.emptyvendor.meta.param.country.invalid |
docs |
external_id |
optional | It is the hashed advertiser-side user id for Advanced Matching. | vendor.meta.param.external_id.emptyvendor.meta.param.external_id.invalid |
docs |
fbc |
optional | It is the Meta click id cookie, documented as `fb.${subdomain_index}.${creation_time}.${fbclid}`. Fix: Send the `_fbc` cookie verbatim. | vendor.meta.param.fbc.emptyvendor.meta.param.fbc.invalid |
docs |
fbp |
optional | It is the Meta browser id cookie, documented as `fb.${subdomain_index}.${creation_time}.${random_number}`. Fix: Send the `_fbp` cookie verbatim. | vendor.meta.param.fbp.emptyvendor.meta.param.fbp.invalid |
docs |
pii.unhashed_email |
required | A parameter carries what looks like a raw email address. Meta requires customer information to be normalized and SHA-256 hashed before it is sent. Fix: Normalize the value, hash it with SHA-256, and send the hex digest instead of the plain address. | vendor.meta.pii.unhashed_email |
docs |
ldu.country_without_state |
required | Limited Data Use sends a country without a state. Meta requires both together, otherwise it geolocates the user instead of honoring the values you sent. Fix: Send `dpost` alongside `dpoco`, or drop both and let Meta geolocate. | vendor.meta.ldu.country_without_state |
docs |
purchase_requires_value_and_currency |
required | A `Purchase` event is missing its value or currency. Meta documents both as required for Purchase, and without them the conversion reports no revenue. Fix: Pass `value` and `currency` in the event data: fbq('track', 'Purchase', { value: 12.34, currency: 'USD' }). | vendor.meta.purchase_requires_value_and_currency |
docs |
Validate a payload
pixellint validate url "$ARTIFACT" --rulepack vendor/meta
Try this failing payload in the playground. Meta pixel missing Pixel ID, unhashed email.
https://www.facebook.com/tr?ev=Purchse&em=buyer@example.com
cargo install pixellint
·
npm install pixellint