The Definitive Guide to Meta Conversions API (CAPI) Server-Side for Operations Above BRL 100k/month
Why relying only on the browser pixel drops conversion events, and how Server-Side infrastructure preserves parameter integrity in Meta Ads.
Operating scenario: Accounts with significant ad budgets lose conversion identifiers when they rely only on browser scripts. The algorithmic auction receives fragmented signals and loses targeting precision.
Technical root cause: Restrictive browser policies such as Safari ITP, plus ad blockers, discard cookies and stop JavaScript tags from running before events are transmitted.
Engineering guideline: Dedicated server infrastructure (sGTM on your own cloud) connected to Meta Conversions API, with HttpOnly first-party cookies and native event_id deduplication.
Meta Ads Signal Architecture in Large-Scale Operations
Companies that invest significant budgets in paid media operate in an auction that is highly sensitive to the quality of the data fed back to it. The Meta Ads machine learning algorithm uses conversion events to calibrate ad delivery and estimate each user's likelihood to buy.
Since Apple's App Tracking Transparency (ATT) and the spread of cookie-blocking policies in browsers such as Safari and Firefox, the traditional browser-based pixel has become vulnerable. A relevant share of the transactions completed on the site never reaches Ads Manager when tracking depends only on scripts running on the customer's device.
The Technical Diagnosis in Events Manager:
In your ad account's Events Manager, the Event Match Quality (EMQ) score for the Purchase event shows how well the data you send is being matched. Low scores signal that the algorithm is receiving incomplete identifiers, which makes it harder to tie the ad click to the transaction that followed.
Anatomy of the Meta Conversions API (CAPI) Payload
The Conversions API creates a direct communication channel between the company's server and Meta's servers. The call fires synchronously or asynchronously when payment is confirmed, sending hashed data through secure REST calls.
Below is an example of a technical JSON payload structured for the /v20.0/{pixel_id}/events endpoint:
{
"data": [
{
"event_name": "Purchase",
"event_time": 1726752000,
"event_id": "order_89412",
"event_source_url": "https://empresa.com.br/checkout/sucesso",
"action_source": "website",
"user_data": {
"em": ["4f728c35d90953a79d0362f6b86f1f4ab8826c7d7b3226db202888cf3e2840c8"],
"ph": ["99c927f87f4c026939943485703ff3cb79ff735c0cf3ff3e0b25e173ffb612c6"],
"client_ip_address": "177.18.240.12",
"client_user_agent": "Mozilla/5.0 (iPhone; CPU iPhone OS 17_5 like Mac OS X)...",
"fbp": "fb.1.1718000000.123456789",
"fbc": "fb.1.1718000000.PAZnRzaAUY-c9wZG9m..."
},
"custom_data": {
"currency": "BRL",
"value": 4850.00,
"content_type": "product",
"order_id": "ORD-2026-89412"
}
}
]
}
Event Deduplication with a Shared event_id
To make sure a conversion is not counted twice, the recommended engineering approach sends the event redundantly and relies on native deduplication. The browser fires the Purchase event through the pixel while the server container simultaneously sends the payload with the same unique event_id.
Meta's infrastructure processes both events, compares the identification key and consolidates the record. If ad-blocking extensions prevent the browser event from firing, the server still delivers the data to the auction intact.
Conventional Pixel (Client-Side)
- Vulnerable to script-blocking extensions
- Cookies discarded after short periods by Safari ITP
- Depends on the stability of the customer's network
- Frequent loss of advanced parameters such as fbp, fbc and IP
Dedicated Server-Side Architecture
- Direct server-to-server communication over a secure protocol
- First-party cookies set over HTTP
- Stable processing at the moment the order is confirmed
- Advanced parameters preserved for a high EMQ score
SHA-256 Hashing and Identifier Normalization
Meta requires all of the user's personal data (PII) to be hashed with SHA-256 before it travels over the network. The hash is only reliable, though, if the data is standardised first:
- Email: Trim leading and trailing spaces and convert to lowercase (example:
[email protected]). - Phone: International format with country code and area code, without spaces, dashes or parentheses (example:
5511999998888). - First and last name: Lowercase, with no punctuation or honorific titles.
- fbp and fbc parameters: Must be preserved exactly as stored in the first-party cookies, with no change of format.
Frequently Asked Questions about Meta Conversions API (CAPI)
Why use CAPI if the browser pixel still works?
The browser pixel is subject to network blocking, execution failures on load and restrictive cookie retention rules. CAPI complements the pixel from the server, making sure the auction receives the transactions even when the browser fails.
What is the difference between CAPI Gateway and a dedicated sGTM?
CAPI Gateway is a simplified, managed solution that Meta provides on AWS instances. sGTM (Server-Side Google Tag Manager) gives you granular control over the data, so you can send the same signal to Meta, Google Ads, TikTok and CRM tools from a single infrastructure.
Can deduplication fail and inflate revenue in the dashboard?
Deduplication only fails if the event_id or event_name values differ between the browser event and the server event. When both share exactly the same identifier, the system consolidates the two sends into a single conversion.
Engineering Implementation Roadmap
- Dedicated Container Hosting: Provision Google Cloud Run containers or AWS instances under a subdomain the brand owns (example:
dados.seudominio.com.br). - First-Party Cookie Configuration: Convert the
_fbpand_fbcparameters intoSet-Cookieheaders with theHttpOnlyandSameSite=Laxdirectives. - Upfront Data Normalization: Clean and sanitize the data before applying the SHA-256 hash function.
- Health Monitoring in Events Manager: Check the deduplication rate and the match quality score in Meta Events Manager on a regular basis.
Does your company invest more than BRL 100k/month and want data governance in the auction?
Random Marketing's engineering team advises on designing and implementing CAPI Server-Side infrastructure for your business.
I want to hire Random Marketing for my company ↗Official documentation & engineering references
Architecture guidelines, API specifications and official technical documentation consulted to support this dossier: