{
  "id": 11842606,
  "title": "Hash the email. Do not hash the IP. Both mistakes still return 200.",
  "url": "https://urgent.news/2026/10/04/hash-the-email-do-not-hash-the-ip-both-mistakes-still-return-200",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-04T04:30:45.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/aleksuix/hash-the-email-do-not-hash-the-ip-both-mistakes-still-return-200-214h"
  },
  "original_language": "en",
  "account": "The Meta Conversions API requires 64-character hex strings in certain user_data fields. Test Events show events are created despite poor match quality. The helper program hashed the email as required by Meta, but also hashed the IP address and click cookie, which is not permitted. Both mistakes result in a 200 HTTP response. Vendors hash the SHA-256 normalization of specific data. The 64-character hex value is the payload, and the algorithm is not a choice. Fields like em, ph, fn, ln, ge, db, ct, st, zp, country, and external_id are hashed with SHA-256. The helper should not hash PII (personal identifying information) fields or request metadata like client_ip_address and client_user_agent. Raw email in hashed slots causes matching issues and log leaks. Click ids, cookies, and request metadata must remain plaintext. Double hashing is not recommended as it leads to non-matchable events. The pixel should hash only the raw value, not a pre-existing digest. Deduplication uses event_id, not a second hash. Test with known values and the vendor's example digest before implementing the helper.",
  "summary": "A Purchase reaches the Meta Conversions API with a 64-character hex string in every user_data field. Test Events shows the event. Match quality on the live dataset stays poor, and nobody can see which field missed. The helper hashed the email, which Meta requires. It also hashed the IP address and the click cookie, which Meta requires you to leave alone. Both mistakes return HTTP 200. Vendors…",
  "key_points": [
    "Meta Conversions API requires 64-character hex strings in userdata fields",
    "Hashing email and IP in certain fields is not permitted",
    "Double hashing leads to non-matchable events"
  ],
  "editors_take": "The requirement for specific hashing of personal data in the Meta Conversions API means vendors must carefully handle data fields to avoid poor match quality and potential log leaks.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}