Providers
The fourteen tags you can configure, what ID each one takes, custom scripts, and the Content-Security-Policy your app needs.
Fourteen providers, each validated against its own ID format so a mistyped container id is caught in the console rather than discovered as a silent gap in reporting weeks later.
| Provider | ID looks like | Default category |
|---|---|---|
| Google Tag Manager | GTM-ABC1234 | analytics |
| Google Analytics 4 | G-ABCD123456 | analytics |
| Google Ads | AW-123456789 + conversion labels | marketing |
| Meta Pixel | 123456789012345 | marketing |
| X (Twitter) Pixel | o1a2b3 + conversion ids | marketing |
| LinkedIn Insight Tag | 1234567 + conversion ids | marketing |
| TikTok Pixel | C4A1B2C3D4E5F6G7H8I9 | marketing |
| Reddit Pixel | t2_abc123 | marketing |
| Microsoft Advertising (UET) | 12345678 | marketing |
| Microsoft Clarity | ab12cd34ef | analytics |
| Hotjar | 1234567 | analytics |
| PostHog | phc_… | analytics |
| Plausible | example.com | analytics |
| Ahrefs Analytics | base64 key | analytics |
Where each id lives
Every one of these is a different console, and not knowing where the id is kept is the most common reason a tag never gets added. The console shows the same line under the field as you type.
| Provider | What to paste | Looks like | Where to find it |
|---|---|---|---|
| Google Tag Manager | Container ID | GTM-ABC1234 | Tag Manager, in the workspace header beside the container name. |
| Google Analytics 4 | Measurement ID | G-ABCD123456 | Analytics, under Admin › Data streams › your web stream, top right. |
| Google Ads | Conversion ID | AW-123456789 | Google Ads, under Goals › Conversions › Google tag. The per-conversion label sits on the conversion action itself, and goes in Conversion labels below. |
| Meta Pixel | Pixel ID | 123456789012345 | Events Manager, under Data sources, beneath the dataset name. |
| X (Twitter) Pixel | Pixel ID | o1a2b3 | X Ads, under Tools › Events manager › your pixel. Per-conversion ids go in Conversion labels below. |
| LinkedIn Insight Tag | Partner ID | 1234567 | Campaign Manager, under Analyze › Insight tag. Per-conversion ids come from Analyze › Conversions. |
| TikTok Pixel | Pixel ID | C4A1B2C3D4E5F6G7H8I9 | TikTok Ads, under Tools › Events › Web events › your pixel. |
| Reddit Pixel | Advertiser ID | t2_abc123 | Reddit Ads, under Events Manager. It is the advertiser id, beginning t2_. |
| Microsoft Advertising (UET) | Tag ID | 12345678 | Microsoft Advertising, under Tools › UET tag. |
| Microsoft Clarity | Project ID | ab12cd34ef | Clarity, under Settings › Setup - the id inside the tracking snippet. |
| Hotjar | Site ID | 1234567 | Hotjar, under Settings › Sites and organisations. |
| PostHog | Project API key | phc_abcdefghijklmnopqrstuvwxyz012345 | PostHog, under Settings › Project › Project API key. The public key, beginning phc_, never a personal one. |
| Plausible Analytics | Domain | example.com | Plausible uses the site domain you added, not a key - exactly as it appears in your Plausible site list. |
| Ahrefs Analytics | Analytics key | AbCdEfGhIjKlMnOpQrStUv== | Ahrefs, under Web Analytics › your project › the key in the snippet. |
This table is generated from the same catalogue the console reads, so the two cannot disagree. Vendors do reorganise their menus - if a path here is wrong, it is wrong in one place.
PostHog also asks for a Region: us.i.posthog.com or eu.i.posthog.com, matching the cloud your project was created in. Only those two are accepted, so a self-hosted PostHog cannot be pointed at from here.
Conversion labels
Google Ads, X and LinkedIn do not take an event name. They take an id you create in the ad platform, one per action you want to count. The console asks for those on the four that matter commercially - sign-up, trial, purchase and subscription - and sends what you filled in.
Leaving one blank is a supported choice: that event is not reported to that network. It is worth knowing because the failure is otherwise invisible - an unreported conversion looks exactly like nobody converting.
Google Tag Manager
GTM is one provider among the fourteen, not a thing BuildBase replaces. Paste one container ID and every event - ours and yours - arrives on the data layer as a trigger, with your triggers, variables and versioning staying where they already are.
A provider we do not have
Two escape hatches, in order of preference.
A script URL. Anything configured entirely through data- attributes - Fathom, Umami, Simple Analytics, Endorsely - can be added as an external script with its attributes. It installs, and it appears in the consent manifest if you name the vendor.
https://cdn.usefathom.com/script.js data-site=ABCDEF
Your own repo. You own your codebase and can add any <script> you like. BuildBase stores no inline JavaScript on your behalf, deliberately: a console that stored executable code would be a stored-XSS surface spanning every customer's origin, and it would duplicate something you can already do.
Tip
Vendors that need an inline init call - fbq('init'), ttq.load() - cannot
be expressed as a script URL, which is why those are first-class providers
instead. If yours is one of them, ask us and we will add it.
Content-Security-Policy
If your app sets a CSP - and it should - the tags need to be allowed, or they are blocked with no error anywhere a developer will see it.
script-src 'self' https://analytics.ahrefs.com https://analytics.tiktok.com
https://bat.bing.com https://connect.facebook.net
https://googleads.g.doubleclick.net https://plausible.io
https://scripts.clarity.ms https://snap.licdn.com
https://static.ads-twitter.com https://static.hotjar.com
https://us-assets.i.posthog.com https://www.clarity.ms
https://www.googletagmanager.com https://www.redditstatic.com
connect-src 'self' https://your-buildbase-api-host
https://ad.doubleclick.net https://www.google-analytics.com
https://www.google.com
img-src 'self' https://ad.doubleclick.net
https://googleads.g.doubleclick.net https://www.facebook.com
https://www.google.com
The console shows the script-src line of this list under Settings › Tracking & Tags. It is the full list for every provider, not only the ones you use, so trim it to the providers you have enabled. The connect-src and img-src lines are only here.
script-src alone is not enough. It loads the tags, and then connect-src and img-src block every hit they send - GA4 records nothing, and no conversion reaches Google Ads or Meta, while the page looks fine. The connect-src and img-src origins above are the ones measured for GA4, Google Tag Manager, Google Ads and Meta under an enforcing policy. For the other providers, load the page with the policy on and add what the browser console reports as refused.
Three reports are expected and need no change:
- Google Ads also pings the visitor's own country domain -
www.google.co.in,www.google.deand so on. No policy can wildcard a top-level domain, so this audience ping is blocked. The conversion still goes throughwww.google.com. - One
script-src 'eval'report on page load. It comes from a feature check in a validation library bundled with the SDK. The library triesFunction("")once and falls back when the policy refuses it. Do not add'unsafe-eval'for it. - GA4 can use other collection hosts for some properties, such as
analytics.google.comor a regional one. If one is reported refused, add it.
Warning
In development your API is usually plain http, which a connect-src 'self' https: policy blocks - taking the tracking config fetch down with every other
API call. Add the API origin explicitly rather than relaxing the policy.
Hosted auth pages load your tags
The hosted login, registration and verification screens load the scripts you attached to that app's auth client, resolved from the sign-in request rather than from anything configured per deployment. They fire sign_up and login there too, at the moment the account exists and the moment the session does.
This is worth having because the page where somebody actually signs up is the highest-intent page in your funnel, and it is the one page your own pixel cannot reach - it is not on your domain. Measuring only the click in and the return out loses everyone who abandons in between, which is most of the people you are paying to find.
Warning
These pages handle credentials, and they are on our origin. Everything you attach to that auth client runs there, including session recorders like Clarity and Hotjar - which means a recording of somebody typing into a password field, on a domain that is not yours, in a vendor account that is. Those vendors mask input values by default and we do not turn that off, but the default is theirs to change and the recording is yours to hold.
Attach to the auth client what you need to measure the conversion, and think twice before attaching anything that reads the page. A tag that only fires events - GA4, Google Ads, Meta, and the other ad platforms - carries none of this.
Nothing loads until the visitor's consent answer arrives with them. See Consent.
One tag, one place
If a tag is already on the page - your own leftover snippet, or a GTM container that also fires GA4 - the SDK detects it and skips its own install rather than loading it twice. Double-installing doubles every conversion, and there is no way to tell which of the two you meant to keep.
Check useTracking().installed to see what the SDK actually put on the page.