{"id":10464,"date":"2026-09-18T07:20:00","date_gmt":"2026-09-18T05:20:00","guid":{"rendered":"https:\/\/www.lukaswojcik.com\/blog\/?p=10464"},"modified":"2026-09-10T12:14:21","modified_gmt":"2026-09-10T10:14:21","slug":"conversions-api-hashing-normalising-customer-parameters-before-sha-256","status":"publish","type":"post","link":"https:\/\/www.lukaswojcik.com\/blog\/en\/digital-marketing\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\/","title":{"rendered":"Conversions API Hashing: Normalising Customer Parameters Before SHA-256 and Which Fields Stay Unhashed"},"content":{"rendered":"<p>A Conversions API event that carries a hashed email address looks the same whether the hashing was done right or wrong. The payload validates, the API answers with a success, the event counter goes up, and the match quality figure stays where it was &#8211; because the address, correctly hashed into a string that corresponds to nothing, was compared against a customer base and found in none of it.<\/p>\n<p>That is the failure mode worth understanding before any of the plumbing: hashing does not fail loudly, it fails by producing something that is technically flawless and semantically empty.<\/p>\n<figure class=\"lw-diagram\">\n<img decoding=\"async\" src=\"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/diagrams\/streuwert-form-en.png\" width=\"1120\" height=\"580\" loading=\"lazy\" alt=\"The same email address hashed twice: once trimmed and lowercased, once as it came from the form, producing two completely different SHA-256 values of which only one matches the stored record\"><figcaption>Two real SHA-256 values of the same address. Three characters of whitespace and a few capitals separate them.<\/figcaption><\/figure>\n<h2>Why a Small Difference Is a Total Difference<\/h2>\n<p>A hash function is built so that a minimal change to the input produces an unrecognisably different output. That property is what makes hashing useful, and it is exactly what makes a normalisation mistake fatal: there is no such thing as almost matching. Two hashes are identical or they have nothing to do with each other, and no amount of fuzzy matching downstream can recover the difference.<\/p>\n<p>So the entire question of whether an event finds a person is decided before the hash function is ever called, in the few lines that decide what exactly goes into it.<\/p>\n<h2>The Form Each Parameter Has to Take<\/h2>\n<table style=\"width:100%;border-collapse:collapse\">\n<thead>\n<tr>\n<th style=\"white-space:nowrap;vertical-align:top\">Parameter<\/th>\n<th>Required form<\/th>\n<th>What goes wrong<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"white-space:nowrap;vertical-align:top\"><code>em<\/code><\/td>\n<td>trimmed, lowercase<\/td>\n<td>a capital from the form, a trailing space from a paste<\/td>\n<\/tr>\n<tr>\n<td style=\"white-space:nowrap;vertical-align:top\"><code>ph<\/code><\/td>\n<td>digits only, with country code<\/td>\n<td>the national trunk zero in +49 (0)170 survives<\/td>\n<\/tr>\n<tr>\n<td style=\"white-space:nowrap;vertical-align:top\"><code>fn<\/code>, <code>ln<\/code><\/td>\n<td>lowercase, no punctuation or spaces<\/td>\n<td>a hyphen in a double-barrelled surname<\/td>\n<\/tr>\n<tr>\n<td style=\"white-space:nowrap;vertical-align:top\"><code>ct<\/code><\/td>\n<td>lowercase, no spaces<\/td>\n<td>Frankfurt am Main keeps its spaces<\/td>\n<\/tr>\n<tr>\n<td style=\"white-space:nowrap;vertical-align:top\"><code>st<\/code>, <code>country<\/code><\/td>\n<td>two-letter lowercase code<\/td>\n<td>the country is written out<\/td>\n<\/tr>\n<tr>\n<td style=\"white-space:nowrap;vertical-align:top\"><code>ge<\/code><\/td>\n<td>exactly <code>f<\/code> or <code>m<\/code><\/td>\n<td>anything else, hashed as if it were a value<\/td>\n<\/tr>\n<tr>\n<td style=\"white-space:nowrap;vertical-align:top\"><code>db<\/code><\/td>\n<td>YYYYMMDD<\/td>\n<td>a locale date format, silently reordered<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The phone number deserves a note of its own, because it is the one case that cannot be normalised mechanically. Stripping non-digits from <code>+49 (0)170 1234567<\/code> leaves <code>4901701234567<\/code>, and the zero after the country code is a national dialling prefix that has no place in an international number. No rule can decide that reliably for every country, which is why the honest handling is to strip, then flag the suspicious pattern for a human rather than guess.<\/p>\n<h2>The Parameters That Must Not Be Hashed<\/h2>\n<p>The opposite mistake is rarer and just as final. <code>client_ip_address<\/code>, <code>client_user_agent<\/code>, <code>fbp<\/code> and <code>fbc<\/code> are sent in plain text. They are not personal identifiers in the sense the hashed fields are; they are values Meta matches against its own records, and a hashed one is a string that corresponds to nothing on the other side.<\/p>\n<p>This happens most often when a hashing helper is applied to the whole user-data object at once, which is a reasonable-looking piece of code and wrong in exactly four fields. A helper that hashes by field name rather than by object is the version that survives a schema change.<\/p>\n<h2>What This Looks Like From Outside<\/h2>\n<pre class=\"wp-block-kevinbatdorf-code-block-pro\"><code># the same address, three ways\n\"  Max.Mustermann@Example.COM \"   &rarr; 524d6368ceb086b2b1d8fed14ee75313&hellip;\n\"  max.mustermann@example.com \"   &rarr; de4c5edc5348280eedb5b029d7851764&hellip;\n\"max.mustermann@example.com\"      &rarr; dd432348e6c3373c5f646913fa94ae79&hellip;\n\n# only the third is ever compared against anything<\/code><\/pre>\n<p>None of these produces an error. The event count in the events manager is identical in all three cases, the delivery is confirmed in all three cases, and the only figure that moves is the match quality &#8211; downwards, slowly, in a way that is easy to attribute to seasonality or to a consent change.<\/p>\n<p>Which is why the useful check is not the API response but a comparison against a known value. Take one address from the customer base, hash it the way the shop hashes it, hash it the way the specification prescribes, and compare the two strings. They match or the pipeline has a normalisation bug, and the answer takes a minute.<\/p>\n<h2>Where the Normalisation Belongs<\/h2>\n<p>The last decision is architectural. Normalisation can happen in the browser, in the server container, or in the backend that has the customer record &#8211; and only the last of those has the original value in the form the customer base stores it in.<\/p>\n<p>Doing it in the server-side container is the common middle ground and works, provided the container receives the raw value and not something a form has already mangled. Doing it in the browser is the one arrangement to avoid: it puts the plain address into a request that leaves the visitor&#8217;s machine, which is precisely what the hashing was there to prevent.<\/p>\n<div class=\"lw-quellen\">\n<h2>Sources<\/h2>\n<ul>\n<li><a href=\"https:\/\/developers.facebook.com\/documentation\/ads-commerce\/conversions-api\" target=\"_blank\" rel=\"noopener noreferrer\">Meta Conversions API<\/a><\/li>\n<\/ul>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Every customer parameter in a Conversions API event has to be written in one exact form before it is hashed. Get the form wrong and the hash is still valid, still accepted, and matched to nobody.<\/p>\n","protected":false},"author":1,"featured_media":15179,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[91057,91061],"class_list":["post-10464","post","type-post","status-publish","format-standard","hentry","category-digital-marketing","tag-meta-conversions-api","tag-server-side-gtm"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Conversions API Hashing: Normalising Customer Parameters Before SHA-256 and Which Fields Stay Unhashed - Lukas Wojcik - Blog<\/title>\n<meta name=\"description\" content=\"Why trimming and lowercasing decide whether a Conversions API event finds a person, and which parameters must not be hashed at all.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.lukaswojcik.com\/blog\/en\/digital-marketing\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Conversions API Hashing: Normalising Customer Parameters Before SHA-256 and Which Fields Stay Unhashed - Lukas Wojcik - Blog\" \/>\n<meta property=\"og:description\" content=\"Why trimming and lowercasing decide whether a Conversions API event finds a person, and which parameters must not be hashed at all.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.lukaswojcik.com\/blog\/en\/digital-marketing\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\/\" \/>\n<meta property=\"og:site_name\" content=\"Lukas Wojcik - Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-18T05:20:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-10464-a-valid-hash-that-matches-nothing-n.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lukas Wojcik\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lukas Wojcik\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/digital-marketing\\\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/digital-marketing\\\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\\\/\"},\"author\":{\"name\":\"Lukas Wojcik\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\"},\"headline\":\"Conversions API Hashing: Normalising Customer Parameters Before SHA-256 and Which Fields Stay Unhashed\",\"datePublished\":\"2026-09-18T05:20:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/digital-marketing\\\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\\\/\"},\"wordCount\":734,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\"},\"image\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/digital-marketing\\\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-10464-a-valid-hash-that-matches-nothing-n.png\",\"keywords\":[\"Meta Conversions API\",\"Server-Side GTM\"],\"articleSection\":[\"Digital Marketing\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/digital-marketing\\\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/digital-marketing\\\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\\\/\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/digital-marketing\\\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\\\/\",\"name\":\"Conversions API Hashing: Normalising Customer Parameters Before SHA-256 and Which Fields Stay Unhashed - Lukas Wojcik - Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/digital-marketing\\\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/digital-marketing\\\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-10464-a-valid-hash-that-matches-nothing-n.png\",\"datePublished\":\"2026-09-18T05:20:00+00:00\",\"description\":\"Why trimming and lowercasing decide whether a Conversions API event finds a person, and which parameters must not be hashed at all.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/digital-marketing\\\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/digital-marketing\\\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/digital-marketing\\\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-10464-a-valid-hash-that-matches-nothing-n.png\",\"contentUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-10464-a-valid-hash-that-matches-nothing-n.png\",\"width\":1200,\"height\":630,\"caption\":\"Conversions API Hashing: Normalising Customer Parameters Before SHA-256 and Which Fields Stay Unhashed\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/digital-marketing\\\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Conversions API Hashing: Normalising Customer Parameters Before SHA-256 and Which Fields Stay Unhashed\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/\",\"name\":\"Lukas Wojcik - Blog\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\",\"name\":\"Lukas Wojcik\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"contentUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"width\":424,\"height\":636,\"caption\":\"Lukas Wojcik\"},\"logo\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\"},\"sameAs\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Conversions API Hashing: Normalising Customer Parameters Before SHA-256 and Which Fields Stay Unhashed - Lukas Wojcik - Blog","description":"Why trimming and lowercasing decide whether a Conversions API event finds a person, and which parameters must not be hashed at all.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.lukaswojcik.com\/blog\/en\/digital-marketing\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\/","og_locale":"en_US","og_type":"article","og_title":"Conversions API Hashing: Normalising Customer Parameters Before SHA-256 and Which Fields Stay Unhashed - Lukas Wojcik - Blog","og_description":"Why trimming and lowercasing decide whether a Conversions API event finds a person, and which parameters must not be hashed at all.","og_url":"https:\/\/www.lukaswojcik.com\/blog\/en\/digital-marketing\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\/","og_site_name":"Lukas Wojcik - Blog","article_published_time":"2026-09-18T05:20:00+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-10464-a-valid-hash-that-matches-nothing-n.png","type":"image\/png"}],"author":"Lukas Wojcik","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Lukas Wojcik","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/digital-marketing\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\/#article","isPartOf":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/digital-marketing\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\/"},"author":{"name":"Lukas Wojcik","@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9"},"headline":"Conversions API Hashing: Normalising Customer Parameters Before SHA-256 and Which Fields Stay Unhashed","datePublished":"2026-09-18T05:20:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/digital-marketing\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\/"},"wordCount":734,"commentCount":0,"publisher":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9"},"image":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/digital-marketing\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\/#primaryimage"},"thumbnailUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-10464-a-valid-hash-that-matches-nothing-n.png","keywords":["Meta Conversions API","Server-Side GTM"],"articleSection":["Digital Marketing"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.lukaswojcik.com\/blog\/en\/digital-marketing\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/digital-marketing\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\/","url":"https:\/\/www.lukaswojcik.com\/blog\/en\/digital-marketing\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\/","name":"Conversions API Hashing: Normalising Customer Parameters Before SHA-256 and Which Fields Stay Unhashed - Lukas Wojcik - Blog","isPartOf":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/digital-marketing\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\/#primaryimage"},"image":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/digital-marketing\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\/#primaryimage"},"thumbnailUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-10464-a-valid-hash-that-matches-nothing-n.png","datePublished":"2026-09-18T05:20:00+00:00","description":"Why trimming and lowercasing decide whether a Conversions API event finds a person, and which parameters must not be hashed at all.","breadcrumb":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/digital-marketing\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.lukaswojcik.com\/blog\/en\/digital-marketing\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/digital-marketing\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\/#primaryimage","url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-10464-a-valid-hash-that-matches-nothing-n.png","contentUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-10464-a-valid-hash-that-matches-nothing-n.png","width":1200,"height":630,"caption":"Conversions API Hashing: Normalising Customer Parameters Before SHA-256 and Which Fields Stay Unhashed"},{"@type":"BreadcrumbList","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/digital-marketing\/conversions-api-hashing-normalising-customer-parameters-before-sha-256\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.lukaswojcik.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Conversions API Hashing: Normalising Customer Parameters Before SHA-256 and Which Fields Stay Unhashed"}]},{"@type":"WebSite","@id":"https:\/\/www.lukaswojcik.com\/blog\/#website","url":"https:\/\/www.lukaswojcik.com\/blog\/","name":"Lukas Wojcik - Blog","description":"","publisher":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.lukaswojcik.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9","name":"Lukas Wojcik","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","contentUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","width":424,"height":636,"caption":"Lukas Wojcik"},"logo":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg"},"sameAs":["https:\/\/www.lukaswojcik.com\/blog"]}]}},"_links":{"self":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts\/10464","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/comments?post=10464"}],"version-history":[{"count":4,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts\/10464\/revisions"}],"predecessor-version":[{"id":18251,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts\/10464\/revisions\/18251"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/media\/15179"}],"wp:attachment":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/media?parent=10464"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/categories?post=10464"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/tags?post=10464"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}