Technical

Allowed parameters

Also called captured query keys.

Allowed parameters is the list of query-string keys a collector agrees to store besides its built-in campaign tags. Any key not on the list is dropped from the recorded URL before it is saved.

How it is measured

It is a setting, not a count. You observe it by loading a test URL such as `/pricing?utm_source=news&plan=team&email=a@b.co` and reading the stored URL in the dashboard or the raw event. Keys on the list survive; the rest disappear.

The network tab is the place to confirm it. Find the POST to the collector and read its `url` field. If `email` shows up there, the stripping is happening too late, on the server, after the browser already sent it.

Worked example

A WordPress shop sees `/shop/?orderby=price&filter_color=red&session=9f2c71` in the address bar. The allow-list holds `orderby` and `filter_color`. The stored path becomes `/shop/?orderby=price&filter_color=red`, and the `session` key, a login token from a plugin, never leaves the browser.

Three weeks later someone adds `s`, WordPress search, to the list. The report now shows 'running shoes' next to 'my name is jane doe' as stored text. They remove the key and ask for the affected rows to be purged.

How it differs

Allowed parameters decides which keys the collector keeps. A query parameter is the key=value pair that sits in the URL whether or not anyone records it. The list excludes every key you did not name, including ones you never knew existed.

Common errors

Allowing `token`, `email`, or `code` because they look useful. Allowing a key that carries a unique value per click, so one page turns into thousands of rows. Forgetting that matching is case sensitive. Adding a key and expecting old rows to change. Assuming the list also cleans the Referer header.

In practice

Export your top 50 stored URLs and read them for anything personal. Keep the list short: sort, filter, page, and the few keys that change what the page shows. Review it whenever a plugin or ad tool starts appending a new key.

See also

Query parameter, UTM parameter, Pageview

Sources

Count this on a real site.

Watch my website