Docs menu · API reference

Docs / COD Order Protection

COD Order Protection

API reference: hold and webhook

The endpoints, headers and payloads, for stores and systems calling PixelFly directly.

POST https://<your-tracking-domain>/cod/hold    (header X-PF-Key: pf_live_…)
POST https://<your-tracking-domain>/cod/webhook (header X-Webhook-Secret: pfwh_…)

Your tracking domain is your sGTM domain or custom domain; proxy containers without one use https://track.pixelfly.io. Browser tags can also call GET /cod/hold?k=<API Key>&d=<URL-encoded JSON>. If PixelFly is briefly unreachable the Worker queues the request and answers 202 {"action":"queued"}.

{
  "order_id": "12345",
  "event_time": 1699012345,
  "value": 1500.00,
  "currency": "BDT",
  "payment_method": "cod",
  "email": "customer@example.com",
  "phone": "01712345678",
  "name": "Rina Begum",
  "fbp": "fb.1....", "fbc": "fb.1....",
  "gclid": "CjwK...", "ga_client_id": "1234567890.1790000000", "ga_session_id": "1790933629",
  "contents": [{ "item_id": "101", "item_name": "Product", "price": 750, "quantity": 2 }]
}

Confirming an order that was never held? Send value and currency with the webhook (plus email / phone if you have them); without them nothing is sent and the order waits as missing purchase data.

We use cookies to enhance your experience, analyze site traffic, and for marketing purposes. By continuing to use our site, you consent to our use of cookies. Learn more