Skip to content
Bach.ai

Conversion API (CAPI) for Meta Ads: The Complete D2C Setup Guide

Updated Published
Drafted with AI assistance and edited by the Bach.ai team. How we write

How do I set up Meta Conversions API correctly?

Send server-side events alongside the browser Pixel, and give every event a matching event_id and event_name so Meta can deduplicate the pair. Most CAPI implementations technically work but fail here — duplicate events inflate reported conversions, which looks like success until the revenue does not arrive.

D2C brands running Meta Ads in 2026 lose part of their attribution signal to iOS privacy changes, ad blockers, and cookie restrictions. Conversion API (CAPI) is the only reliable way to recover that signal — and yet many brands either skip it or set it up incorrectly, leaving Event Match Quality well below where it should be.

Quick Answer

Meta Conversion API (CAPI) sends events from your server directly to Meta, bypassing browser limitations like iOS tracking prevention and ad blockers. To set it up correctly: enable the Facebook & Instagram channel on Shopify with Maximum Data Sharing (it includes CAPI), or for custom stores, deploy CAPI via Google Tag Manager Server-Side, Stape, or a direct server integration. Always send hashed customer data (email, phone, IP, user agent) for deduplication, share a unique event_id between Pixel and CAPI for every event, and target Event Match Quality (EMQ) above 7.0.

What CAPI actually fixes for D2C

The Meta Pixel runs in the browser. iOS users on recent versions — a large share of e-commerce traffic, and usually the higher-value share — plus Brave and Firefox users and anyone running an ad blocker are partly or wholly invisible to it. CAPI sends events from your server — where none of those blockers can interfere — directly to Meta’s servers.

The recovered signal does three things. It improves attribution accuracy so your reported ROAS moves closer to what your store actually recorded — how much closer depends on how much signal you were losing, which is measurable by comparing the two directly. It feeds Meta’s algorithm more conversion events so optimization exits Learning Phase faster. And it powers Lookalike Audiences off complete data instead of fragments.

Three ways to deploy CAPI for D2C stores

Method Best for Setup time Cost
Shopify Facebook & Instagram channel Shopify Basic/Advanced stores 15 minutes Free
GTM Server-Side + Stape WooCommerce, custom React/Next.js stores 4-8 hours $18–$48/mo
Direct server integration Custom Node/Python backends 2-3 days dev Free (your infra)

For most D2C brands on Shopify, the native channel is the right call. It auto-generates event_id, hashes customer data correctly, and stays synced when Shopify pushes updates. Only move to GTM Server-Side or direct integration if you need custom events Shopify does not support.

Shopify CAPI setup — the exact steps

Shopify routes CAPI through the Facebook & Instagram sales channel. Here is the sequence:

  1. Install the channel. Shopify Admin → Sales channels → Add channel → Facebook & Instagram by Meta.
  2. Authorize your Meta Business account. Use the account that owns your Pixel and Ad Account.
  3. Choose Maximum Data Sharing. This is critical. Standard only sends browser Pixel. Enhanced sends limited CAPI. Maximum sends both browser Pixel and full CAPI with deduplication.
  4. Verify your domain. Required for iOS attribution. Do this in Meta Business Settings → Brand Safety → Domains.
  5. Set 8 prioritized events in Aggregated Event Measurement. Order: Purchase, InitiateCheckout, AddToCart, ViewContent, then four more based on your funnel.
  6. Wait 48 hours, then check EMQ. Events Manager → Pixel → Settings → Event Match Quality. Anything below 6.0 means hashed data is incomplete.

CAPI for WooCommerce stores

WooCommerce does not have a native CAPI like Shopify. Two paths work for D2C brands:

Plugin route (faster). PixelYourSite Pro ($48/year one-time) or Pixel Manager for WooCommerce. Both push browser Pixel + CAPI with shared event_id out of the box. Check how whichever plugin you pick normalises phone numbers for your market — stripping the leading + and any spaces before hashing is where most of them differ, and it is the field that most often breaks matching.

GTM Server-Side route (more flexibility). Spin up a GTM Server container, host it on Stape ($18/mo for starter) or Google Cloud Run. Tag the WooCommerce client GTM to forward events to the server container, then deploy Meta’s official server-side template. This is the only option if you run a headless WooCommerce frontend.

Event deduplication — the make-or-break detail

When both browser Pixel and CAPI fire the same Purchase event, Meta needs to count it once, not twice. Deduplication works two ways:

  • event_name + event_id (the primary key): a unique ID your store generates per event (e.g., the Shopify order ID). Pixel sends it, CAPI sends the same one, with the same event name. Meta deduplicates events received within 48 hours of the first event with that event_id (Meta for Developers: deduplicate pixel and server events).
  • event_name + fbp or external_id (the weaker fallback): when event_id is missing, Meta can match on the event name plus the fbp browser ID or your external_id. Meta says this generally works only when the browser event arrives first and the server event second, and it can’t deduplicate a browser-only or server-only setup, or two server events (About deduplication for Meta Pixel and Conversions API events). Timestamps are not a deduplication key.

If event_id is not shared, you will see inflated Purchase counts — up to double the real number when every purchase is counted twice. This breaks every metric downstream. In Shopify with Maximum Data Sharing, event_id is handled automatically. In WooCommerce or custom builds, you must explicitly pass the same event_id in both Pixel fbq calls and server-side requests.

Customer Information Parameters (CIPs) — what to send

Meta uses hashed customer data to match server events to actual users. The more (and cleaner) data you send, the higher your EMQ. For D2C, send all of these:

Parameter Source Notes by market
em (email) Checkout form Lowercase, trim whitespace before hashing
ph (phone) Checkout form Country code first, digits only — no leading +, no spaces or dashes — before hashing
fn / ln (first/last name) Checkout form Lowercase, no special chars
ct (city) Shipping address Lowercase, no spaces
st (state) Shipping address Lowercase two-letter code where the market uses one (US, India, Australia); the full name lowercased otherwise
zp (postal code) Shipping address 5-digit ZIP in the US, 6-digit PIN in India, alphanumeric in the UK and Canada — send it unhashed in the format the address uses
country Shipping address Lowercase two-letter ISO country code — “us”, “gb”, “in”, “ae” — for the destination, not your own
client_ip_address Server request Real client IP, not your server IP
client_user_agent Browser HTTP header Full UA string
fbp _fbp cookie Unique browser ID the Meta Pixel saves in a first-party cookie
fbc _fbc cookie Click ID from fbclid URL param

All PII (em, ph, fn, ln, ct, st, zp) must be SHA-256 hashed before sending. IP, UA, fbp, and fbc are sent in plain text.

Reading your Event Match Quality (EMQ) score

EMQ is a 0-10 score Meta gives each event based on how many CIPs you send and how clean they are. Target above 7.0 for Purchase events; above 6.0 for upper funnel.

Check it weekly during the first month after setup. The most common reasons D2C brands score below 6.0: phone numbers sent with the leading + and spaces intact, so Meta cannot match them; names sent in mixed case or with titles like “Mr.”/“Mrs.” attached; and the postal-code field left empty because checkout did not require it.

Common Questions

Is Meta Conversion API free to use?

Yes. The API itself is free from Meta. Costs come from your deployment method — Shopify’s native channel is free; GTM Server-Side hosting on Stape starts at $18/month; direct server integration is free but takes 2-3 days of developer time.

What happens if I run Pixel without CAPI in 2026?

You will under-report conversions — most heavily from iOS and ad-blocker users, where browser-only tracking degrades worst. Meta’s algorithm then optimises on incomplete data, your CPAs look inflated, and your Lookalike Audiences get built from fragmented profiles. The size of the gap is account-specific: measure it by comparing Pixel-only events against your store’s own order count for the same window.

How do I test if my CAPI is firing correctly?

Go to Events Manager → your Pixel → Test Events tab. Add your test event code (TEST12345 or similar) to your CAPI payload. Place a test order. Within 2-3 minutes you should see the Purchase event tagged “Server” in the Test Events feed, alongside a “Browser” event with the same event_id. If only one fires, deduplication is broken.

Can CAPI work without the browser Pixel?

Technically yes, but you should always run both. The browser Pixel captures session-level signals (time on page, scroll depth, button clicks) that the server cannot see. CAPI captures conversions when the browser fails. Together they give Meta the most complete picture.

What to do next

CAPI is the single highest-ROI fix most D2C brands can ship in a week — and most are doing it wrong. Bach.ai inspects your Pixel and CAPI deployment, surfaces deduplication errors, EMQ drops, and missing parameters with exact remediation steps. Bach.ai is live at app.wittelsbach.ai — connect Meta, get a full audit free.

Method and sources

“Send server-side events alongside the browser Pixel, and give every event a matching event_id and event_name so Meta can deduplicate the pair.”

Source: Where this guide describes platform behaviour, it follows Meta’s published advertising and Marketing API documentation, which changes without notice — verify anything load-bearing against the current version before you act on it. Every threshold the guide asks you to supply is first-party, drawn from your own account exports and commerce ledger, because no external benchmark can stand in for your own margin structure.

Sources: About deduplication for Meta Pixel and Conversions API events, Meta for Developers: deduplicate pixel and server events, Meta for Developers: fbp and fbc parameters (checked 1 Oct 2026).

See what your Meta ads are really costing you.

Connect your account and Bach ranks potential revenue leaks with estimates and actions you can review. Free for 7 days, no credit card.

Start Free Audit
Start your free audit