Conversion API Prerequisites

Prev Next

You have two options for sending user data with the Quantcast Conversions API:

If you currently use Quantcast Live Tag and have conversions firing for authenticated (logged in or uniquely identifiable) users, you can include your own unique user identifier in the normal browser-initiated pixel events (e.g., page views). You can use the same identifier when sending server-side conversion events (please see below for sending conversion events). Note that this identifier must not be plain-text or hashed emails, or any other PII.

To do so, add an external_id parameter to your existing pixel call for authenticated or identifiable users. Quantcast will then record the association between your identifier and the user on each pixel fire. Here is an example of a Live Tag event with an added external_id field:

_qevents.push({
  qacct: "p-XXXXXXXXX",
  external_id: "user-id-abc123", // <-- here
  ...
});

Notes:

  • You must choose an identifier that is available both on the browser side (in Live Tag) and on your server side when the conversion happens.

  • Quantcast does not support receiving hashed emails or other PII as external_id.

  • If you want to send hashed External IDs, you must hash External ID values in both the Live Tag and the Conversions API. Quantcast will not modify or re-hash your external_id.

Option 2: Using Quantcast Browser Tokens

Browser Tokens are temporary, user-specific tokens that allow Quantcast to link server-side conversions back to the user’s specific web activity.

When a user visits your website, you can obtain a Browser Token using the methods explained below. Store this token in your backend/CRM platform and include it in server-side conversion events. Browser Tokens are valid for up to 90 days, but the exact expiry time will be specified in the token response.

Browser Token object:

Attribute

Type

Description

token

string

The browser token string. This is the value that you need to store and pass in offline conversion events.

expires

int

The token expiry in Unix Timestamp. There is no need to store this value, but it is useful for refreshing the token if needed.

There are three ways to acquire this token:

  • Via Live Tag: If you currently use Quantcast Live Tag, you can simply pass a token_callback parameter to the object passed to _qevents. Live Tag will acquire a token and pass it to your provided function. For example:

window._qevents = window._qevents || [];

_qevents.push({
  "qacct": "p-XXXXXXXXX",
  "event": "_fp.event.PageView",
  "token_callback": function(qcBrowserToken) {
    // This is just an example to send the retrieved token to your servers.
    // You need to implement some way to store the token on your side
    // and retrieve it when sending server-side events.
    //
    // `qcBrowserToken.token` is the browser token string
    // `qcBrowserToken.expires` is the expiration time of the token in unix epoch time
    navigator.sendBeacon("/store-token", JSON.stringify(token));
  }
});
import token from "@quantcast-labs/events-sdk";

token("<p-account-id>").then((qcToken) => {
  // qcToken.token is the browser token string
  // qcToken.expires is the expiration time of the token in unix epoch time
  /* code to send this token to your servers comes here */
}).catch(console.log);
  • Calling the Quantcast Token API Manually: When integrating with the Conversions API, it may be preferable to use neither the Quantcast SDK or Live Tag. Should this be the case, the token endpoint can still be invoked directly so long as the request originates from a browser associated with the customer. The token endpoint accepts a number of URL parameters, provided as a series of key-value pairs encoded in form/x-www-form-urlencoded format.

GET https://pixel.quantserve.com/token

The token endpoint accepts Transparency and Consent Framework v2, US Privacy API, and Global Privacy Platform consent signals. The endpoint will honor privacy choices and not generate a token if the request lacks required consents.

Parameter

Description

a

[required] The Account ID in the Quantcast platform, starting with p-.

fpa

A first party identifier (such as a cookie) from the website making the call. Useful for cookieless targeting and attribution.

d

The domain that the cookie is set on.

gdpr

A number (0 or 1) indicating if GDPR applies to this request.

gdpr_consent

A Base64-URL encoded Transparency & Consent String compatible with TCFv2. This value is required if gdpr=1.

us_privacy

A US Privacy API string in the format of the IAB US Privacy API. This value MAY be included if a USP API compliant Consent Manager is present on the page. It is deprecated in favor of the Global Privacy Platform.

gpp

A Global Privacy Platform Consent String. This value SHOULD be provided if the page includes a GPP-compatible Consent Management Provider.

gpp_sid

A comma-separated list of section ids that applied to this request when consent was collected. This value should contain the values supplied in the applicableSections parameter of the response from any GPP-compatible Consent Management Platform.

See the "Full GPP String passing" section of the GPP Consent String Specification.

Here’s an example of calling the token endpoint directly:

const requestUrl = new URL("https://pixel.quantserve.com/token");

const params = new URLSearchParams({
  a: "p-XXXXXXXXX",
  // this value and other privacy signals must be retrieved from your IAB-compliant CMP
  gdpr: "1", // or "0" if gdpr does not apply to this browsing session
  gdpr_consent: "....",
  ...
});

requestUrl.search = params.toString();

fetch(requestUrl, { credentials: 'include' }) // <-- important to pass this option to the fetch call
   // response looks something like this:
   // {"expires":1744580688,"token":"Q0--svL...jVvE-9W8vAeIJu"}
  .then(response => response.json())
  .then((qcToken) => {
    // qcToken.token is the browser token string
    // qcToken.expires is the expiration time of the token in unix epoch time
    /* code to send this token to your servers comes here */
  });

Once you implement the necessary changes for user identification, you can send offline conversions to Quantcast’s Conversions API.