What the tracker sends (request payload)
The exact POST request the tracker sends to /api/event, every field in its JSON payload, and what is never sent: no cookies, identifiers or fingerprints.
Every hit is one POST to {origin}/api/event:
Content-Type: text/plain, so browsers don't send a CORS preflight,credentials: 'omit': no cookies are sent or accepted,keepalive: true, so hits survive page navigation.navigator.sendBeaconis the fallback whenfetchthrows.
The server answers 202 Accepted with an empty body, whether or not the hit is later kept, so the response never tells a script anything about your settings.
Body#
{
"s": "pa_7Q2K9XH3AB",
"t": "pageview",
"u": "https://example.com/pricing?utm_source=newsletter",
"r": "https://www.google.com/",
"l": "en-US",
"w": 1440,
"p": { "plan": "pro" }
}
| Key | Long name | Sent with | Meaning |
|---|---|---|---|
s |
site |
all | Site id |
t |
type |
all | pageview, event, engagement, vital or click |
u |
url |
all | Page URL after exclusions, masks and query parameter stripping |
r |
referrer |
when present | document.referrer, or a URL on your own site for SPA navigations |
l |
language |
all | navigator.language |
w |
screen_width |
all | screen.width in CSS pixels (stored as a size bucket) |
n |
name |
event, vital | Event name, or the Web Vital (LCP, INP, CLS, FCP, TTFB) |
p |
props |
pageview, event | Properties |
e |
engaged_ms |
engagement | Visible time on the page in milliseconds |
sd |
scroll_depth |
engagement | Maximum scroll depth, 0 to 100 |
v |
value |
vital | The Web Vital value |
c |
selector |
click | Short CSS selector of the clicked element |
h |
hash_mode |
when on | 1 if the fragment is part of the path |
d |
dnt |
when on | 1 if Do Not Track is on |
g |
gpc |
when on | 1 if Global Privacy Control is on |
The server also accepts rv/revenue and cu/currency at the top
level, but the tracker puts them in p.
Anything larger than 32 KB is ignored.
What isn't sent#
No cookies, no stored identifiers, no user id, no screen height or color depth, no installed fonts or plugins, no canvas or audio fingerprints, no timezone, no mouse movement, no form contents.
The server receives the IP address and User-Agent because every HTTP request carries them. They're used in memory and dropped. See How it works.