Skip to content
Huggehub Global Digital StudioParis --:--London --:--New York --:--Now accepting new projects →AI / Commerce / Technology / GrowthEurope • United Kingdom • United States

Performance · 10 min read ·

Meta Conversions API Setup: The Complete Guide (CAPI vs Pixel)

Browser tracking misses a growing share of conversions. The Conversions API sends them from your server — here's how to set it up properly.

By Hatim El Badaoui

Glass storefront panels connected by chrome pathways to checkout and analytics modules

Meta's ad delivery learns from conversions. When the Pixel misses purchases — because of ad blockers, browser privacy features, iOS restrictions or pages that close before the script fires — Meta optimises on incomplete data and your cost per purchase rises.

The Meta Conversions API (CAPI) fixes that by sending events from your server directly to Meta. This guide covers how it works, how it fits with the Pixel and how to set it up without double-counting.

Conversions API vs Pixel

Meta PixelConversions API
Runs inThe visitor's browserYour server
Blocked by ad blockers / browser privacyOftenNo
Can send offline and CRM eventsNoYes (orders confirmed later, phone sales, qualified leads)
Browser signals (cookies, fbc/fbp)AutomaticYou pass them yourself

Meta recommends running both, with deduplication. The Pixel captures browser context; CAPI guarantees the event arrives.

Step 1 — Choose your integration path

  • Shopify and major platforms — the native Meta / Facebook sales channel integration can send server events with little setup. Check it is enabled at the maximum data-sharing level.
  • Conversions API Gateway — Meta's hosted option that mirrors Pixel events server-side on your own cloud account.
  • Server-side Google Tag Manager — flexible if you already run sGTM.
  • Direct integration — your backend calls the API. Best for custom stores, CRMs and cash-on-delivery flows where the real conversion happens after the website session.

Step 2 — Build the event

A direct integration sends a POST to https://graph.facebook.com/{version}/{pixel_id}/events with an access token generated in Events Manager. Each event includes:

  • event_name — Purchase, Lead, AddToCart…
  • event_time — Unix timestamp in seconds, within the last seven days.
  • event_id — the same ID the Pixel used, for deduplication.
  • action_source — for example website, or system_generated / physical_store for other channels.
  • user_data — hashed customer information plus browser identifiers.
  • custom_data — value and currency for purchases.
{
  "data": [{
    "event_name": "Purchase",
    "event_time": 1790600000,
    "event_id": "order-10482",
    "action_source": "website",
    "event_source_url": "https://shop.example.com/checkout/thank-you",
    "user_data": {
      "em": ["<sha256 of normalised email>"],
      "ph": ["<sha256 of normalised phone>"],
      "client_ip_address": "203.0.113.7",
      "client_user_agent": "Mozilla/5.0 …",
      "fbc": "fb.1.1790599000.AbCdEf",
      "fbp": "fb.1.1790598000.123456789"
    },
    "custom_data": { "value": 49.90, "currency": "EUR" }
  }]
}

Step 3 — Hash customer data correctly

Personal identifiers must be normalised, then hashed with SHA-256 before they leave your server:

  • Email — trim and lowercase, then hash.
  • Phone — digits only with country code (e.g. 212612345678), then hash.
  • Names, city, postcode — lowercase, remove punctuation, then hash.
  • Do not hash IP address, user agent, fbc or fbp.

Our open-source meta-conversions-api-client is a dependency-free Python client that builds normalised events, SHA-256-hashes emails before sending and raises clear errors on API failures. Pixel ID and token are passed at call time, never hard-coded.

Step 4 — Deduplicate with event_id

If the Pixel and the server both send the same purchase, Meta keeps one when both events share the same event_name and event_id and arrive within 48 hours. Use a stable ID you have in both places — the order number is ideal. Without deduplication your reported conversions inflate and optimisation gets worse, not better.

Step 5 — Test, then watch Event Match Quality

  1. Add a test_event_code from Events Manager and check events appear in the Test Events tab.
  2. Confirm the Pixel and server events show as deduplicated.
  3. Remove the test code and monitor Event Match Quality. Sending email, phone, fbc, fbp, IP and user agent together usually lifts it.

Cash-on-delivery and CRM events

In COD markets such as Morocco, a web "purchase" is only a promise; the real sale happens at delivery. Sending a server event when an order is confirmed or delivered lets you optimise for customers who actually pay — one of the changes behind our Zinaé Cosmetics results.

Privacy

For EU and UK visitors, only send marketing events for users who consented, and document it in your privacy notice. Hashing protects data in transit; it does not replace consent.

Need tracking you can trust? Our Meta Ads team sets up Pixel + CAPI, deduplication and COD events as standard.

Frequently asked questions

Do I still need the Meta Pixel if I use the Conversions API?

Meta recommends using both with deduplication. The Pixel captures browser signals; the Conversions API makes sure events arrive even when the browser blocks tracking.

How does Meta deduplicate Pixel and CAPI events?

Events with the same event_name and event_id received within 48 hours are counted once. Use a stable ID such as the order number in both.

Which fields need hashing?

Personal identifiers such as email, phone, names, city and postcode are normalised and SHA-256 hashed. IP address, user agent, fbc and fbp are sent unhashed.

Can I send offline or CRM conversions?

Yes. The Conversions API accepts events from your CRM or order system — for example confirmed or delivered cash-on-delivery orders — with the appropriate action_source.

Let's build what's next

Let's build what's next.

Have a project, product or ambitious idea? Tell us where you want to go.