Use the correct web or app identifiers, client_id or app_instance_id, and a server-held API secret. Session association and backdated events have additional requirements and time limits.
The validation endpoint checks requests but does not collect events. Validate the request and verify actual ingestion separately.
