ads-server-side-tracking
Server-side tracking pipeline audit covering server-side Google Tag Manager (sGTM), Meta CAPI Gateway, Conversions API health, event deduplication via event_id, server-side hit ratio targets, pixel debugging, and PII hashing discipline. Use when user says server-side tracking, sGTM, server-side GTM, server-side tagging, CAPI, Conversions API, CAPI Gateway, Meta Conversions API, event deduplication, event_id, pixel debug, pixel health, Pixel/CAPI audit, first-party tracking, iOS 14.5 recovery, or server-side hit ratio.
What this skill does
# Server-Side Tracking Pipeline Audit Audits the entire server-side measurement pipeline that backs every paid channel's modeled conversion data. Without server-side tracking in 2026, expect 30-40% conversion data loss from iOS ATT, ITP, and aggressive ad blockers — that's the gap between what's actually happening and what your bid algorithms can see. This sub-skill is technical and deep. It's NOT the same as `ads-attribution`, which audits the *attribution model* sitting on top of these events. ## Process 1. Collect server-side stack inventory: sGTM container info, Meta CAPI integration method (Gateway / direct / partner integration), event schema documentation, hosting infrastructure (Cloud Run / GCS / AWS) 2. Read `ads/references/conversion-tracking.md` for cross-platform baseline 3. Test event flow: trigger known events → verify they appear in BOTH client-side (Pixel Helper / Tag Assistant) AND server-side (Events Manager test events / GA4 DebugView) 4. Audit deduplication, hashing, and parameter completeness 5. Score health PASS / WARNING / FAIL per surface 6. Generate findings report ## What to Analyze ### Server-Side Google Tag Manager (sGTM) - **sGTM container deployed** — hosted on Cloud Run, GCS, App Engine, or custom infrastructure. Self-hosted preferred over Google-managed for cost and data residency - **Custom domain configured** (`tags.example.com`) — first-party domain avoids ITP / ad-blocker blocking that hits googletagmanager.com - **Client-side GTM forwards to sGTM** correctly; cookies, IP, user-agent preserved - **GA4 events flow via sGTM** (no direct client → GA4 fallback) - **Conversion Linker tag** enabled — preserves Google click IDs (gclid, gbraid, wbraid) across cross-domain navigation - **Server-side privacy filters** — strip non-essential PII before forwarding to analytics; only hash + forward what's needed for matching ### Meta CAPI / CAPI Gateway - **CAPI active** — Conversions API server-to-server alongside the Pixel - **CAPI Gateway** preferred over manual server implementation (auto- hashing, parameter coverage, lower maintenance) - **All major events server-side**: PageView, ViewContent, AddToCart, InitiateCheckout, Purchase, Lead, CompleteRegistration - **Event Match Quality (EMQ) ≥8.0** for Purchase — confirm via Events Manager → Overview → Data sources - **customer_information parameters** sent server-side: `em` (email), `ph` (phone), `fn`/`ln` (name), `ct`/`st`/`zp` (geo), `external_id`, `client_ip_address`, `client_user_agent`, `fbc`, `fbp` - **Hashing**: lowercased + trimmed SHA-256 for PII fields BEFORE send - **action_source** field set per event (`website`, `app`, `physical_store`, `email`, `system_generated`) ### Event Deduplication - **event_id** generated client-side, included in BOTH the Pixel event AND the CAPI / sGTM payload — Meta + Google both dedupe on this - **Dedup rate ≥90%** measured in Events Manager → Diagnostics - **Timestamp alignment** — server-side event timestamp within 5 minutes of client-side counterpart - **event_name consistency** — server-side uses the same canonical event names as client-side (don't rename in transit) ### Server-Side Hit Ratio - **Server-side ≥80% of client-side hits** for Purchase / Lead — anything lower means iOS / ITP / ad-blocker data loss isn't being recovered - **Server-side >100% acceptable** — means server-side captures conversions the client-side missed (good — that's what server-side is for) - **Hit ratio monitored over time** — drops below 60% indicate broken server-side firing or missing event_id ### Pixel / Tag Debug Walkthrough When deployed, validate every event end-to-end: - **Facebook Pixel Helper** (Chrome extension) shows the Pixel firing client-side with correct event_name + event_id + value + currency - **Meta Events Manager → Test Events** shows the CAPI event arriving server- side with matching event_id and customer_information parameters populated - **Google Tag Assistant** confirms client-side gtag firing - **GA4 DebugView** confirms server-side event arriving with event params - **Network tab** shows client → sGTM forwarding (not client → Google direct) - **`window.dataLayer`** populates expected variables before any tag fires ### Custom Event Taxonomy - **Canonical event names** documented (e.g., `purchase` not `Purchase` or `PURCHASE` or `order_complete`) - **Standard params per event**: `value`, `currency`, `content_ids`, `content_type`, `num_items` - **Custom params namespaced** (`cx_segment`, `cx_funnel_step`) to avoid collision with platform-standard params - **Schema versioned** — when the taxonomy changes, bump a version param so downstream platforms can handle the cutover ### Hash Quality & PII Handling - **Email**: lowercased + trimmed + SHA-256 (no other normalization) - **Phone**: E.164 format + SHA-256 (e.g., `+15551234567`) - **Name**: lowercased + trimmed + SHA-256 per first / last separately - **City / state / zip**: lowercased + SHA-256 - **NEVER hash already-hashed values** — double-hashing breaks matching - **NEVER send plain PII server-side** — only hashed - **GDPR / CPRA / CDPA compliance**: confirm consent state is read before sending PII server-side, even hashed ## Key Thresholds | Metric | Pass | Warning | Fail | |--------|------|---------|------| | sGTM custom domain | Active | Configured, not active | Not configured | | CAPI Gateway | Active | Manual CAPI | Pixel-only | | EMQ (Purchase) | ≥8.0 | 6.0-7.9 | <6.0 | | Dedup rate | ≥90% | 70-89% | <70% | | Server / client hit ratio | 80-120% | 50-79% | <50% | | customer_information completeness | 6+ params | 4-5 params | <4 params | | Hash convention | Documented + verified | Implicit | Inconsistent | | Test events validation | All 6 events pass | 3-5 events pass | <3 events pass | ## Output ### Server-Side Tracking Health Score ``` Server-Side Tracking Health Score: XX/100 (Grade: X) sGTM Pipeline: XX/100 ████████░░ (20%) CAPI / CAPI Gateway: XX/100 ██████████ (25%) Deduplication: XX/100 █████████░ (15%) Server-Side Hit Ratio: XX/100 ████████░░ (15%) Pixel Debug (6 events): XX/100 ███████░░░ (10%) Hash Quality / PII Handling: XX/100 ██████░░░░ (15%) ``` ### Deliverables - `SERVER-SIDE-TRACKING-AUDIT.md`: Full pipeline findings - Test-event reproduction log (which events validated end-to-end on which date, with screenshots from Events Manager / DebugView) - EMQ improvement roadmap (parameter-by-parameter) - Hit-ratio dashboard recommendation - Pre-launch checklist for any new platform integration (Amazon Marketing Cloud, Apple Ads, TikTok Events API)
Related in Ads & Marketing
ads
IncludedMulti-platform paid advertising audit and optimization skill. Analyzes Google, Meta, YouTube, LinkedIn, TikTok, Microsoft, and Apple Ads. 250+ checks with scoring, parallel agents, industry templates, and AI creative generation.
banana
IncludedAI image generation Creative Director powered by Google Gemini Nano Banana models. Use this skill for ANY request involving image creation, editing, visual asset production, or creative direction. Triggers on: generate an image, create a photo, edit this picture, design a logo, make a banner, visual for my anything, and all /banana commands. Handles text-to-image, image editing, multi-turn creative sessions, batch workflows, and brand presets.
rpg-migration-analyzer
IncludedAnalyzes legacy RPG (Report Program Generator) programs from AS/400 and IBM i systems for migration to modern Java applications. Extracts business logic from RPG III/IV/ILE source code, identifies data structures (D-specs), file operations (F-specs), program dependencies (CALLB/CALLP), and converts RPG constructs to Java equivalents. Generates migration reports, complexity estimates, and Java implementation strategies with POJO classes, JPA entities, and service methods. Use when modernizing AS/400 or IBM i legacy systems, analyzing RPG source files (.rpg, .rpgle, .RPGLE), converting RPG to Java, mapping data specifications to Java classes, planning legacy system migration, or when user mentions RPG analysis, Report Program Generator, RPG III/IV/ILE, AS/400 modernization, IBM i migration, packed decimal conversion, or mainframe application rewrite.
brand-library-architect
IncludedBuild a complete brand library for a product — visual asset render pipeline, brand documentation set (BRAND, COPY, MANIFESTO, BIOS, FAQ, GLOSSARY, TONE, PRICING), open-source convention files (README, CONTRIBUTING, SECURITY, CODE_OF_CONDUCT), and a self-contained press kit. This skill should be used when the user asks to "build a brand library / brand kit / press kit / brand assets" for a product, "set up a brand library workflow," "create a positioning manifesto plus visual identity," or any combination of brand documentation + visual asset pipeline. Apply phase-by-phase or run end-to-end. Templates are product-agnostic and use {{TOKEN}} placeholders the skill prompts the user to fill.
writing-tech-post
IncludedAuthors engineering blog posts end-to-end: launch deep-dives, incident postmortems, architecture migrations, performance case studies, tutorials, AI/agent system writeups, security disclosures, and research-to-product translations. Picks the correct archetype, plans the abstraction ladder, enforces an evidence cadence (diagrams, benchmarks, profiles, traces, code, ablations), tunes voice against publisher house styles (Datadog, Vercel, GitHub, AWS, Meta, Cloudflare, Jane Street), and runs a pre-publish gate for narrative momentum and disclosure ethics. Use when drafting a new engineering post, restructuring a draft that feels flat, deciding which evidence form belongs where, validating that depth and product context are balanced, or preparing a postmortem, migration, or performance narrative for external publication. Do not use for API reference documentation, README authoring, marketing copy, release notes, generic SEO content, ghost-written executive thought leadership, or non-engineering long-form essays.
blog-google
IncludedGoogle API integration for blog performance: PageSpeed Insights, CrUX Core Web Vitals with 25-week history, Search Console performance, URL Inspection, Indexing API, GA4 organic traffic, NLP entity analysis for E-E-A-T, YouTube video search for embedding, and Google Ads Keyword Planner. Progressive feature availability based on credential tier (API key, OAuth/service account, GA4, Ads). Shares config with claude-seo at ~/.config/claude-seo/google-api.json. Use when user says "google data", "page speed", "core web vitals", "search console", "indexation", "GA4", "keyword research", "nlp entities", "blog performance", "youtube search", "google api setup".