_fbp created
A post-click same-origin request carries both _fbp and fbp_auto_set.
HAR-backed analysis of the target=meta landing flow, Meta identifier creation, AppsFlyer attribution, and which events actually left the browser.
_fbp createdA post-click same-origin request carries both _fbp and fbp_auto_set.
_fbc absentThe page only creates it from fbclid, which this landing URL did not have.
The actual AppsFlyer click contains no fbp, fbc, or fbclid.
The Meta connection failed and no facebook.com/tr request appears in the HAR.
The destination in the HAR exactly matches an active ad in Meta's official library, including its campaign-specific dance deep link.
AIVIDEOART.COThe CTA uses l.facebook.com/l.php, whose encoded destination is the exact get-started-v5?target=meta&deep_link_value=genericDance URL.
The wrapper refreshes to that destination without adding fbclid, fbp, fbc, or UTM parameters. The missing fbclid is therefore expected for this Ad Library preview link.
The capture confirms that the official Ad Library destination was opened. It does not contain the preceding l.facebook.com request, and it does contain a Safari/Google autocomplete lookup for the full destination immediately before navigation. It therefore cannot prove whether the CTA was clicked directly or the destination was copied or entered in Safari.
The initial page is a 200 response with an internal Next.js rewrite. The only browser-visible HTTP redirect occurs later at AppsFlyer.
| UTC time | Evidence |
|---|---|
| 21:04:13.569 | Landing document returns HTTP 200. The response sets only the existing project cookie. |
| 21:04:18.148 | connect.facebook.net fails with Proxyman status 999 (Error). |
| 21:04:18.653 | AppsFlyer OneLink is requested without fbp, fbc, or fbclid. |
| 21:04:18.697 | First-party telemetry records “Clipboard write success on first stage.” |
| 21:04:19.336 | A separate AppsFlyer impression request is sent. |
| 21:04:19.971 | A same-origin request carries _fbp and fbp_auto_set, confirming client-side creation. |
The code treats Meta cookie names and AppsFlyer query names differently: cookies use leading underscores, while redirect parameters do not.
_fbp fallbackOn a Meta-targeted click, the page checks for _fbp. If missing, it generates a value in Meta’s browser-ID shape and writes it for 90 days at Path=/.
It also writes fbp_auto_set=true. The HAR proves that this branch ran.
_fbc from click IDThe page reads fbclid from the landing query. It only synthesizes _fbc when that value exists and an _fbc cookie does not.
No fbclid existed here, so neither _fbc nor fbc_auto_set was created.
The page is tagged, but tagging and successful delivery are different findings. This capture only supports the former.
Pixel ID 467581009113723 is embedded in the captured page config.
The client calls the local fbq stub with a hashed external identifier.
PageView and Lead are only called when fbclid is non-null.
No library load completes and no Meta event beacon reaches the network.
No Meta browser event was delivered. The pixel initialization may have remained queued locally, while PageView and Lead were skipped because this URL had no fbclid.
The click is attributed as Facebook-origin traffic, but it lacks the Meta browser and click identifiers that would make the attribution chain more specific.
pid=facebook_w2adeep_link_value=genericDanceexternal_idfbclidfbpfbcAppsFlyer returns HTTP 301 to the Apple App Store and receives a separate impression request without these identifiers.
The related call to data.aivideoart.co/api/customEventPush is operational telemetry, not proof of a Meta Pixel conversion.
The payload contains an event ID ending in -error, the original landing URL, a redacted hashed external identifier, the browser user-agent, and an item description saying “Clipboard write success on first stage” with the generated OneLink.
It contains no event_name, fbp, fbc, or fbclid.
The capture and referenced code together point to a client-side sequencing issue.
The OneLink is constructed during page initialization using the cookies available then. The fallback _fbp is created later in the click handler, but the already-built URL is not regenerated before navigation. Result: the site creates _fbp, yet the outbound AppsFlyer click does not receive it.
The same bridge page is configured for five paid web-to-app channels, each with its own click-identifier passthrough. Meta is one lane of five, not the whole funnel.
facebook_w2a — passes fbc, fbptiktok_w2a — passes ttclid, ttpsnapchat_w2a — passes ScCidpinterest_w2a — passes epiknewsbreak_w2a — passes nb_cidEvery channel additionally forwards external_id and browser_user_agent for server-side (CAPI-style) matching. target=google also resolves.
Campaign parameters follow a fixed pattern per channel: <channel>_w2a-campaign, -channel, -ad, -adset.
Two OneLink templates are referenced from the page: 0DoU/8q4o34ah (the one in the capture) and 0DoU/r2ls2sbz.
The deep_link_value parameter is the creative identifier, carried from ad click through the install gap into the app.
The captured value genericDance matches the Ad Library creative (“Make anyone dance with AI Video”). The bridge page accepts arbitrary feature values — aiVlogCategory, viralDances, trends and others all resolve — so each ad deep-links into the specific feature it advertises rather than a generic home screen.
The telemetry line “Clipboard write success on first stage” is the deferred deep-link mechanism: the campaign token is copied before the App Store handoff and read by the app on first launch. It is what preserves creative-level attribution across an install gap where the store link drops parameters — the same gap that loses fbp in the flow analyzed above.
Dance is both the lead acquisition creative and the largest single recipe class in the catalog (44 of 201 cards, plus 4 pet-dance cards). A separate sweep of api.aivideoart.co/features/<key>/model — which authorizes on the x-userid header alone — returned the exact backend recipe for all 201 cards; every dance card runs nano-banana image preparation into Kling motion control. Acquisition spend and production stack point at the same feature.
The capture includes substantially more than this landing flow and should be handled as sensitive data.
The roughly 700 MB HAR contains 1,586 entries, hundreds of credential-bearing headers, access-token query fields, and embedded request and response bodies from Google, iCloud, Slack, WhatsApp, Apple, and other services. Because the artifact was downloadable without authentication, the hosted copy should be removed and potentially exposed credentials revoked or rotated.