pixellint

vendor/segment · vendor documented

A Segment track call needs an event name

A server posts to api.segment.io/v1/batch. The response is 200. Downstream destinations never see the event. The HTTP API is a collector, not a schema checker.

The track spec marks event as required. A group call needs groupId, and an alias call needs previousId. The collector still takes a call that omits them. It does not invent a name. Every call also needs userId or anonymousId. context.ip is an address, not a digest.

track requires an event name

identify, page, screen, group, and alias do not. The rule is scoped to type: track. A mixed batch only flags the track rows.

Rule: vendor.segment.body.track_requires_an_event_name

Every call needs a person

userId for a known user, anonymousId for an unidentified one. A track with properties and no identity is associated with nobody.

Rule: vendor.segment.body.call_needs_an_identifier

group needs a group id

A batched group call without groupId never attaches the user to a company. previousId is the same trap on alias.

Rule: vendor.segment.body.group_requires_group_id

What this pack matches

Hosts
api.segment.io, segmentapis.com
Paths
…/v1/…
Vendor docs
segment.com/docs/connections/sources/catalog/libraries/server/http-api/

Rules

Codes are stable. A finding in CI, MCP, or the playground lands on the same id.

Field Required What it checks Rule ids Source
writeKey optional It identifies the source the data lands in. Segment also accepts it as HTTP basic auth, so it is not required in the body. Fix: Send the source write key in the body or as the basic auth username. vendor.segment.body.writeKey.empty docs
type required Segment documents that each call in a batch must carry a `type` naming a valid method. Fix: Set `type` to one of identify, track, page, screen, group, or alias. vendor.segment.body.type.missing
vendor.segment.body.type.empty
vendor.segment.body.type.invalid
docs
event optional It is the name of the action the user performed, and Segment documents it as required on a track call. Fix: Name the event, such as `Item Purchased`. vendor.segment.body.event.empty docs
groupId optional It identifies the group. Segment documents it as required on a group call. Fix: Set `groupId` to the group in your database. vendor.segment.body.groupId.empty docs
previousId optional It is the previous unique identifier. Segment documents it as required on an alias call. Fix: Set `previousId` to the id being merged. vendor.segment.body.previousId.empty docs
body.track_requires_an_event_name required A `track` call carries no `event`. Segment documents the event name as required, and drops the call without it. Fix: Add the event name to the call. vendor.segment.body.track_requires_an_event_name docs
body.group_requires_group_id required A `group` call carries no `groupId`. Segment documents the group id as required. Fix: Set `groupId` to the group in your database. vendor.segment.body.group_requires_group_id docs
body.alias_requires_previous_id required An `alias` call carries no `previousId`. Segment documents the previous unique identifier as required. Fix: Set `previousId` to the id being merged. vendor.segment.body.alias_requires_previous_id docs
userId optional It is your own identifier for the user. Segment documents that a call needs either this or `anonymousId`. vendor.segment.body.userId.empty docs
anonymousId optional It stands in for a user id when there is none. Segment documents that a call needs either this or `userId`. vendor.segment.body.anonymousId.empty docs
timestamp optional Segment documents the timestamp as an ISO 8601 date string. Leave it out for events happening now. Fix: Send an ISO 8601 timestamp, or omit it and let Segment stamp the call. vendor.segment.body.timestamp.empty
vendor.segment.body.timestamp.invalid
docs
sentAt optional Segment documents `sentAt` as an ISO 8601 date string, the time the client sent the event. Fix: Send an ISO 8601 timestamp, such as `2026-07-26T00:30:12.984Z`. vendor.segment.body.sentAt.empty
vendor.segment.body.sentAt.invalid
docs
messageId optional Segment deduplicates on `messageId` and documents fewer than 100 characters. Fix: Send a unique `messageId` of at most 99 characters. vendor.segment.body.messageId.empty
vendor.segment.body.messageId.invalid
docs
context.ip optional It is the visitor IP, sent unhashed. vendor.segment.body.context.ip.empty docs
context.userAgent optional It is the user agent of the device making the request. Segment documents it as unhashed on `context`. Fix: Send the browser or device user agent string, or drop the empty pair. vendor.segment.body.context.userAgent.empty docs
context.page.url optional It is the current page URL. Segment documents `url` on `context.page`. Fix: Send an absolute URL in `context.page.url`, including the scheme. vendor.segment.body.context.page.url.empty
vendor.segment.body.context.page.url.invalid
docs
properties.currency optional It is the ISO 4217 currency of `properties.revenue`. Segment documents it as a reserved track property. Fix: Send a three-letter code such as `USD`, or omit the field and Segment assumes US dollars. vendor.segment.body.properties.currency.empty
vendor.segment.body.properties.currency.invalid
docs
properties.revenue optional It is the dollar amount an event resulted in. Segment documents a reserved decimal number, such as `19.99`. Fix: Send a number such as `19.99`, with no currency symbol. vendor.segment.body.properties.revenue.empty
vendor.segment.body.properties.revenue.invalid
docs
properties.value optional It is an abstract value for an event that does not generate dollar revenue. Segment documents a reserved number. Fix: Send a number such as `1`, with no unit suffix. vendor.segment.body.properties.value.empty
vendor.segment.body.properties.value.invalid
docs
properties.url optional It is the page's full URL. Segment documents `url` as a reserved page property. Fix: Send an absolute URL in `properties.url`, including the scheme. vendor.segment.body.properties.url.empty
vendor.segment.body.properties.url.invalid
docs
context.locale optional It is the locale of the current user. Segment documents a string such as `en-US`. Fix: Send a locale tag such as `en-US`, or omit the field. vendor.segment.body.context.locale.empty
vendor.segment.body.context.locale.invalid
docs
body.call_needs_an_identifier required The call carries neither `userId` nor `anonymousId`. Segment documents one of the two as required on every call. Fix: Send `userId` for a known user, or `anonymousId` for an unidentified one. vendor.segment.body.call_needs_an_identifier docs
body.hashed_plaintext_field required `context.ip` or `context.userAgent` looks like a SHA-256 digest, but Segment documents both as plaintext. Fix: Send the raw IP address or user agent string. vendor.segment.body.hashed_plaintext_field docs

Validate a payload

pixellint validate json @payload.json --rulepack vendor/segment

Try this failing payload in the playground. Segment group call without groupId.

{"writeKey":"seg-write-key-abc","batch":[{"type":"group","userId":"019mr8mf4r"}]}

cargo install pixellint · npm install pixellint