What it is
The Meta Pixel reports events (page views, adds to cart, purchases) to a Meta ad account so campaigns can be optimised and attributed. It identifies the browser with `_fbp`, and captures the click that brought the visitor in with `_fbc`.
The classifier is deliberately narrow about facebook.com. A social plugin on /plugins/ is a media embed, and a request to /tr is the pixel. Treating every facebook.com request as advertising would misclassify a share button; treating none of them as advertising would miss the pixel entirely.
What a scan matches
A verification scan drives a real browser and records the outbound requests observed during its configured journeys, so Meta Pixel is identified by request hosts and paths rather than by source-code claims. Requests on unvisited paths, after unperformed interactions or solely on the server remain outside that observation.
- connect.facebook.net: where fbevents.js is served
- facebook.net
- facebook.com on the /tr path: the pixel endpoint specifically, which is how a scan tells a pixel apart from a page embed
Cookies are classified by name before domain because many analytics and advertising tags write first-party cookies through the page, which places a vendor-related identifier on your domain. Matching known names helps attribute those values without assuming that every first-party cookie came from your own application.
| Cookie | What it is for |
|---|---|
| _fbp | The browser identifier Meta uses to link activity to an ad account |
| _fbc | The click identifier captured from an fbclid parameter on arrival |
Controlling it with consent
With the named adapter, enter the Pixel ID and remove any hardcoded pixel from your theme. Before marketing consent the managed pixel is withheld. After approval it loads and supplies vendor consent. On withdrawal it sends the vendor revoke signal.
Two things stay outside the runtime’s reach and need their own handling: a second pixel installed inside a tag manager or a platform app, and the server-side Conversions API, which runs on your infrastructure and never touches the page.
This one has a first-class adapter
Enter the identifier in the property’s technology list and the runtime applies that adapter’s control strategy. Depending on the vendor, that means withholding the loader, establishing denied defaults, or loading a functional surface with tracking opted out; the article above describes the exact behavior. Remove copies installed in a theme, plugin, app or tag manager first, or another installation can remain outside that control.
What breaks if it is refused: campaign optimisation and attribution for visitors who refused. Nothing on the page.
Verifying it
Check fbevents.js, the requests to /tr, and Meta’s own test events across before, reject, allow and withdraw, including with a script that loads late. Confirm there is exactly one installation.
- Before a choice: optional tracking endpoints and optional identifiers are absent; any intentionally loaded necessary or functional surface matches the control model described above
- After rejecting optional categories: optional activity remains absent and the refusal persists across a reload
- After granting the relevant category: the expected loader or embed appears and the feature behaves normally
- After withdrawing: new optional activity stops; where the vendor supports a consent signal, verify that the signal is sent as well as checking network behavior
Common questions
Does the Conversions API avoid the consent requirement?
No. Moving collection server-side changes the transport, not the purpose or the legal analysis. It also puts the data outside anything a browser-side consent runtime can control, so the consent state has to be carried into your server integration deliberately.
Why does a scan report Facebook as media on some pages?
Requests to facebook.com/plugins/ are page embeds (a like button, a comments widget) and are classified as media. The pixel is matched on the /tr path.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- Meta for Developers: fbp and fbc parameters
Vendor documentation
Checked
- Meta: United States Regional Privacy Notice
Vendor documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.