Skip to main content
Back to Blog

Taboola Conversions API Setup: S2S Postback Without Code

Set up the Taboola Conversions API (S2S postback) with no code. Create the Realize conversion, connect SignalBridge, and verify in minutes. Start free.

19 min read
Taboola Conversions API Setup: S2S Postback Without Code

Key Takeaways

  • •The "Taboola Conversions API" is Taboola Realize's server-to-server (S2S) tracking: a GET postback to trc.taboola.com/actions-handler/log/3/s2s-action, or a bulk POST of up to 1,000 conversions — authenticated by the Taboola click ID, not by an API key
  • •Taboola appends the click ID to your landing page as tblci, but the postback parameter must be named click-id (with a hyphen), and the event name must match the Realize Event Name exactly — otherwise the conversion is silently ignored
  • •Per Taboola's deduplication rules, when the pixel and S2S report the same event for the same Click ID, the S2S event is kept — so running both is safe, and Taboola recommends it for the most complete data
  • •You can run Taboola S2S with no code in about 3 minutes: create the conversion in Realize, connect Taboola in SignalBridge, then verify with Realize's Test Events → Server Events tool
  • •SignalBridge queues every Taboola conversion in a durable outbox, retries 408, 429 and 5xx responses with exponential backoff (30 seconds up to 6 hours), and counts only HTTP 204 as delivered

What is the Taboola Conversions API?

The Taboola Conversions API is the name advertisers use for Taboola Realize's server-to-server (S2S) conversion tracking. Instead of a browser pixel, your server — or a tool like SignalBridge — sends each conversion to Taboola with the click ID, using a GET postback or a bulk POST of up to 1,000 conversions. No API key is required.

Taboola's own documentation calls the two delivery methods the S2S postback URL and bulk S2S conversions. Third-party vendors such as Hightouch label the bulk endpoint the "Taboola Conversions API", and that is how many advertisers search for it. They all describe the same mechanism:

Name you will seeWhat it actually isEndpoint
Taboola Conversions APICommon industry name for Taboola's S2S trackingEither endpoint below
S2S postback URLOne GET request per conversionhttps://trc.taboola.com/actions-handler/log/3/s2s-action
Bulk S2S conversionsOne POST with up to 1,000 conversionshttps://trc.taboola.com/{account-id}/log/3/bulk-s2s-action
Taboola PixelBrowser JavaScript (the thing S2S complements)cdn.taboola.com/libtrc/unip/.../tfa.js

This guide shows how to turn it on without writing code using SignalBridge's Taboola by Realize integration, and explains exactly what is happening underneath so you can debug it. If you want the developer-level deep dive on building your own postback endpoint, read our Taboola server-side tracking guide.


Why send Taboola conversions server-side?

Taboola's Realize platform optimizes bids on the conversions it can see. Its Maximize Conversions bidding, for example, "uses conversion data and behavioral signals to adjust bids in real time", according to Realize's El Corte Inglés case study. On the Q2 2026 earnings call, Taboola management described Realize+ as an AI optimization framework bringing the kind of automation advertisers expect from Google Performance Max and Meta Advantage+ to the open web, with more than 300 advertisers already in beta.

Every one of those systems is only as good as the conversion data it receives. A browser pixel cannot send what the browser blocks:

  • 1.1 billion people run ad blockers globally, about 30% of internet users, and 37% of US desktop users block ads (see our ad blocker statistics for 2026).
  • Native funnels often pass through advertorial or pre-sell pages and redirects, which is exactly where browser-side tracking and click IDs break.
  • Safari and Firefox restrict the cookies and scripts that browser-based attribution depends on.
  • Shoppers who pay through an external gateway often close the tab before the thank-you page, so the pixel never fires.

Server-side delivery removes the browser from the conversion path. Taboola recommends combining both methods: its conversion tracking overview states, "For more complete conversion data, use both pixel and S2S when possible." The same logic applies to every platform we support, from Meta CAPI to Google Enhanced Conversions.


Four ways to send Taboola conversions without writing code

"No code" means different things depending on the method. Here is how the realistic options compare:

MethodCode requiredSurvives ad blockersOngoing maintenanceCostBest for
Taboola Pixel (Shopify app, WooCommerce integration, codeless conversions)NoneNo — runs in the browserLowFreeBaseline coverage and retargeting audiences
Server-side GTM with a Taboola tag templateNo custom code, but you need a GTM server containerYesMedium — you host and monitor the containerServer hosting feesTeams already fluent in server GTM
Custom postback endpointYes — you build capture, storage, retriesYesHighDeveloper timeCustom stacks and CRM-based conversions
SignalBridgeNoneYesLow — managed deliveryFrom $29/moStores and lead-gen teams that want S2S running in minutes

Taboola's official Shopify app is its recommended way to install the browser pixel on Shopify, and we recommend keeping it. SignalBridge adds the server-side half. See our server-side tracking pricing comparison for how the managed options stack up on cost.


What the Taboola Conversions API needs before you start

Every working Taboola S2S setup depends on three things. Get these right and the rest is mechanical.

1. A valid click ID. Taboola automatically appends tblci={click_id} to every ad URL. The click ID is a case-sensitive string, typically 70 to 120 characters, and Taboola warns that "a truncated (or otherwise corrupted) value will be ignored." Redirects, link shorteners, and URL cleaners that rewrite query strings are the usual way it gets damaged.

2. An exact event name. The name you send must match the Event Name field of a conversion defined in Realize. Not the Conversion Name, which is just a label. Names are case-sensitive: lead and Lead are different events.

3. The parameter rename. Your landing page receives tblci, but the postback must send it back as click-id (with a hyphen). Taboola states the parameter "must be named click-id, exactly as shown. Otherwise, no conversions will be recorded."

If you use SignalBridge, point 3 is handled for you. Points 1 and 2 are covered in the steps below.


How to set up the Taboola Conversions API without code (6 steps)

These steps assume you already run campaigns in Realize. Total time is about 3 minutes once you have your Taboola API credentials.

Step 1: Create the conversions in Taboola Realize

In Realize, create one event-based conversion for each outcome you want Taboola to optimize toward:

  1. Open Realize and select your account (top left).
  2. In the left sidebar, choose Tracking.
  3. Click + New Conversion, select Create conversions using code, and click Continue.
  4. Enter a descriptive Conversion Name (for example, "Purchase"). This is only a label.
  5. Set Conversion Type to EVENT and leave Fixed Value blank for purchases, since the value is dynamic.
  6. Choose the Category and confirm the Event Name matches the table below.
  7. For purchases, keep both Include in total conversions and Include in total value checked. For soft events such as add to cart, clear Include in total value so they do not inflate reported revenue.
  8. Skip the Event Code section (that is the pixel snippet) and click Create.

Use this mapping so the names SignalBridge sends line up with your Realize conversions:

SignalBridge eventName sent to TaboolaRealize default Event NameWhat to do
Purchasemake_purchasemake_purchaseMatches out of the box
AddToCartadd_to_cartadd_to_cartMatches out of the box
InitiateCheckoutinitiate_checkoutstart_checkoutEdit the Event Name to initiate_checkout when creating the conversion
LeadleadleadMatches out of the box
CompleteRegistrationcomplete_registrationcomplete_registrationMatches out of the box
ViewContentview_contentview_contentMatches out of the box
AddPaymentInfoadd_payment_infoadd_payment_infoMatches out of the box
SearchsearchsearchMatches out of the box

The checkout row is the one that trips people up. Taboola's default Event Name for the Start Checkout category is start_checkout, while SignalBridge sends initiate_checkout. Realize lets you edit the Event Name when you create the conversion, so set it to initiate_checkout and the two sides match. SignalBridge supports 17 events in total; for any event without a Taboola preset (for example start_trial or schedule), create a conversion whose Event Name equals the name SignalBridge sends.

Step 2: Confirm the tblci click ID reaches your site

Click one of your Taboola ads (or use the test link from Step 5) and check that the landing page URL contains tblci= followed by a long string. Taboola adds this automatically, so no campaign setup is needed unless you changed the default.

Two rules keep the click ID intact:

  • Do not strip query parameters. If you use a redirect, advertorial page, or link shortener between Taboola and your store, make sure it forwards tblci unchanged.
  • Keep the default parameter name. Taboola lets you define a custom parameter such as tbl_click_id={click_id}, but SignalBridge's script captures the standard tblci parameter, so leave the default in place.

Step 3: Connect Taboola in SignalBridge

  1. Open your SignalBridge dashboard and go to Pixel Settings for your store.
  2. Find Taboola (labelled "S2S Conversion Tracking") in the integration catalog and click Connect Taboola.
  3. Enter your Client ID, Client Secret, and Account ID. These are your Taboola Backstage API credentials, available in your Taboola account settings or from your Taboola account manager. The Account ID looks like taboolaaccount-yourbrand.
  4. Click Connect. SignalBridge requests a token and checks that it can reach the account. A Connected badge confirms success.
  5. Click Test at any time. A healthy connection returns "Connection successful! Credentials valid and Backstage API accessible."

You may wonder why credentials are needed when the postback itself requires none. The S2S postback is unauthenticated, as Taboola's docs state. The credentials let SignalBridge validate that the account is yours and sync your Taboola ad spend, so you can see true CPA and ROAS next to your conversions. See the Taboola by Realize integration page for the full feature list.

Step 4: Add the tracking script and choose your lead event

If you have not installed SignalBridge yet, add the one-line tracking script (Shopify merchants can install from the Shopify App Store). The script captures tblci from the landing URL, stores it in a first-party cookie for 30 days, and includes it with your events.

Back in the Taboola card, use Lead event routing if you track lead-style actions. It lets you pick which Taboola event receives SignalBridge's lead-type events (Lead, CompleteRegistration, SubmitApplication, Contact, SignUp, Subscribe, StartTrial, Schedule). Choose the one that matches the conversion you created in Realize. If you run a single "Lead" conversion in Realize, route everything to lead.

Step 5: Verify with Realize's Server Events test tool

Never trust a configuration you have not seen working. Taboola ships a purpose-built S2S verification tool:

  1. In Realize, open Tracking, then the Test Events tab under Conversions.
  2. Expand Server Events and select a campaign.
  3. Click Generate QR Code. It adds a tblci test value to the URL.
  4. Scan the code with your phone (or open the test link on desktop) and complete the conversion on your store, such as a test purchase.
  5. Watch the Events Received panel on the right. Your event should appear within moments with the correct conversion name and no error icon.

If the event appears, your click ID, event name, and delivery are all correct.

Step 6: Decide how the pixel and S2S work together

Keep the Taboola Pixel installed. Taboola's deduplication rules make running both safe, and its tip is to install the base pixel "even when using S2S only for conversion tracking" because it helps Taboola optimize your campaigns. Then confirm each key conversion has Include in total conversions checked so Taboola's bidding optimizes toward it.


How Taboola deduplicates pixel and S2S events

The most common worry is double counting. Taboola handles it with a defined rule set, and only events from the same click are compared:

ScenarioWhat Taboola does
Same event, same Click ID, received via pixel and S2SThe S2S event is kept; the pixel event is deduplicated
Two identical S2S events, same Click ID and order ID, within one minuteThe second one is deduplicated
Same order ID but different Click IDsBoth are counted, because they are different user journeys

Taboola calls running both methods "dual-method tracking" and names it the best practice. It gives you redundancy: if the pixel is blocked, S2S still delivers; if both fire, S2S wins. Pass a unique orderid with every purchase so duplicates can be recognized. For the general theory behind this, see our guide to event deduplication.


What the raw postback looks like

You do not need to write this by hand with SignalBridge, but understanding it makes debugging far faster.

The single-conversion postback (GET)

GET https://trc.taboola.com/actions-handler/log/3/s2s-action?click-id=GiC3sJdfEHXrroWoRIMZNc-HmQGs4UllzePkXl8h7XSOfSDOqFUoqNjkqZDk_6u1ATCn214&name=make_purchase&revenue=89.50&currency=USD&orderid=ORD-10492

Note the /log/ segment in the path. It is part of Taboola's documented endpoint, and tutorials that omit it send requests to the wrong URL.

ParameterRequiredFormatNotes
click-idYesCase-sensitive string, about 70–120 charactersThe tblci value, unchanged
nameYesCase-sensitive stringThe Realize Event Name, not the Conversion Name
revenueNoInteger or decimalFor example 9.99
currencyNo3-letter code, case-sensitiveAccount default is used if omitted
quantityNoIntegerItems in the order
orderidNoStringYour order ID, used for deduplication

Taboola documents 19 supported currency codes: AUD, BRL, CAD, CNY, EUR, GBP, HKD, ILS, INR, JPY, KRW, MXN, NZD, RUB, SGD, THB, TRY, USD, and ZAR. If your store sells in another currency (for example CHF, SEK, PLN, DKK, or BGN), confirm with your Taboola account manager how revenue is handled before you rely on value-based bidding.

The bulk endpoint (POST)

High-volume advertisers can send up to 1,000 conversions per request. Note the hyphenated keys, the actions wrapper, and the millisecond timestamp:

POST https://trc.taboola.com/123456/log/3/bulk-s2s-action
Content-Type: application/json
{
  "actions": [
    {
      "timestamp": 1620723457405,
      "click-id": "GiCsfhikbv6Ov6YdzFR8_JyZp76Rxqey1Lu0AQ",
      "name": "make_purchase",
      "revenue": 54.0,
      "currency": "USD",
      "orderid": "ORD-101"
    }
  ]
}

The {account-id} in the path is your numeric Taboola Account ID, and no authentication header is sent.

Response codes

ResponseMeaningWhat to do
204 No ContentConversion receivedNothing
400Missing or misspelled click-id, unparsable click ID, missing name, or a misspelled endpointFix the request; retrying will not help
408, 429, 5xxTimeout, rate limit, or Taboola-side errorRetry with backoff
Bulk 204Only confirms Taboola received the batch; parameter values are not validated in bulk requestsAlways confirm in the Events Received panel

That last row matters: a bulk request can return 204 and still record nothing if the click ID is wrong. Taboola states that "at this time, the param values in bulk submit requests are not validated."


What SignalBridge does behind the scenes

Building these mechanics yourself is where S2S projects stall. Here is what the integration handles for you:

ConcernHow SignalBridge handles it
Click ID captureThe script reads tblci from the landing URL and persists it in a first-party cookie for 30 days, so it survives multi-session journeys
Click ID validationValues shorter than 50 characters, containing whitespace, or equal to null or undefined are rejected rather than sent as junk
Event mappingMaps 17 events to Taboola names (make_purchase, add_to_cart, lead, and so on) with revenue, currency, and order ID attached
ConsentForwards events to Taboola only when marketing consent allows ad-platform delivery
Durable deliveryEvery event is written to an encrypted outbox before delivery, so a Taboola outage cannot lose it
RetriesRetries 408, 429, and 5xx responses with exponential backoff from 30 seconds up to 6 hours, with jitter, and honors Taboola's Retry-After header
Success criteriaOnly HTTP 204 counts as delivered
Unknown outcomesIf a request is sent but no response is observed, the event is parked rather than blindly replayed, because replaying could double-count
Bad eventsRequests Taboola rejects as invalid are set aside instead of retried forever

Pair this with bot filtering so fake sessions never become conversion signals. Native placements attract more non-human traffic than most channels, and an optimizer trained on bot conversions buys more bot traffic.


Troubleshooting: conversions appear in SignalBridge but not in Taboola

Work down this table in order. The first three causes account for the large majority of failures.

SymptomLikely causeFix
Conversion shows No Activity in RealizeEvent Name mismatch (case, underscores, or the start_checkout vs initiate_checkout gap)Compare the Realize Event Name with the name SignalBridge sends, character by character
Test Events shows an error icon or nothingWrong parameter name: tblci= was sent instead of click-id=Use click-id (with a hyphen) in the postback
Some clicks convert, others never doClick ID was truncated or rewritten by a redirect or link shortenerMake the landing flow forward tblci unchanged
Only some orders reach TaboolaS2S can only report conversions that came from a Taboola clickExpected: organic and other-channel orders have no tblci
Revenue is zero or missing in RealizeCurrency not in Taboola's documented list, or Include in total value is uncheckedCheck the currency and the conversion's checkbox settings
Bulk request returns 204 but nothing recordsBulk requests do not validate valuesTest one record through the single postback first
Events stop after a consent bannerMarketing consent was denied, so ad-platform forwarding is blocked by designVerify your consent setup
Needs Reconnect badge in SignalBridgeTaboola API token could not be acquiredClick Reconnect and re-enter your credentials

Remember the attribution window too. Conversions outside the Click Through Conversion Window configured on the Realize conversion are not credited to the click.


Measuring the impact on Taboola performance

Do not judge the setup by raw conversion counts alone. Compare these over two to four weeks:

  1. Taboola-reported conversions vs. your order system. Compare what Realize reports with your own count of orders that came from Taboola clicks. A persistent gap signals a click ID or event-naming problem.
  2. CPA and ROAS trend. More complete conversion data should lower reported CPA, because Taboola is now seeing sales it previously missed. Your true ROAS should stay flat; reported ROAS should converge on it.
  3. Monthly spot checks. Run the Server Events test once a month, and again after any theme, redirect, or checkout change, so a broken click ID is caught in days rather than quarters.

If Taboola is an assist channel in your funnel rather than a last-click winner, also review assisted conversions before you judge its value.


FAQ

Does Taboola have a Conversions API?

Yes, but Taboola calls it server-to-server (S2S) tracking. Advertisers send conversions through either a GET postback URL or a bulk endpoint that accepts up to 1,000 conversions per request. Third parties often label the bulk endpoint the "Taboola Conversions API". Neither method uses an API key; the Taboola click ID attributes each conversion.

What is the Taboola S2S postback URL?

The postback URL is https://trc.taboola.com/actions-handler/log/3/s2s-action, called with the query parameters click-id and name (both required) plus optional revenue, currency, quantity, and orderid. A successful request returns HTTP 204. Note the /log/ segment, which some older tutorials omit.

Why does Taboola use tblci in the URL but click-id in the postback?

Taboola appends the click ID to your landing page as tblci, but the S2S API expects the same value under the name click-id, with a hyphen. If you send tblci= in the postback, no conversion is recorded. SignalBridge performs this rename automatically.

Can I set up the Taboola Conversions API without code?

Yes. Create the event-based conversion in Realize, connect Taboola in SignalBridge with your Client ID, Client Secret, and Account ID, and verify the result in Realize's Test Events tool. The whole process takes about 3 minutes, and no theme edits or developer work are required.

Do I still need the Taboola Pixel if I use S2S?

Taboola recommends using both. Its documentation advises installing the base pixel even when S2S handles conversion tracking, because the pixel helps Taboola optimize campaigns. If both report the same event for the same Click ID, Taboola keeps the S2S event and deduplicates the pixel event.

How do I know the Taboola S2S integration is working?

Use the Server Events tool in Realize under Tracking, then Test Events. Generate the QR code, complete a test conversion, and confirm the event appears in the Events Received panel with the right conversion name and no error icon. Do not rely on a 204 response alone, especially for bulk requests.

Does the Taboola Conversions API work with Shopify?

Yes. Keep Taboola's official Shopify pixel app for browser-side coverage and add SignalBridge for the server-side half. Purchase events are sent with revenue, currency, and order ID, and the two methods deduplicate on the Taboola side.


Ready to recover more conversions?

Start tracking what your pixels miss. Set up in 5 minutes, no credit card required.

Start Free Trial