Explains how Facebook's fbclid URL parameter is structured and what can be extracted from it. The author collected roughly 50,000 fbclid-bearing URLs from public crawls and identified two generations: legacy values (2018-early 2024), almost always ~61 characters and containing only a platform marker, and modern values (April 2024-present), typically 100-190 characters and carrying multiple named fields. The first two header characters (Iw or PA) reliably indicate whether the click originated from Facebook (Iw) or Instagram (PA). All decoding work is reverse-engineered and field meanings are presented as the author's best guesses.
Describes the modern fbclid anatomy: a 2-character header, a URL-safe base64 payload, and an optional AEM trailer. Base64-decoding the payload reveals readable field names and values (for example clck, extn, aem, srtc, app_id) and binary data that can include click timestamps, a browser or client identifier, the source app ID, and other opaque IDs. Legacy fbclids decode to a marker, a version byte, and 42 uninterpreted bytes. The author updated the Unfurl tool to decode these newer fbclid formats and provides hex examples demonstrating the extracted fields and an app_id string.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.