Measurement Bridge guide

A reusable checklist for first-open measurement and server-side postbacks.

What it can change remotely

The Cloudflare console can register apps, enable first-open measurement, add or disable generic destinations on code-approved receiver hosts, stage the fixed OpenAI Conversions adapter, choose events, map generic fields, select consent gates, and HMAC-sign generic requests without a mobile release.

The OpenAI adapter is compiled and tested locally, but is not deployed or enabled. It still requires a Pixel ID, API key, authoritative server-owned ads consent, provider validation, and explicit enablement. Direct Meta, TikTok, and Google adapters are not active. Never put an access token in an endpoint URL. The bridge also cannot download a brand-new native SDK; that must be compiled, reviewed, and released through Apple or Google.

Add an app and postback

  1. Open Conversion Relay, enter the Conversion admin token, and load configuration.
  2. Choose Register another app, assign its stable app_id, and leave measurement disabled until its build is tested.
  3. For a generic receiver, use a host reviewed in Worker code and enter its exact credential-free HTTPS endpoint, request format, and consent gate. For OpenAI, select the compiled adapter; its endpoint, JSON format, ads-consent gate, and no-HMAC policy are fixed.
  4. Select only the events the receiver contract requires. OpenAI maps signup, trial, subscription, and first open in compiled code and accepts no operator-defined fields.
  5. Keep the destination disabled, choose Preview exact plan, and compare the redacted request with the receiver documentation.
  6. Apply the reviewed plan, test against a non-production receiver or test Pixel, then enable and apply a second reviewed plan.
  7. Use delivery counters and the stable event ID at the receiver to verify receipt; retries retain that same ID.

Available events

EventTruth source
install_first_openCompiled Measurement Bridge, once per pseudonymous installation.
sign_up_completedAuthenticated backend account completion.
trial_startedVerified RevenueCat webhook only.
subscription_startedVerified RevenueCat/store purchase only.

Available fields

FieldUse
event_id, event_name, dateStable deduplication ID, event type, and UTC occurrence time.
amount, amount_minor, currencyProvider-confirmed commerce value in major or minor units.
plan_name, product_idReviewed plan label and exact store product identifier.
install_id, account_id_hash, app_id, platformPseudonymous attribution and app/platform routing.
email_sha256Normalized hash; preferred where the partner supports it.
emailRaw email only for authoritative backend events, explicit ads consent, encrypted PII configuration, and an approved partner contract.

Background delivery contract

Operator to-do