You rarely write this request by hand: the browser script sends it. Installing the script is JavaScript (w.js). If you build your own sender, follow the payload rules below.
Endpoint
https://app.tapcub.com/api/v1/pulse Collect browser events
Public collector endpoint (proxied to the collector, not the API process). Always responds 202. Structural rejects (bad JSON, missing v/s/t, non-http(s) u, t=id without a known op, t=ac without a known k) are silent: the status stays 202 and the body is empty. A pageview may return a tracker config JSON body (Content-Type application/json); other accepts have an empty body. A batch is a raw array (at most 50 items; extras are dropped) or { sent, items }. There is no API key: the site is s (site key) on each item.
Request body application/jsonrequired
Responses
- 202Accepted. Body is empty, or a tracker config object when a pageview produced one.
Response fields 202
tintegerCollection tier for this request
123
cintegerLoad the chat script
1
xintegerLoad the identity extension
1
iintegerIdentified mode
1
aintegerAutocapture
1
hintegerHold events until identified
1
cnintegerChina mode echo for app SDKs
1
aoobjecttextbooleansamplenumberdenystring[]formsbooleanscrollbooleanflushintegerbatchintegerisstringIdentity source
csobjectreqbooleanpurposesstring[]prestringverstringcnintegerrejintegerrcobjectNon-default remote config for non-web SDKs
rpobjectSession replay: s sample percent, u script URL
snumbermtintegermiintegerustringexstring[]Responses carry Cache-Control: no-store. Besides structural errors, an unknown or paused site, a banned IP or site key, and a rate limit also return 202 with an empty body; the event is dropped and counted. The body limit is 64 KB. A larger body is rejected by the framework before the handler runs (413).
A batch wrapper with a send time:
{ "sent": 1759363200123, "items": [ { "v": 1, "s": "site-key", "t": "pv", "u": "https://example.com/" } ] }sent is the client send time in milliseconds. It is used with each item's ts to correct the clock. A skew over 24 hours falls back to arrival time.
Payload rules
The field table comes from the contract. These rules decide whether an item is kept:
vis1or2.did,sid,mid, andtsare used by version 2.t=evneeds an event name inn.t=idneeds a legalop.t=acneeds a legalk.pholds flat properties. Values are string, number, or boolean.- Over-long optional fields are truncated or downgraded and the item is kept. One bad optional field does not drop the event.
The body returned for the first pv is config JSON with short keys. The script uses it to decide whether to load identity, consent, and replay. It is not the data envelope used by open queries.
Config
https://app.tapcub.com/api/v1/pulse/cfg Fetch collector config
Public. SDK init reads the site config. Does not write an event. s is the site key (8–32 characters). pt is an optional SDK platform; omitted means web. Unknown, paused, or unavailable sites return 404 with an empty body. The JSON is a TrackerCfg; a web site with nothing to extend may still return { t }.
Query parameters2
sstringrequiredSite key.
ptstringSDK platform. Unknown values are treated as web.
webmp_weixinmp_alipaymp_bytedancemp_baidump_kuaishou
Responses
- 200Tracker config
- 404Unknown or paused site, or the collector cannot answer. Empty body.
Response fields 200
tintegerCollection tier for this request
123
cintegerLoad the chat script
1
xintegerLoad the identity extension
1
iintegerIdentified mode
1
aintegerAutocapture
1
hintegerHold events until identified
1
cnintegerChina mode echo for app SDKs
1
aoobjecttextbooleansamplenumberdenystring[]formsbooleanscrollbooleanflushintegerbatchintegerisstringIdentity source
csobjectreqbooleanpurposesstring[]prestringverstringcnintegerrejintegerrcobjectNon-default remote config for non-web SDKs
rpobjectSession replay: s sample percent, u script URL
snumbermtintegermiintegerustringexstring[]Writes no event, reads no device data, and stores nothing. It only returns the compliance tier for the IP country.
Related routes
Rates are on Rate limits. Replay chunks use a different route, POST /api/v1/replay: 204 when accepted, or 200 with {"stop":1} when the session is over quota or replay is off.
Point the script at the collection host shown in the console's install snippet.