pixellint

vendor/mixpanel · vendor documented

Mixpanel's project token rides inside properties

The track endpoint posts a JSON array, not an envelope. There is no top-level api_key. The project token is properties.token on every event. distinct_id and $insert_id are recommended so a retry is not counted twice. time is an integer Unix timestamp. Query ip, verbose, and img are 0 or 1. properties.ip is an address, not a digest. /import is vendor/mixpanel-import. /engage is vendor/mixpanel-engage. /groups is vendor/mixpanel-groups.

token is properties.token

Not the HTTP header, not a root field. Mixpanel documents it inside the event properties object.

Rule: vendor.mixpanel.body.properties.token.empty

What this pack matches

Hosts
mixpanel.com
Paths
…/track…
Vendor docs
docs.mixpanel.com/reference/track-event

Rules

Codes are stable. A finding in CI, MCP, or the playground lands on the same id.

Field Required What it checks Rule ids Source
ip optional Mixpanel documents `ip=1` so the request address is used to compute a `distinct_id` when none is sent. vendor.mixpanel.param.ip.empty
vendor.mixpanel.param.ip.invalid
docs
verbose optional Mixpanel documents `verbose=1` so the 200 body says whether the track call was accepted. vendor.mixpanel.param.verbose.empty
vendor.mixpanel.param.verbose.invalid
docs
img optional Mixpanel documents `img=1` so the response is a 1x1 transparent pixel. vendor.mixpanel.param.img.empty
vendor.mixpanel.param.img.invalid
docs
event required Mixpanel documents the event name as required. Fix: Name the event, such as `Signed Up`. vendor.mixpanel.body.event.missing
vendor.mixpanel.body.event.empty
docs
properties required Mixpanel documents the properties object as required, since the project token rides inside it. Fix: Add a `properties` object carrying at least `token`. vendor.mixpanel.body.properties.missing docs
properties.token required It is the project token the event is attributed to. Fix: Send the project token from your Mixpanel project settings. vendor.mixpanel.body.properties.token.missing
vendor.mixpanel.body.properties.token.empty
docs
properties.distinct_id recommended It identifies the user who performed the event. Mixpanel documents it as the unique user identifier; without it the event is not tied to a person. Fix: Send the same `distinct_id` you use elsewhere for this user. vendor.mixpanel.body.properties.distinct_id.missing
vendor.mixpanel.body.properties.distinct_id.empty
docs
properties.time optional Mixpanel documents `time` as a Unix timestamp in seconds or milliseconds. A non-numeric value is not that format. Fix: Send seconds or milliseconds since epoch, as an integer. vendor.mixpanel.body.properties.time.empty
vendor.mixpanel.body.properties.time.invalid
docs
properties.$insert_id recommended Mixpanel uses it to drop duplicates, so a retried request is not counted twice. `/import` requires it in vendor/mixpanel-import. Fix: Send a stable id per event. vendor.mixpanel.body.properties.$insert_id.missing
vendor.mixpanel.body.properties.$insert_id.empty
docs
properties.ip optional Mixpanel uses `properties.ip` for GeoIP. This is different from the query `ip` flag. Send an address, not a digest. vendor.mixpanel.body.properties.ip.empty docs
properties.$current_url optional It is the URL of the page on which the event was tracked. Mixpanel documents `$current_url` on the JavaScript SDK default-property table. Fix: Send an absolute URL in `properties.$current_url`, including the scheme. vendor.mixpanel.body.properties.$current_url.empty
vendor.mixpanel.body.properties.$current_url.invalid
docs
properties.$referrer optional It is the referring URL, including your own domain. Mixpanel documents `$referrer` on the JavaScript SDK default-property table. `$direct` belongs on `$initial_referrer`, not here. Fix: Send an absolute referring URL, or omit the field when `document.referrer` is empty. vendor.mixpanel.body.properties.$referrer.empty
vendor.mixpanel.body.properties.$referrer.invalid
docs
properties.mp_lib optional It names the Mixpanel library that sent the event, such as `web`, `android`, `swift`, `react-native`, or `flutter`. Mixpanel documents `mp_lib` on the SDK default-property table. Fix: Send `properties.mp_lib`, or drop the empty pair. vendor.mixpanel.body.properties.mp_lib.empty docs
properties.$lib_version optional It is the Mixpanel library version. Mixpanel documents `$lib_version` on the SDK default-property table. Fix: Send `properties.$lib_version`, or drop the empty pair. vendor.mixpanel.body.properties.$lib_version.empty docs
properties.$device_id optional It is the device-local Mixpanel ID. Mixpanel documents `$device_id` as regenerated by `reset()`. Fix: Send `properties.$device_id`, or drop the empty pair. vendor.mixpanel.body.properties.$device_id.empty docs
properties.$user_id optional It is the identified user ID. Mixpanel documents `$user_id` as set by `identify()`. Fix: Send `properties.$user_id` after identify, or drop the empty pair. vendor.mixpanel.body.properties.$user_id.empty docs
properties.$screen_height optional It is the device screen height in pixels, or points on iOS. Mixpanel documents `$screen_height` on the SDK default-property table. Fix: Send `properties.$screen_height` as an integer pixel or point count. vendor.mixpanel.body.properties.$screen_height.empty
vendor.mixpanel.body.properties.$screen_height.invalid
docs
properties.$screen_width optional It is the device screen width in pixels, or points on iOS. Mixpanel documents `$screen_width` on the SDK default-property table. Fix: Send `properties.$screen_width` as an integer pixel or point count. vendor.mixpanel.body.properties.$screen_width.empty
vendor.mixpanel.body.properties.$screen_width.invalid
docs
body.hashed_plaintext_field required `properties.ip` looks like a SHA-256 digest, but Mixpanel documents it as an IP address. Fix: Send the raw IP address. vendor.mixpanel.body.hashed_plaintext_field docs

Validate a payload

pixellint validate json @payload.json --rulepack vendor/mixpanel

Try this failing payload in the playground. Mixpanel track with a hashed properties.ip.

[{"event":"Signed Up","properties":{"token":"mp-token-abc","distinct_id":"user-10024","$insert_id":"evt-9931","time":1770000000,"ip":"a85e9ca18f34935ab9b0381b25bfad2455444112b0149270fd88e3da172fe196"}}]

cargo install pixellint · npm install pixellint