A Meta Conversions API Payload Builder and CAPI Event Tester That Runs in Your Browser
Fill in an event and this free Meta Conversions API payload builder writes the Facebook CAPI payload for you. It normalises and SHA-256 hashes customer details the way Meta’s documentation describes, builds the fbc click ID, and gives you a cURL command, the matching pixel call with the same event ID and a dataLayer starting point. Already have a payload? Paste it and the CAPI event tester checks it against the published rules.
Type on the left. The payload, the checks and the code update as you type.
Use made-up data here. Everything is worked out in your browser and nothing you type is sent anywhere. Even so, there is no reason to paste real customer details into a web page.
Items (become content_ids and contents)
Paste the whole request body, just the data array, or one event. It is read in your browser and is not sent anywhere. Remove your access token before you paste.
Two modes: build a correct event from scratch, or check one you already send.
A complete request body with event_name, event_time, action_source, user_data and custom_data.
Email, phone, name, city, state, postcode, country, birth date and gender are cleaned, then SHA-256 hashed in your browser.
Turns the click ID from an ad link into the fb.1.timestamp.fbclid format Meta expects.
Each action_source needs different fields. Website events need the page address and the browser user agent.
Flags times in milliseconds, in the future, or older than Meta accepts.
Value as a number, a valid currency code, and content_ids that agree with contents.
cURL, the matching fbq pixel call with the same event ID, and a dataLayer push for a server-side setup.
Paste JSON to find plain-text emails, wrong-length hashes, hashed cookies and repeated event IDs.
Three steps. Your data never leaves your browser.
Pick the event, where it happened, and add made-up customer details and order values.
Every missing field and formatting mistake is listed with the fix.
Take the JSON or cURL, add your own access token on your own machine, and send it with a test event code.
The Meta Conversions API (CAPI) lets your server tell Meta about a purchase, a lead or another action directly, instead of relying only on the browser pixel. The message your server sends is called the payload. It is a block of JSON that lists one or more events.
Each event says what happened (event_name), when (event_time), where (action_source), who did it (user_data) and what it was worth (custom_data). If one event in a request is invalid, Meta rejects the whole request, so small mistakes matter.
Meta’s documentation says these must be normalised and then hashed with SHA-256: em, ph, fn, ln, ge, db, ct, st, zp and country. Hashing external_id is recommended.
These must not be hashed: client_ip_address, client_user_agent, fbc, fbp and lead_id. Hashing them is a common mistake, and Meta can no longer use them.
A hash changes completely if one character changes. [email protected] and [email protected] give two different hashes, and only the lowercase one can match. So the value is cleaned first: emails are trimmed and lowercased, phone numbers keep digits only with the country code, cities lose spaces and punctuation.
Most sites send the same event twice: once from the browser pixel and once from the server. Meta keeps one of them when both carry the same event name and the same ID. The server sends it as event_id and the pixel as eventID. The builder writes both sides with the same ID.
The builder lists which matching keys your event carries, such as hashed email, phone, click ID and browser ID, and gives a rough label: Basic, Good or Strong. This is the tool’s own simple guide. It is not Meta’s Event Match Quality score. Only Events Manager can show that, because it depends on whether Meta can actually match your data to accounts.
It checks the structure of a payload against Meta’s published documentation. It cannot send the event, confirm that Meta accepted it, or show your real match quality. It cannot tell whether a hash was made from a correctly normalised value, because a hash cannot be reversed. Meta also changes its rules and API versions, so use the current version shown in Meta’s developer documentation. Always test with Events Manager > Test events before you go live.
From Meta’s developer documentation. Check the current docs before you build.
| Field | Rule | Hashed? |
|---|---|---|
| event_name | Required. A standard event such as Purchase, or your own name | No |
| event_time | Required. Unix time in seconds. Up to 7 days old for most events | No |
| action_source | Required. One of 9 values such as website, app or physical_store | No |
| event_source_url | Required for website events | No |
| client_user_agent | Required for website events | No |
| event_id | Recommended. Must match the pixel’s eventID to deduplicate | No |
| em, ph | Lowercase email. Phone as digits with country code | Yes, SHA-256 |
| fn, ln, ct, st, zp, country, db, ge | Lowercase, no punctuation. Country as 2 letters, birth date as YYYYMMDD | Yes, SHA-256 |
| external_id | Your own customer ID | Recommended |
| fbc, fbp | Cookie values. fbc is fb.1.time in milliseconds.fbclid | No, never |
| client_ip_address | The visitor’s IPv4 or IPv6 address | No, never |
| value, currency | Required for Purchase. Value as a number, currency as an ISO 4217 code | No |
See the exact JSON before you write the server code.
Check a payload from a server container or a plugin in seconds.
Hand a client’s developer a correct example with the checklist.
Understand what your Conversions API setup should be sending.
33 free tools for tracking, analytics, advertising and SEO. No login needed.
Get GTM listener code for HubSpot, GoHighLevel, iframe and native forms that pushes a clean dataLayer event.
Open the listener generator →Test whether redirects strip gclid, fbclid and UTM parameters before visitors reach your page.
Open the redirect checker →Turn your email, phone and address variables into correctly formatted, hashed values for each ad platform.
Open the hashing generator →Upload a GTM container export to document every tag, trigger and variable and find unused, duplicate and risky items.
Open the GTM analyzer →Hear from our clients. Loved by 600+ businesses worldwide.
“I had an excellent experience working with MD on my Google Ads account. Everything was set up perfectly and worked smoothly without any issues or troubleshooting needed. His expertise and attention to detail made the whole process effortless.”
“I worked with Niamul on multiple Google Analytics projects and was impressed by his expertise and precision. He has a strong grasp of tracking, reporting, and optimization, always ensuring accurate insights. He is proactive, reliable, and easy to collaborate with.”
“MD Niamul is extremely skilled. He fixed my Shopify, Google Analytics, and Google Ads conversion tracking perfectly. Everything works exactly as it should now, and he even added an extra data layer, which was very helpful. Outstanding service, fast delivery, and highly recommended.”
“Reliable, knowledgeable, and truly trustworthy. I’ve been working with Niamul for over a year, and he consistently delivers exceptional results across all analytics tasks. His expertise, communication, and commitment make him my go-to specialist for tracking, measurement, and data accuracy.”
“MD N delivered flawless Meta Pixel, CAPI, and server-side tracking. He understood our goals quickly, explained everything clearly, and ensured full transparency. Communication was smooth, updates were consistent, and the results improved our data accuracy and ad performance.”
Five-star reviews from businesses and agencies in the USA, Canada, UK and Australia.
Read All ReviewsYes. It runs in your browser with no login and no email form.
No. The hashing and all the checks run in your browser. Nothing you type or paste is uploaded. It is still best to use made-up customer details.
No, and you should not. The tool never asks for it. The cURL command contains the placeholder ACCESS_TOKEN, which you replace on your own machine.
Email, phone, first name, last name, gender, date of birth, city, state, postcode and country must be normalised and SHA-256 hashed. The IP address, user agent, fbc, fbp and lead_id must not be hashed.
Meta’s documentation says event_time can be up to 7 days before you send the event, with a longer window for physical store events. Sending events close to real time works best.
event_name, event_time, action_source, event_source_url and client_user_agent, plus at least one customer information field.
Send the same event name and the same ID from both. The server field is event_id and the pixel option is eventID. The Pixel tab shows the matching call.
No. Only Meta’s Events Manager can show that. The identity coverage label here is a simple guide to which matching keys your event carries.
It means the payload follows the published structure. Meta can still reject it for reasons the tool cannot see, such as a wrong pixel ID, an expired token or a newer rule. Test it in Events Manager under Test events.
I am MD Niamul, a conversion tracking and web analytics specialist and an official Stape partner. I set up the Meta Conversions API through server-side Google Tag Manager and Stape, with deduplication and consent handled properly, then test every event in Events Manager.