TripleLift user sync validates the published endpoint alternatives.
The xuid, getuid and sync routes have distinct published query contracts. The pack checks positive member IDs, redirect URLs and supported privacy signals.
Partner dongles, redirect allowlists, browser cookies and geographic applicability require external context. Optional consent syntax checks do not establish permission to sync.
Apply the contracts within their published source scope.
Partner dongles, redirect allowlists, browser cookies and geographic applicability require external context. Optional consent syntax checks do not establish permission to sync.
What this pack matches
Rules
Codes are stable. A finding in CI, MCP, or the playground lands on the same id.
| Field | Required | What it checks | Rule ids | Source |
|---|---|---|---|---|
route |
optional | Published sync endpoint path. | docs | |
mid |
optional | TripleLift explicitly requires the buyer member ID to be a positive integer. It is assigned by TripleLift, with no locally testable registry. | vendor.triplelift-sync.param.mid.emptyvendor.triplelift-sync.param.mid.invalid |
docs |
xuid |
optional | The /xuid endpoint stores this opaque buyer identifier. | vendor.triplelift-sync.param.xuid.empty |
docs |
dongle |
optional | TripleLift provides this opaque partner mapping code. Its account association requires external configuration. | vendor.triplelift-sync.param.dongle.empty |
docs |
redir |
optional | The documented redirect destination is an encoded absolute URL. $UID is substituted by TripleLift. The decoded URL is checked here; raw query encoding and the allowlist are separate limitations. | vendor.triplelift-sync.param.redir.emptyvendor.triplelift-sync.param.redir.invalid |
docs |
gdpr |
optional | GDPR territory is signaled as 1; the published quick-check example also uses 0. | vendor.triplelift-sync.param.gdpr.emptyvendor.triplelift-sync.param.gdpr.invalid |
docs |
gdpr_consent |
optional | An IAB TCF consent string is accepted under gdpr_consent or cmp_cs. Consent fields are optional, but absent or invalid consent prevents GDPR sync. | vendor.triplelift-sync.param.gdpr_consent.emptyvendor.triplelift-sync.param.gdpr_consent.invalid |
docs |
us_privacy |
optional | Optional CCPA signal uses the IAB US Privacy string. | vendor.triplelift-sync.param.us_privacy.emptyvendor.triplelift-sync.param.us_privacy.invalid |
docs |
gpp |
optional | Optional GPP encoded consent string. | vendor.triplelift-sync.param.gpp.emptyvendor.triplelift-sync.param.gpp.invalid |
docs |
gpp_sid |
optional | The IAB URL macro specification defines one applicable section ID or at most two comma-separated IDs. This limit applies to URL macros, not the unrestricted JS API array. Evidence: formal standard. | vendor.triplelift-sync.param.gpp_sid.emptyvendor.triplelift-sync.param.gpp_sid.invalid |
docs |
mapping_fields_missing |
recommended | A documented /xuid mapping call supplies mid, xuid and the partner dongle. The documentation does not publish a rejection schema for absence. | vendor.triplelift-sync.mapping_fields_missing |
docs |
redirect_missing |
recommended | The documented getuid and sync flows supply an encoded redir destination. | vendor.triplelift-sync.redirect_missing |
docs |
gdpr_sync_without_consent |
recommended | TripleLift will not perform a GDPR sync without a valid consent string. Consent parameters themselves are explicitly optional. | vendor.triplelift-sync.gdpr_sync_without_consent |
docs |
gpp_without_sections |
recommended | GPP sync signals are documented as an encoded string and applicable section IDs. | vendor.triplelift-sync.gpp_without_sections |
docs |
sections_without_gpp |
recommended | Applicable GPP IDs need the corresponding encoded consent string. | vendor.triplelift-sync.sections_without_gpp |
docs |
gpp_sections_missing_from_header |
required | Applicable GPP section IDs must identify sections in the encoded consent header. | vendor.triplelift-sync.gpp_sections_missing_from_header |
docs |
method |
optional | The documented browser redirect flow uses HTTPS GET. Complete HTTP capture contract. Native JSON type: string. | vendor.triplelift-sync.http.method.emptyvendor.triplelift-sync.http.method.invalid |
docs |
Validate a payload
pixellint validate url "$ARTIFACT" --rulepack vendor/triplelift-sync
Or paste it into the playground. Same engine, in the browser, nothing sent anywhere.
cargo install pixellint
·
npm install pixellint