BuildBaseBuildBase

Providers

The fourteen tags you can configure, what ID each one takes, custom scripts, and the Content-Security-Policy your app needs.

Fourteen providers, each validated against its own ID format so a mistyped container id is caught in the console rather than discovered as a silent gap in reporting weeks later.

ProviderID looks likeDefault category
Google Tag ManagerGTM-ABC1234analytics
Google Analytics 4G-ABCD123456analytics
Google AdsAW-123456789 + conversion labelsmarketing
Meta Pixel123456789012345marketing
X (Twitter) Pixelo1a2b3 + conversion idsmarketing
LinkedIn Insight Tag1234567 + conversion idsmarketing
TikTok PixelC4A1B2C3D4E5F6G7H8I9marketing
Reddit Pixelt2_abc123marketing
Microsoft Advertising (UET)12345678marketing
Microsoft Clarityab12cd34efanalytics
Hotjar1234567analytics
PostHogphc_…analytics
Plausibleexample.comanalytics
Ahrefs Analyticsbase64 keyanalytics

Where each id lives

Every one of these is a different console, and not knowing where the id is kept is the most common reason a tag never gets added. The console shows the same line under the field as you type.

ProviderWhat to pasteLooks likeWhere to find it
Google Tag ManagerContainer IDGTM-ABC1234Tag Manager, in the workspace header beside the container name.
Google Analytics 4Measurement IDG-ABCD123456Analytics, under Admin › Data streams › your web stream, top right.
Google AdsConversion IDAW-123456789Google Ads, under Goals › Conversions › Google tag. The per-conversion label sits on the conversion action itself, and goes in Conversion labels below.
Meta PixelPixel ID123456789012345Events Manager, under Data sources, beneath the dataset name.
X (Twitter) PixelPixel IDo1a2b3X Ads, under Tools › Events manager › your pixel. Per-conversion ids go in Conversion labels below.
LinkedIn Insight TagPartner ID1234567Campaign Manager, under Analyze › Insight tag. Per-conversion ids come from Analyze › Conversions.
TikTok PixelPixel IDC4A1B2C3D4E5F6G7H8I9TikTok Ads, under Tools › Events › Web events › your pixel.
Reddit PixelAdvertiser IDt2_abc123Reddit Ads, under Events Manager. It is the advertiser id, beginning t2_.
Microsoft Advertising (UET)Tag ID12345678Microsoft Advertising, under Tools › UET tag.
Microsoft ClarityProject IDab12cd34efClarity, under Settings › Setup - the id inside the tracking snippet.
HotjarSite ID1234567Hotjar, under Settings › Sites and organisations.
PostHogProject API keyphc_abcdefghijklmnopqrstuvwxyz012345PostHog, under Settings › Project › Project API key. The public key, beginning phc_, never a personal one.
Plausible AnalyticsDomainexample.comPlausible uses the site domain you added, not a key - exactly as it appears in your Plausible site list.
Ahrefs AnalyticsAnalytics keyAbCdEfGhIjKlMnOpQrStUv==Ahrefs, under Web Analytics › your project › the key in the snippet.

This table is generated from the same catalogue the console reads, so the two cannot disagree. Vendors do reorganise their menus - if a path here is wrong, it is wrong in one place.

PostHog also asks for a Region: us.i.posthog.com or eu.i.posthog.com, matching the cloud your project was created in. Only those two are accepted, so a self-hosted PostHog cannot be pointed at from here.

Conversion labels

Google Ads, X and LinkedIn do not take an event name. They take an id you create in the ad platform, one per action you want to count. The console asks for those on the four that matter commercially - sign-up, trial, purchase and subscription - and sends what you filled in.

Leaving one blank is a supported choice: that event is not reported to that network. It is worth knowing because the failure is otherwise invisible - an unreported conversion looks exactly like nobody converting.

Google Tag Manager

GTM is one provider among the fourteen, not a thing BuildBase replaces. Paste one container ID and every event - ours and yours - arrives on the data layer as a trigger, with your triggers, variables and versioning staying where they already are.

A provider we do not have

Two escape hatches, in order of preference.

A script URL. Anything configured entirely through data- attributes - Fathom, Umami, Simple Analytics, Endorsely - can be added as an external script with its attributes. It installs, and it appears in the consent manifest if you name the vendor.

https://cdn.usefathom.com/script.js   data-site=ABCDEF

Your own repo. You own your codebase and can add any <script> you like. BuildBase stores no inline JavaScript on your behalf, deliberately: a console that stored executable code would be a stored-XSS surface spanning every customer's origin, and it would duplicate something you can already do.

Tip

Vendors that need an inline init call - fbq('init'), ttq.load() - cannot be expressed as a script URL, which is why those are first-class providers instead. If yours is one of them, ask us and we will add it.

Content-Security-Policy

If your app sets a CSP - and it should - the tags need to be allowed, or they are blocked with no error anywhere a developer will see it.

script-src  'self' https://analytics.ahrefs.com https://analytics.tiktok.com
            https://bat.bing.com https://connect.facebook.net
            https://googleads.g.doubleclick.net https://plausible.io
            https://scripts.clarity.ms https://snap.licdn.com
            https://static.ads-twitter.com https://static.hotjar.com
            https://us-assets.i.posthog.com https://www.clarity.ms
            https://www.googletagmanager.com https://www.redditstatic.com
connect-src 'self' https://your-buildbase-api-host
            https://ad.doubleclick.net https://www.google-analytics.com
            https://www.google.com
img-src     'self' https://ad.doubleclick.net
            https://googleads.g.doubleclick.net https://www.facebook.com
            https://www.google.com

The console shows the script-src line of this list under Settings › Tracking & Tags. It is the full list for every provider, not only the ones you use, so trim it to the providers you have enabled. The connect-src and img-src lines are only here.

script-src alone is not enough. It loads the tags, and then connect-src and img-src block every hit they send - GA4 records nothing, and no conversion reaches Google Ads or Meta, while the page looks fine. The connect-src and img-src origins above are the ones measured for GA4, Google Tag Manager, Google Ads and Meta under an enforcing policy. For the other providers, load the page with the policy on and add what the browser console reports as refused.

Three reports are expected and need no change:

  • Google Ads also pings the visitor's own country domain - www.google.co.in, www.google.de and so on. No policy can wildcard a top-level domain, so this audience ping is blocked. The conversion still goes through www.google.com.
  • One script-src 'eval' report on page load. It comes from a feature check in a validation library bundled with the SDK. The library tries Function("") once and falls back when the policy refuses it. Do not add 'unsafe-eval' for it.
  • GA4 can use other collection hosts for some properties, such as analytics.google.com or a regional one. If one is reported refused, add it.

Warning

In development your API is usually plain http, which a connect-src 'self' https: policy blocks - taking the tracking config fetch down with every other API call. Add the API origin explicitly rather than relaxing the policy.

Hosted auth pages load your tags

The hosted login, registration and verification screens load the scripts you attached to that app's auth client, resolved from the sign-in request rather than from anything configured per deployment. They fire sign_up and login there too, at the moment the account exists and the moment the session does.

This is worth having because the page where somebody actually signs up is the highest-intent page in your funnel, and it is the one page your own pixel cannot reach - it is not on your domain. Measuring only the click in and the return out loses everyone who abandons in between, which is most of the people you are paying to find.

Warning

These pages handle credentials, and they are on our origin. Everything you attach to that auth client runs there, including session recorders like Clarity and Hotjar - which means a recording of somebody typing into a password field, on a domain that is not yours, in a vendor account that is. Those vendors mask input values by default and we do not turn that off, but the default is theirs to change and the recording is yours to hold.

Attach to the auth client what you need to measure the conversion, and think twice before attaching anything that reads the page. A tag that only fires events - GA4, Google Ads, Meta, and the other ad platforms - carries none of this.

Nothing loads until the visitor's consent answer arrives with them. See Consent.

One tag, one place

If a tag is already on the page - your own leftover snippet, or a GTM container that also fires GA4 - the SDK detects it and skips its own install rather than loading it twice. Double-installing doubles every conversion, and there is no way to tell which of the two you meant to keep.

Check useTracking().installed to see what the SDK actually put on the page.

Next

  • Overview - attaching a tag to an app.
  • Events - conversion labels in practice.