Checklist
Does Meta CAPI still fire after Reject All?
Reject All left a store's Meta Pixel quiet. _fbp stayed and was still sent to a first-party server endpoint. The browser cannot see CAPI. Not legal advice.
In brief
Reject All on a cookie banner is a browser choice. Meta CAPI runs on a server. A quiet Pixel does not tell you whether CAPI stopped. On 2026-10-05, Store A's US session sent zero requests to Meta hosts. The pre-click _fbp stayed, and a first-party collector still received it after Reject with ad_storage update:false. The browser cannot show whether CAPI fired or stayed off. This page is not legal advice.
Not legal advice
This page explains how to observe whether Meta-related identifiers and server-bound data keep moving after a browser Reject All. It is not legal advice, not a Meta Ads or CAPI setup guide, not a Shopify webhook tutorial, and not a ruling on any store or server event. ConsentProbe reports show Network rows, cookies, and storage on labeled visits. They do not show Meta's servers, a store's server container, or app webhook logs. Observation is not counsel permission.
Last updated October 5, 2026. Before-Accept Meta, server-side GTM, Reject leftovers, and cookie clearing stay on their own pages. This page covers a quiet Pixel after Reject All.
Short answer
Reject All on a cookie banner is a browser choice. Meta CAPI runs on a server. A quiet Pixel does not tell you whether CAPI stopped. On 2026-10-05, Reject All on Store A left zero requests to Meta hosts. The pre-click _fbp kept the same value and was still posted to a first-party collector with ad_storage update:false. Whether CAPI forwarded that ID is not in the browser log.
Compare the Reject time with the server event time. In this capture _fbp outlived Reject All. Server-side CAPI events commonly send that value as fbp for matching. Check Events Manager Test Events or the server container log for the same minutes. Meta's Conversions API end-to-end guide tells implementers to apply the same consent decision to CAPI as to the Pixel. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe does not install a CMP.
What the 2026-10-05 sessions showed
Both visits used Chrome Incognito, a fresh profile, Preserve log, Disable cache, and a US exit in Illinois. One session per store. They do not describe Shopify stores in general.
Store A runs Shopify with OneTrust. The first layer showed Manage Preferences, Accept Cookies, Reject All, and a close control. The homepage loaded at 03:00:15 UTC (11:00:15 CST) with no clicks. At 03:00:16 UTC a Shopify web pixel of type facebook_pixel loaded its sandbox. At 03:00:19 UTC (11:00:19 CST) a first-party _fbp was created before any click. The capture has no Set-Cookie for it, so a script wrote it. The script is not identified. _fbc was absent.
At 03:00:20 UTC, POST /a/elevar/browser/bulk returned 204. The body was event dl_user_data, included marketing._fbp, and set consent_v2.ad_storage to default true. That flag is the US-baseline state before a choice. Do not read it as an EU opt-in failure. Shopify consentManagement GraphQL then sent marketing false and analytics true. OtAutoBlock.js listed connect.facebook.net/en_US/fbevents.js under category C0004.
Reject All was clicked at 03:01:52.759 UTC (11:01:52 CST). At 03:01:52.805 UTC, POST /api/unstable/graphql.json sent marketing false, analytics false, preferences true, and saleOfData false. OneTrust groups were C0003:1, C0001:1, C0004:0, and C0002:0. At 03:02:32.601 UTC (11:02:32 CST), after another page load, POST /a/elevar/browser/bulk returned 204 again and still carried marketing._fbp. ad_storage was default true and update false. ad_user_data was update false.
None of the 1,508 request URLs match facebook.com, facebook.net, fbcdn, or /tr, so fbevents.js was never fetched. Web-pixel sandbox iframes fell from about 22 to 6 after Reject. _fbp was still there, same value.
Store B had no banner click. Its US first layer showed Preferences and Accept, with no Reject button. Preferences stayed closed. The HTML contained a Reject all label for that popup. At 02:57:58 UTC (10:57:58 CST) a Shopify web pixel loaded fbevents.js. At 02:58:00 UTC the browser fetched signals/config from connect.facebook.net. At 02:58:02.618 UTC (10:58:02 CST) it POSTed a PageView to facebook.com/tr/ with ev=PageView, a=shopify_web_pixel, and fbp. _fbp was present. _fbc was absent.
Both HTML documents set facebookCapiEnabled to true. That value is only a configuration flag, and it is not a server event.
| UTC / CST | Store | Record |
|---|---|---|
| 03:00:19 / 11:00:19 | A | _fbp written before any click. No Set-Cookie. |
| 03:01:52 / 11:01:52 | A | Reject All. Marketing and analytics set to false. |
| 03:02:32 / 11:02:32 | A | Elevar bulk post still had _fbp. update false. |
| 02:58:02 / 10:58:02 | B | PageView on facebook.com/tr/ included fbp. No click. |
Browser view and server view
Store A sent zero requests to Meta hosts. After Reject, /a/elevar/browser/bulk still carried that _fbp.
| Layer | Visible after Reject | Not visible |
|---|---|---|
| Meta Pixel | Host requests. Store A had 0. | Server send to Meta |
| _fbp / _fbc | Kept, deleted, or rewritten. Store A kept _fbp. | Later server use |
| First-party collector | Body and consent label on /a/elevar/browser/bulk. | What that server forwards |
| CAPI flag | facebookCapiEnabled in the HTML. | Whether an event fired |
Reproduce it in DevTools
One fresh profile. These steps do not configure CAPI.
- Open Incognito and DevTools before the URL. In Network, turn on Preserve log and Disable cache.
- Load the store without clicking the banner. Filter facebook, then /tr. Note fbevents.js, signals/config, and facebook.com/tr, with times.
- Under Application, Cookies, filter _fb and record _fbp. The middle number is the creation time in milliseconds.
- Click Reject All. Do not close the banner or click Accept. Note the time. OneTrust stores it as datestamp.
- Reload, open one more page, and repeat the filters. Search Network for the _fbp value. If payload search is missing, export the HAR and search the file.
- Check Cookies for _fbp again.
- Open Events Manager Test Events or the server container preview for those minutes. Compare event_name, fbp, and event_id.
- Write the Reject time, browser Meta requests after it, whether _fbp stayed, and server events for that fbp, naming the log.
- After a fix, rerun the same URL and the same consent state.
What the browser cannot show
We did not observe CAPI after Reject, either firing or staying off. The browser cannot see CAPI. DevTools does not show a server request to Meta from CAPI, Signals Gateway, or an app webhook.
We do not know what Elevar's server does with ad_storage update:false. It may drop the event, strip fbp, or forward it. Only server logs or Events Manager can show which. event_id deduplication, another region, and another session are outside this capture.
facebookCapiEnabled set to true is only a configuration flag. It is not a server event. A free US-baseline scan is not an EU or California legal conclusion.
Check the browser half
Run Fresh and Reject for the browser half. ConsentProbe records Pixel rows, whether _fbp remains, and first-party collector posts. It does not replace Meta server logs. ConsentProbe does not install a CMP.
FAQ
Does Reject All stop Meta CAPI?
Only if the server path reads the consent state and refuses to send. The browser cannot confirm that.
The Pixel is quiet but Events Manager is busy. Is that possible?
Yes. The browser can stop calling Meta while a server can keep sending events keyed on the same _fbp.
Does Reject All delete _fbp?
Not in the session we captured. The value set before any click was unchanged after Reject. The cookie-clearing guide covers cookies that survive the click.
Is this the same page as Meta Pixel and CAPI before Accept?
No. That guide is the check before Accept. This page is after Reject All, when the choice may not have reached the server.
Can ConsentProbe see CAPI?
It sees the browser half, including first-party collector posts. Server logs are separate.
Is this legal advice?
No. It is not legal advice. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.
Limits of this page
Each store is one US session, so these visits do not describe Shopify stores in general. The browser cannot see CAPI. facebookCapiEnabled is only a configuration flag, and what the server does with update:false is unknown. A US default-granted state is not an EU opt-in failure. It is not legal advice. Observation is not counsel permission. ConsentProbe does not install a CMP.
Related guides
Next checks are the before-Accept Meta guide, Reject leftovers, server-side GTM, the marketing-pixels FAQ, cookie clearing, and the evidence pack.
- Meta Pixel and CAPI before Accept
- Reject All still tracking
- Do Server-Side GTM tags fire before Accept?
- Does Reject All stop marketing pixels?
- Does Reject All clear cookies already set?
- Cookie consent evidence pack
- Re-test after a GPC or Reject All fix
- Shopify pre-consent checklist
- CMP claims vs runtime evidence
- Free US-baseline vs paid EU and California
- Cookie audit product: what ConsentProbe records before Accept
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
Save a US-baseline technical record
After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.