Free tool by MD Niamul

Free Meta CAPI Payload Builder Build, Hash and Check a Meta Conversions API Event Before You Send It

A Meta Conversions API Payload Builder and CAPI Event Tester That Runs in Your Browser

Hashes in your browser, nothing is sent
Build a payload or check your own
JSON, cURL, pixel and dataLayer code

Fill in an event and this free Meta Conversions API payload builder writes the Facebook CAPI payload for you. It normalises and SHA-256 hashes customer details the way Meta’s documentation describes, builds the fbc click ID, and gives you a cURL command, the matching pixel call with the same event ID and a dataLayer starting point. Already have a payload? Paste it and the CAPI event tester checks it against the published rules.

13Standard events ready to build
5Output formats
850+Projects delivered
600+Five-star reviews
MD Niamul, creator of the free meta capi payload builder
upworkTop Rated Plus
Conversions APIFree Payload Builder
OfficialStape Partner

What the Meta CAPI Payload Builder Covers

SHA-256 Hashing
Email Normalisation
Phone Normalisation
event_id Deduplication
event_time Check
action_source Rules
fbc From fbclid
fbp Format
value and currency
content_ids and contents
Limited Data Use
test_event_code
cURL Command
Matching Pixel Call
dataLayer for sGTM
Plain-Text Detection
Identity Coverage
Excel Checklist
FREE META CAPI PAYLOAD BUILDER

Build or Check a Conversions API Payload

Type on the left. The payload, the checks and the code update as you type.

Meta CAPI Payload BuilderBuild · Hash · Validate · cURL · Pixel · dataLayer
Free · No login

Use made-up data here. Everything is worked out in your browser and nothing you type is sent anywhere. Even so, there is no reason to paste real customer details into a web page.

1. Event

2. Customer information user_data · type plain text, the tool normalises and hashes it

3. Event details custom_data

Items (become content_ids and contents)

4. Options

Your payload

Follows Meta’s published parameter rulesNever asks for your access tokenJSON and Excel downloads
WHAT IT DOES

What Does the Meta CAPI Payload Builder Do?

Two modes: build a correct event from scratch, or check one you already send.

Builds the Payload

A complete request body with event_name, event_time, action_source, user_data and custom_data.

Normalises and Hashes

Email, phone, name, city, state, postcode, country, birth date and gender are cleaned, then SHA-256 hashed in your browser.

Builds fbc From fbclid

Turns the click ID from an ad link into the fb.1.timestamp.fbclid format Meta expects.

Checks Required Fields

Each action_source needs different fields. Website events need the page address and the browser user agent.

Checks the Timestamp

Flags times in milliseconds, in the future, or older than Meta accepts.

Checks Value and Items

Value as a number, a valid currency code, and content_ids that agree with contents.

Gives You the Code

cURL, the matching fbq pixel call with the same event ID, and a dataLayer push for a server-side setup.

Tests Your Own Payload

Paste JSON to find plain-text emails, wrong-length hashes, hashed cookies and repeated event IDs.

How Does the CAPI Payload Builder Work?

Three steps. Your data never leaves your browser.

01

Fill in the event

Pick the event, where it happened, and add made-up customer details and order values.

02

Read the checks

Every missing field and formatting mistake is listed with the fix.

03

Copy and test

Take the JSON or cURL, add your own access token on your own machine, and send it with a test event code.

What Is a Meta Conversions API Payload?

The Meta Conversions API (CAPI) lets your server tell Meta about a purchase, a lead or another action directly, instead of relying only on the browser pixel. The message your server sends is called the payload. It is a block of JSON that lists one or more events.

Each event says what happened (event_name), when (event_time), where (action_source), who did it (user_data) and what it was worth (custom_data). If one event in a request is invalid, Meta rejects the whole request, so small mistakes matter.

Which customer details must be hashed?

Meta’s documentation says these must be normalised and then hashed with SHA-256: em, ph, fn, ln, ge, db, ct, st, zp and country. Hashing external_id is recommended.

These must not be hashed: client_ip_address, client_user_agent, fbc, fbp and lead_id. Hashing them is a common mistake, and Meta can no longer use them.

Why does normalising matter?

A hash changes completely if one character changes. [email protected] and [email protected] give two different hashes, and only the lowercase one can match. So the value is cleaned first: emails are trimmed and lowercased, phone numbers keep digits only with the country code, cities lose spaces and punctuation.

How does deduplication work?

Most sites send the same event twice: once from the browser pixel and once from the server. Meta keeps one of them when both carry the same event name and the same ID. The server sends it as event_id and the pixel as eventID. The builder writes both sides with the same ID.

What is identity coverage?

The builder lists which matching keys your event carries, such as hashed email, phone, click ID and browser ID, and gives a rough label: Basic, Good or Strong. This is the tool’s own simple guide. It is not Meta’s Event Match Quality score. Only Events Manager can show that, because it depends on whether Meta can actually match your data to accounts.

What this tool cannot check

It checks the structure of a payload against Meta’s published documentation. It cannot send the event, confirm that Meta accepted it, or show your real match quality. It cannot tell whether a hash was made from a correctly normalised value, because a hash cannot be reversed. Meta also changes its rules and API versions, so use the current version shown in Meta’s developer documentation. Always test with Events Manager > Test events before you go live.

Conversions API Fields at a Glance

From Meta’s developer documentation. Check the current docs before you build.

FieldRuleHashed?
event_nameRequired. A standard event such as Purchase, or your own nameNo
event_timeRequired. Unix time in seconds. Up to 7 days old for most eventsNo
action_sourceRequired. One of 9 values such as website, app or physical_storeNo
event_source_urlRequired for website eventsNo
client_user_agentRequired for website eventsNo
event_idRecommended. Must match the pixel’s eventID to deduplicateNo
em, phLowercase email. Phone as digits with country codeYes, SHA-256
fn, ln, ct, st, zp, country, db, geLowercase, no punctuation. Country as 2 letters, birth date as YYYYMMDDYes, SHA-256
external_idYour own customer IDRecommended
fbc, fbpCookie values. fbc is fb.1.time in milliseconds.fbclidNo, never
client_ip_addressThe visitor’s IPv4 or IPv6 addressNo, never
value, currencyRequired for Purchase. Value as a number, currency as an ISO 4217 codeNo

Who Is This Builder For?

Developers

See the exact JSON before you write the server code.

Tracking specialists

Check a payload from a server container or a plugin in seconds.

Agencies

Hand a client’s developer a correct example with the checklist.

Store owners

Understand what your Conversions API setup should be sending.

MORE FREE TOOLS

More Free Marketing Tools by MD Niamul

33 free tools for tracking, analytics, advertising and SEO. No login needed.

Free Form Tracking Listener Generator

Get GTM listener code for HubSpot, GoHighLevel, iframe and native forms that pushes a clean dataLayer event.

Open the listener generator →

Free UTM & Click ID Redirect Checker

Test whether redirects strip gclid, fbclid and UTM parameters before visitors reach your page.

Open the redirect checker →

Free SHA-256 Hashing Code Generator

Turn your email, phone and address variables into correctly formatted, hashed values for each ad platform.

Open the hashing generator →

Free GTM Container Analyzer

Upload a GTM container export to document every tag, trigger and variable and find unused, duplicate and risky items.

Open the GTM analyzer →

Trusted by 600+ Brands & Agencies

MYLENE
HOVER BOARDS
GT SOLI
CAMBRIDGE
BIENEN CORB 24
ZULU SHACK CREATIVE
ADPSY LLC
HIGH PERFORMANCE MEDIA
ADS PERFORMANCE
LEGESI
TESTIMONIAL

Analytics & Conversion Tracking Client Testimonials

Hear from our clients. Loved by 600+ businesses worldwide.

Madison Jonas, client of MD Niamul
Madison JonasGoogle Ads clientLinkedIn recommendation
★★★★★

“I had an excellent experience working with MD on my Google Ads account. Everything was set up perfectly and worked smoothly without any issues or troubleshooting needed. His expertise and attention to detail made the whole process effortless.”

Mehboob Khan, client of MD Niamul
Mehboob KhanGoogle Analytics projectsLinkedIn recommendation
★★★★★

“I worked with Niamul on multiple Google Analytics projects and was impressed by his expertise and precision. He has a strong grasp of tracking, reporting, and optimization, always ensuring accurate insights. He is proactive, reliable, and easy to collaborate with.”

Jacco Bouw, client of MD Niamul
Jacco BouwShopify, GA4 & Google Ads trackingLinkedIn recommendation
★★★★★

“MD Niamul is extremely skilled. He fixed my Shopify, Google Analytics, and Google Ads conversion tracking perfectly. Everything works exactly as it should now, and he even added an extra data layer, which was very helpful. Outstanding service, fast delivery, and highly recommended.”

Ryan S Kemp, client of MD Niamul
Ryan S KempCMO, Co-Founder, Zulu Shack CreativeLinkedIn recommendation
★★★★★

“Reliable, knowledgeable, and truly trustworthy. I’ve been working with Niamul for over a year, and he consistently delivers exceptional results across all analytics tasks. His expertise, communication, and commitment make him my go-to specialist for tracking, measurement, and data accuracy.”

Casper Klein, client of MD Niamul
Casper KleinMeta Pixel & server-side trackingLinkedIn recommendation
★★★★★

“MD N delivered flawless Meta Pixel, CAPI, and server-side tracking. He understood our goals quickly, explained everything clearly, and ensured full transparency. Communication was smooth, updates were consistent, and the results improved our data accuracy and ad performance.”

600+

Five-star reviews from businesses and agencies in the USA, Canada, UK and Australia.

Read All Reviews

Video Testimonials: Hear It From Our Clients

FAQ

Frequently Asked Questions About the Free Meta CAPI Payload Builder

Is the Meta CAPI payload builder free?

Yes. It runs in your browser with no login and no email form.

Is my data sent anywhere?

No. The hashing and all the checks run in your browser. Nothing you type or paste is uploaded. It is still best to use made-up customer details.

Do I need to enter my access token?

No, and you should not. The tool never asks for it. The cURL command contains the placeholder ACCESS_TOKEN, which you replace on your own machine.

Which fields must be hashed for the Conversions API?

Email, phone, first name, last name, gender, date of birth, city, state, postcode and country must be normalised and SHA-256 hashed. The IP address, user agent, fbc, fbp and lead_id must not be hashed.

How old can a Conversions API event be?

Meta’s documentation says event_time can be up to 7 days before you send the event, with a longer window for physical store events. Sending events close to real time works best.

Which fields are required for a website event?

event_name, event_time, action_source, event_source_url and client_user_agent, plus at least one customer information field.

How do I stop the pixel and the Conversions API counting an event twice?

Send the same event name and the same ID from both. The server field is event_id and the pixel option is eventID. The Pixel tab shows the matching call.

Does this show my Event Match Quality score?

No. Only Meta’s Events Manager can show that. The identity coverage label here is a simple guide to which matching keys your event carries.

Does a clean check mean Meta will accept the event?

It means the payload follows the published structure. Meta can still reject it for reasons the tool cannot see, such as a wrong pixel ID, an expired token or a newer rule. Test it in Events Manager under Test events.

A Correct Payload Is Step One. Sending It Reliably Is the Real Work

I am MD Niamul, a conversion tracking and web analytics specialist and an official Stape partner. I set up the Meta Conversions API through server-side Google Tag Manager and Stape, with deduplication and consent handled properly, then test every event in Events Manager.