pixellint

TripleLift user sync validates the published endpoint alternatives.

The xuid, getuid and sync routes have distinct published query contracts. The pack checks positive member IDs, redirect URLs and supported privacy signals.

Partner dongles, redirect allowlists, browser cookies and geographic applicability require external context. Optional consent syntax checks do not establish permission to sync.

Apply the contracts within their published source scope.

Partner dongles, redirect allowlists, browser cookies and geographic applicability require external context. Optional consent syntax checks do not establish permission to sync.

What this pack matches

Hosts
eb2.3lift.com
Paths
/xuid, /getuid, /sync
Vendor docs
docs.triplelift.com/docs/user-sync

Rules

Codes are stable. A finding in CI, MCP, or the playground lands on the same id.

Field Required What it checks Rule ids Source
route optional Published sync endpoint path. docs
mid optional TripleLift explicitly requires the buyer member ID to be a positive integer. It is assigned by TripleLift, with no locally testable registry. vendor.triplelift-sync.param.mid.empty
vendor.triplelift-sync.param.mid.invalid
docs
xuid optional The /xuid endpoint stores this opaque buyer identifier. vendor.triplelift-sync.param.xuid.empty docs
dongle optional TripleLift provides this opaque partner mapping code. Its account association requires external configuration. vendor.triplelift-sync.param.dongle.empty docs
redir optional The documented redirect destination is an encoded absolute URL. $UID is substituted by TripleLift. The decoded URL is checked here; raw query encoding and the allowlist are separate limitations. vendor.triplelift-sync.param.redir.empty
vendor.triplelift-sync.param.redir.invalid
docs
gdpr optional GDPR territory is signaled as 1; the published quick-check example also uses 0. vendor.triplelift-sync.param.gdpr.empty
vendor.triplelift-sync.param.gdpr.invalid
docs
gdpr_consent optional An IAB TCF consent string is accepted under gdpr_consent or cmp_cs. Consent fields are optional, but absent or invalid consent prevents GDPR sync. vendor.triplelift-sync.param.gdpr_consent.empty
vendor.triplelift-sync.param.gdpr_consent.invalid
docs
us_privacy optional Optional CCPA signal uses the IAB US Privacy string. vendor.triplelift-sync.param.us_privacy.empty
vendor.triplelift-sync.param.us_privacy.invalid
docs
gpp optional Optional GPP encoded consent string. vendor.triplelift-sync.param.gpp.empty
vendor.triplelift-sync.param.gpp.invalid
docs
gpp_sid optional The IAB URL macro specification defines one applicable section ID or at most two comma-separated IDs. This limit applies to URL macros, not the unrestricted JS API array. Evidence: formal standard. vendor.triplelift-sync.param.gpp_sid.empty
vendor.triplelift-sync.param.gpp_sid.invalid
docs
mapping_fields_missing recommended A documented /xuid mapping call supplies mid, xuid and the partner dongle. The documentation does not publish a rejection schema for absence. vendor.triplelift-sync.mapping_fields_missing docs
redirect_missing recommended The documented getuid and sync flows supply an encoded redir destination. vendor.triplelift-sync.redirect_missing docs
gdpr_sync_without_consent recommended TripleLift will not perform a GDPR sync without a valid consent string. Consent parameters themselves are explicitly optional. vendor.triplelift-sync.gdpr_sync_without_consent docs
gpp_without_sections recommended GPP sync signals are documented as an encoded string and applicable section IDs. vendor.triplelift-sync.gpp_without_sections docs
sections_without_gpp recommended Applicable GPP IDs need the corresponding encoded consent string. vendor.triplelift-sync.sections_without_gpp docs
gpp_sections_missing_from_header required Applicable GPP section IDs must identify sections in the encoded consent header. vendor.triplelift-sync.gpp_sections_missing_from_header docs
method optional The documented browser redirect flow uses HTTPS GET. Complete HTTP capture contract. Native JSON type: string. vendor.triplelift-sync.http.method.empty
vendor.triplelift-sync.http.method.invalid
docs

Validate a payload

pixellint validate url "$ARTIFACT" --rulepack vendor/triplelift-sync

Or paste it into the playground. Same engine, in the browser, nothing sent anywhere.

cargo install pixellint · npm install pixellint