pixellint

vendor/meta · vendor documented

Meta Pixel and Facebook CAPI need a Pixel ID

The browser pixel is a GET to facebook.com/tr. Without id, Meta has nothing to attribute. ev is required; an unrecognized value warns because custom events are legal, which is how Purchse (a typo) ships as a custom event. Facebook CAPI is the server pipe on the same Pixel ID.

Advanced Matching hashes em, ph, fn, ln, external_id, ge, db, ct, st, zp, and country as SHA-256 hex. fbc and fbp follow fb.N.timestamp.value. A raw email or country on the query string is a privacy incident and a matching miss.

Facebook CAPI is the server pipe

meta pixel and CAPI share one Pixel ID. The browser hit is facebook.com/tr. Facebook CAPI is the Graph events POST. CAPI implementation uses the same event_id on both pipes.

id is the numeric Pixel ID

It comes from Events Manager. A missing or empty id is an error. The pack does not invent a format beyond numeric.

Rule: vendor.meta.param.id.missing

Unhashed email on the query string

Normalize, SHA-256, send the hex. The same rule exists on the Conversions API pack for the JSON body.

Rule: vendor.meta.pii.unhashed_email

What this pack matches

Hosts
facebook.com
Paths
/tr
Vendor docs
developers.facebook.com/docs/meta-pixel/get-started

Rules

Codes are stable. A finding in CI, MCP, or the playground lands on the same id.

Field Required What it checks Rule ids Source
id required It is the numeric Pixel ID from Events Manager. Fix: Set `id` to the numeric Pixel ID shown in Events Manager. vendor.meta.param.id.missing
vendor.meta.param.id.empty
vendor.meta.param.id.invalid
docs
ev required Custom event names are allowed, so check that this is a deliberate custom event and not a misspelled standard one. Fix: Use a standard event name, or confirm the custom event is registered in Events Manager. vendor.meta.param.ev.missing
vendor.meta.param.ev.empty
vendor.meta.param.ev.invalid
docs
noscript optional The base code sends `noscript=1` from the img fallback. vendor.meta.param.noscript.empty
vendor.meta.param.noscript.invalid
docs
dpo optional Limited Data Use is enabled by sending `dpo=LDU`. vendor.meta.param.dpo.empty
vendor.meta.param.dpo.invalid
docs
dpoco optional It is the country for Limited Data Use: `1` for the United States, `0` to let Meta geolocate. vendor.meta.param.dpoco.empty
vendor.meta.param.dpoco.invalid
docs
dpost optional It is the state code for Limited Data Use, or `0` to let Meta geolocate. vendor.meta.param.dpost.empty
vendor.meta.param.dpost.invalid
docs
cd[value] optional It is the monetary value of the conversion. Meta documents `value` as required for Purchase events. Fix: Send the value as a number, without a currency symbol. vendor.meta.param.cd[value].empty
vendor.meta.param.cd[value].invalid
docs
cd[currency] optional It is the ISO 4217 currency code of the conversion value. Meta documents `currency` as required for Purchase events. Fix: Send the three-letter code, such as `USD`. vendor.meta.param.cd[currency].empty
vendor.meta.param.cd[currency].invalid
docs
cd[content_name] optional It is the page or product name on the image pixel. Meta documents `content_name` as a string. Fix: Send the name in `cd[content_name]`, or drop the empty pair. vendor.meta.param.cd[content_name].empty docs
cd[content_category] optional It is the page or product category on the image pixel. Meta documents `content_category` as a string. Fix: Send the category in `cd[content_category]`, or drop the empty pair. vendor.meta.param.cd[content_category].empty docs
cd[content_ids] optional It is a product id on the image pixel. Meta documents `content_ids` and shows `cd[content_ids]` on the img tag. Fix: Send catalog IDs in `cd[content_ids]`, or drop the empty pair. vendor.meta.param.cd[content_ids].empty docs
cd[content_type] optional It says whether `content_ids` are products or product groups. Meta documents `product` or `product_group`. Fix: Set `cd[content_type]` to `product` or `product_group`. vendor.meta.param.cd[content_type].empty
vendor.meta.param.cd[content_type].invalid
docs
cd[num_items] optional It is the item count on the image pixel. Meta documents `num_items` as an integer for InitiateCheckout. Fix: Send a whole number in `cd[num_items]`, such as `2`. vendor.meta.param.cd[num_items].empty
vendor.meta.param.cd[num_items].invalid
docs
cd[search_string] optional It is the search query on the image pixel. Meta documents `search_string` for Search events. Fix: Send the query in `cd[search_string]`, or drop the empty pair. vendor.meta.param.cd[search_string].empty docs
cd[predicted_ltv] optional It is predicted lifetime value on the image pixel. Meta documents `predicted_ltv` as a number. Fix: Send `cd[predicted_ltv]` as a number, such as `250.00`. vendor.meta.param.cd[predicted_ltv].empty
vendor.meta.param.cd[predicted_ltv].invalid
docs
eid optional It is the event id on the image pixel. Meta documents `eid` for deduplication against Conversions API `event_id`. Fix: Send the same id the Conversions API fired in `eid`, or drop the empty pair. vendor.meta.param.eid.empty docs
em optional It is the hashed email for Advanced Matching. Meta requires customer emails to be normalized and SHA-256 hashed. Fix: Trim and lowercase the address, hash it with SHA-256, and send the hex digest in `em`. vendor.meta.param.em.empty
vendor.meta.param.em.invalid
docs
ph optional It is the hashed phone number for Advanced Matching. Fix: Normalize the number, hash it with SHA-256, and send the hex digest in `ph`. vendor.meta.param.ph.empty
vendor.meta.param.ph.invalid
docs
fn optional It is the hashed first name for Advanced Matching. vendor.meta.param.fn.empty
vendor.meta.param.fn.invalid
docs
ln optional It is the hashed last name for Advanced Matching. vendor.meta.param.ln.empty
vendor.meta.param.ln.invalid
docs
ge optional It is the hashed gender for Advanced Matching. Fix: Normalize gender, hash it with SHA-256, and send the hex digest in `ge`. vendor.meta.param.ge.empty
vendor.meta.param.ge.invalid
docs
db optional It is the hashed date of birth for Advanced Matching. Fix: Normalize the date of birth, hash it with SHA-256, and send the hex digest in `db`. vendor.meta.param.db.empty
vendor.meta.param.db.invalid
docs
ct optional It is the hashed city for Advanced Matching. Fix: Lowercase and trim the city, hash it with SHA-256, and send the hex digest in `ct`. vendor.meta.param.ct.empty
vendor.meta.param.ct.invalid
docs
st optional It is the hashed state for Advanced Matching. Fix: Normalize the state, hash it with SHA-256, and send the hex digest in `st`. vendor.meta.param.st.empty
vendor.meta.param.st.invalid
docs
zp optional It is the hashed zip code for Advanced Matching. Fix: Normalize the zip, hash it with SHA-256, and send the hex digest in `zp`. vendor.meta.param.zp.empty
vendor.meta.param.zp.invalid
docs
country optional It is the hashed country for Advanced Matching. Fix: Normalize the two-letter country code, hash it with SHA-256, and send the hex digest in `country`. vendor.meta.param.country.empty
vendor.meta.param.country.invalid
docs
external_id optional It is the hashed advertiser-side user id for Advanced Matching. vendor.meta.param.external_id.empty
vendor.meta.param.external_id.invalid
docs
fbc optional It is the Meta click id cookie, documented as `fb.${subdomain_index}.${creation_time}.${fbclid}`. Fix: Send the `_fbc` cookie verbatim. vendor.meta.param.fbc.empty
vendor.meta.param.fbc.invalid
docs
fbp optional It is the Meta browser id cookie, documented as `fb.${subdomain_index}.${creation_time}.${random_number}`. Fix: Send the `_fbp` cookie verbatim. vendor.meta.param.fbp.empty
vendor.meta.param.fbp.invalid
docs
pii.unhashed_email required A parameter carries what looks like a raw email address. Meta requires customer information to be normalized and SHA-256 hashed before it is sent. Fix: Normalize the value, hash it with SHA-256, and send the hex digest instead of the plain address. vendor.meta.pii.unhashed_email docs
ldu.country_without_state required Limited Data Use sends a country without a state. Meta requires both together, otherwise it geolocates the user instead of honoring the values you sent. Fix: Send `dpost` alongside `dpoco`, or drop both and let Meta geolocate. vendor.meta.ldu.country_without_state docs
purchase_requires_value_and_currency required A `Purchase` event is missing its value or currency. Meta documents both as required for Purchase, and without them the conversion reports no revenue. Fix: Pass `value` and `currency` in the event data: fbq('track', 'Purchase', { value: 12.34, currency: 'USD' }). vendor.meta.purchase_requires_value_and_currency docs

Validate a payload

pixellint validate url "$ARTIFACT" --rulepack vendor/meta

Try this failing payload in the playground. Meta pixel missing Pixel ID, unhashed email.

https://www.facebook.com/tr?ev=Purchse&em=buyer@example.com

cargo install pixellint · npm install pixellint