Skip to content
Bach.ai

Privacy Sandbox Attribution API vs Meta CAPI for DTC

Most DTC teams treat measurement as one problem with one fix: lose cookies, bolt on a server-side connection, call it solved. That collapses two very different jobs into one bucket, and it’s why so many post-cookie measurement stacks feel both over-engineered and strangely blind. The Privacy Sandbox Attribution Reporting API and Meta’s Conversions API operate at different layers of the funnel’s plumbing, and once you see the seam between them, the build decisions get simple.

For the surrounding account decisions, compare Optimize for Purchase or Add-to-Cart? Learning-Speed Math and use Android Privacy Sandbox & the Topics API: A DTC Prep Guide as the next diagnostic.

Two layers, one problem

The shared problem is signal loss. Third-party cookies are going away, browser tracking protections strip identifiers, ad blockers eat client-side events, and the deterministic link between “saw the ad” and “bought the thing” keeps fraying. Both technologies exist to rebuild that link without leaning on the old cross-site cookie.

But they rebuild it in opposite directions.

The Attribution Reporting API rebuilds measurement inside the browser — a neutral, privacy-constrained referee that any ad platform can read from. CAPI rebuilds signal delivery into one platform’s optimization engine — a direct pipe from your server to a single ad system. One is browser-level and platform-agnostic. The other is platform-level and platform-specific. Conflating them is where stacks go wrong.

What the Attribution Reporting API actually does

The privacy sandbox attribution reporting api is browser infrastructure, not a marketing tool you log into. The browser itself becomes the attribution layer. It works in two registrations:

  • Source registration happens when a user sees or clicks an ad. The browser quietly stores that the ad event occurred, without exposing a cross-site identifier to anyone.
  • Trigger registration happens at conversion. The browser privately matches the conversion back to a stored source and later emits a report.

It produces two report flavors, and the distinction matters more than any setup detail:

  • Event-level reports tie a conversion to a specific ad click, but carry only very limited conversion metadata and arrive on a delay. Enough to know “this click converted,” not much about what the conversion was worth.
  • Aggregatable (summary) reports carry richer values — order value, product category, funnel step — but only after passing through an aggregation service that injects statistical noise and only ever reports them in aggregate, never per user.

The design constraints are the whole point: noise injection, contribution budgets, capped cardinality, and deliberate delays. You trade per-user precision and real-time speed for measurement that survives in a world with no shared identifier. It is honest, coarse, slow, and neutral. No single platform owns the answer; the browser hands the same constrained truth to whoever participates.

What CAPI actually does

Meta’s Conversions API is the opposite shape. It’s a server-to-server pipe: your backend sends conversion events directly to the platform, sidestepping the browser entirely for delivery. Three things define it.

First, it’s identity-rich. You pass hashed match keys — email, phone, click identifiers, IP, user-agent — and the platform matches the event to a user it already knows. That’s the deterministic link the cookie used to provide, moved server-side.

Second, it’s deduplicated against the pixel. The browser pixel and the server event share an event_id and event name so the platform counts one conversion, not two. Server-side recovers what client-side loses to blockers and tracking protection; dedup keeps the recovery from double-counting.

Third — and this is the part teams underrate — it feeds the optimization algorithm, not just the report. Every well-matched purchase event with a value attached is training data. It’s how the delivery system learns who your buyers look like and goes to find more of them. CAPI isn’t primarily a measurement tool; it’s a signal-quality tool. Better, fuller, faster events make the machine bid smarter.

Where browser-level ends and platform-level begins

Here’s the seam, side by side:

Dimension Attribution Reporting API Meta CAPI
Layer Browser Platform (server-to-server)
Who can read it Any participating ad system One platform only
Identity basis No cross-site ID; browser-mediated Hashed match keys, deterministic
Timing Delayed, batched Near real-time
Granularity Aggregate-first, noised Per-event, precise
Primary job Neutral measurement Optimization signal + recovery
Improves delivery? No Yes

The practical reading: the Attribution Reporting API can tell you, in aggregate, that conversions happened across the cookieless web — but it cannot make a campaign perform better. It has no hand on the optimization lever. CAPI can make a campaign perform better and recover lost conversions — but it gives you the platform’s view, through the platform’s attribution windows and modeling, not a neutral one. Each is blind exactly where the other sees.

That’s why “we set up CAPI, so we’re covered” is a category error. You’ve fixed signal delivery into one platform. You haven’t built neutral, cross-surface measurement, and you never will from inside a single platform’s pipe.

What this means for your stack today

Be honest about sequencing. These aren’t equal priorities right now.

  1. CAPI is table stakes, today. If you’re running spend on the platform and your server-side events are thin or missing, you’re starving the algorithm and under-reporting results at the same time. Wire it server-side, dedup cleanly with event_id, pass as many hashed match keys as you legitimately hold, and always attach order value. Match quality is the lever — a high match rate is worth more than any clever dashboard.

  2. The Attribution Reporting API is mostly plumbing you consume, not build. Most DTC teams won’t integrate it directly; ad platforms and measurement vendors will read from it on your behalf. What you owe it is awareness: it sets the floor for what cookieless measurement can resolve. When your platform numbers and your aggregate browser-level numbers diverge, that gap is information, not an error to reconcile away.

  3. Neither gives you incrementality. This is the trap. CAPI’s reported conversions include modeled and view-through credit; the browser API is noised and delayed. Both can show a healthy number while a chunk of it would have converted anyway. Your blended truth still lives in MER — total revenue over total spend — and in periodic holdout or geo-style tests. Platform-reported ROAS is a tuning instrument for the algorithm, not your P&L.

  4. Treat them as a portfolio of signals. Server-side events feed and recover. Browser-level attribution keeps the platforms’ self-grading honest in aggregate. Blended economics keep you honest about whether the whole machine is actually growing the business in absolute terms.

This portfolio view is exactly how Bach reads an account — platform signal, recovered events, and blended economics weighed against each other rather than trusting any single number — surfacing where the gaps imply waste, and waiting for your approval before anything changes.

The takeaway

Don’t ask “which one.” Ask “which layer.” CAPI is your near-real-time, identity-rich pipe into one platform’s optimization brain — get it live, get the match rate high, and keep the pixel deduped against it. The Attribution Reporting API is the browser’s slow, noised, neutral referee for the cookieless web — understand it, let your vendors consume it, and read the divergence as signal. Then ignore both for the verdict and trust your blended economics. Browser-level measurement tells you what happened across surfaces; platform-level signal makes a platform perform; only your own unit math tells you whether any of it paid off.

See what your Meta ads are really costing you.

Connect your account and Bach ranks every revenue leak in minutes — each with the money it costs and a one-tap fix. Free for 7 days, no credit card.

Start Free Audit
Start your free audit