Skip to main content
Ad Account Rescue

Meta says our Conversions API events are missing the event_source_url parameter

The notice
Some of the events you share through Conversions API are missing the event_source_url parameter
On this page

Some of the events you send to Meta are labeled as website events but arrive without the page URL Meta requires. Meta's developer documentation says "The event_source_url is required for website events shared using the Conversions API", and it requires client_user_agent on website events too. The fix is on the sending side. Add the URL of the page where the conversion happened to every event you mark with action_source website, and give events that did not happen on your website, such as a phone call or a status change in your CRM, the action_source that matches where they happened. On a health website, check what that URL carries before you send it. If the warning shows a date, treat it as a deadline.

Curve Compliance sets up Meta Conversions API tracking that is built for health businesses from the start. Curve's team replaces browser pixels with HIPAA-compliant, server-side conversion tracking, detects PHI-like patterns before data reaches Meta, uses neutral event names, and hashes identifiers with SHA-256 to Meta's requirements. It keeps attribution through booking tools such as IntakeQ, Calendly and Jane, is typically live in about a week, and comes with a BAA on every plan. Book a call with Curve.

What Meta requires on a website event

  • event_source_url: "The browser URL where the event happened. The URL should match the verified domain." Meta adds: "The event_source_url is required for website events shared using the Conversions API."
  • client_user_agent: "The user agent for the browser corresponding to the event." Meta says it "is required for website events shared using the Conversions API."
  • action_source: "This field allows you to specify where your conversions occurred." The values include website, app, phone_call, chat, email, physical_store, system_generated, business_messaging and other, and Meta says "By using the Conversions API, you agree that the action_source parameter is accurate to the best of your knowledge."

Why health advertisers see this warning

Health businesses send a lot of conversions that never happen on a web page: a consultation booked in a scheduling tool, a patient marked as seen in the CRM, a phone call that turns into an appointment. When those are sent to Meta as website events, they carry no browser URL, and the warning follows.

The warning also matters more once your dataset is in a data source category with restrictions. If you see "Data sharing restrictions applied" on the same dataset, fix the missing URLs promptly, and follow any date the warning gives.

Check what the URL itself says

A page address can reveal health information on its own. A path that names a condition or treatment, or a query string that carries form answers, tells Meta something about the visitor. Meta's core setup, which applies to many health and wellness datasets, "restricts the transmission of custom parameters and anything in a URL following the domain." Meta's own example: a URL like https://jaspersmarket.com/clothes/summer/dresses?item=10 "would be shortened to" the domain.

So a long URL rarely adds anything Meta keeps for a restricted dataset, and it can add risk. Send the URL of the page on your verified domain, and make sure its path and query string don't name a condition, a treatment or anything a patient typed. See what core setup removes.

How to fix it

  1. In Meta Events Manager, open the dataset, go to Diagnostics and expand the warning to see which events are affected.
  2. For each affected event, decide where the conversion actually happened: on a page, in an app, on the phone, in person, or in a back-office system.
  3. For conversions that happened on your website, send event_source_url with the page URL on your verified domain, plus client_user_agent from the visitor's browser.
  4. For conversions that happened somewhere else, send the action_source that describes it, such as phone_call, physical_store or system_generated, instead of website.
  5. Strip anything from the URL that could reveal health information before it leaves your systems.
  6. Check Diagnostics again once new events have arrived.

Don't fix it by relabeling

Changing a website event's action_source just to avoid sending a URL is not a fix. Meta asks you to agree that the value is accurate, and a mislabeled event gives Meta the wrong picture of where your conversions come from. Label each event honestly, and send the URL when the event happened on a page. For the wider question of what server-side sending can and can't do for a health business, read whether server-side tracking gets around a restriction.

Talk to Curve

Missing parameters are a sign the tracking behind your Meta campaigns needs a proper rebuild. Curve's team sets up HIPAA-compliant, server-side conversion tracking in place of browser pixels, detects PHI-like patterns before data reaches Meta, uses neutral event names, and keeps attribution through your booking tool, so the conversions that happen after the click are still credited to the ad. It is typically live in about a week, with a BAA signed on every plan, so book a call with Curve.

How Curve helps

  • Replaces browser pixels with HIPAA-compliant, server-side conversion tracking to Meta Conversions API, Google Ads and TikTok.
  • Detects PHI-like patterns before data reaches Meta, and uses neutral event names.
  • Hashes identifiers with SHA-256 to each platform's requirements.
  • Keeps attribution through booking tools such as IntakeQ, Calendly and Jane, so bookings made after the click are credited to the ad.
  • Signs a BAA on every plan, with setup done for you by Curve's team, typically live in about a week.

Frequently asked questions

What is event_source_url?

Meta describes it as "The browser URL where the event happened." It should match your verified domain, and it is required for website events sent through the Conversions API.

Do events from our CRM or booking tool need event_source_url?

Only if you send them as website events. A conversion that happened on the phone, in person or in a back-office system should carry the action_source that describes it. Meta asks you to keep action_source accurate.

Could the URL expose patient information?

It can. A path or query string can name a condition, a treatment or a form answer. Send the page URL on your verified domain without anything that reveals health information. Under core setup, Meta shortens URLs to the domain anyway.

What happens if we ignore the warning?

Meta lists event_source_url as required for website events, so affected events are at risk. If the warning in Events Manager gives a date, fix the events before it.

How does Curve help with Meta Conversions API tracking?

Curve's team sets up HIPAA-compliant, server-side conversion tracking with PHI-like pattern detection, neutral event names and SHA-256 hashing, keeps attribution through your booking tool, and signs a BAA on every plan. Book a call with Curve.

Sources

Last verified

Talk to Curve about the data side of your restriction

Book a call and Curve's team will look at what your site sends to Meta, Google and TikTok, and show you the compliant setup that keeps your campaigns optimizing.

Book a call