xConnect: Rapid Interaction Spoofing and Contact Identification

Cover Image for xConnect: Rapid Interaction Spoofing and Contact Identification

When you're testing contact sessions and contact identification, you don't want to wait for sessions to end on their own; it's too slow. We are going to set up a handful of bookmarkable API GET endpoints so you can rapidly start a session, identify as a specific contact, viw the current session data, and end the session so that the data is written to the database immediately instead of having to wait.

Endpoints for Ending Sessions and Viewing Session Data


using Sitecore.Analytics;
using Sitecore.Diagnostics;
using System.Web.Mvc;
namespace Client.Foundation.xConnectPoc.Controllers
public class VisitController : Controller
public JsonResult Data()
var currentTracker = Tracker.Current;
var data = currentTracker.Interaction.ToVisitData();
return Json(data, JsonRequestBehavior.AllowGet);
public JsonResult End()
Log.Info("Closing xDB session", this);
return Json(new { Message = "xDB Session Closed" }, JsonRequestBehavior.AllowGet);


using System.Web.Mvc;
using System.Web.Routing;
using Sitecore.Pipelines;
namespace Client.Foundation.xConnectPoc.Pipelines.Initialize
public class InitializeRoutes : Sitecore.Mvc.Pipelines.Loader.InitializeRoutes
public override void Process(PipelineArgs args)
"VisitData", // Route name
new { controller = "Visit", action = "Data" },
new[] { "Client.Foundation.xConnectPoc.Controllers" });
new { controller = "Visit", action = "End" },
new[] { "Client.Foundation.xConnectPoc.Controllers" });


<configuration xmlns:patch="http://www.sitecore.net/xmlconfig/">
<!-- Only enable this in test environments -->
<processor type="Client.Foundation.xConnectPoc.Pipelines.Initialize.InitializeRoutes, Client.Foundation.xConnectPoc" patch:before="processor[@type='Sitecore.Mvc.Pipelines.Loader.InitializeRoutes, Sitecore.Mvc']"/>

Now we need to set up the logic to get or set the contact and populate its fields. Getting or setting the contact also implies that we need to support contact identification. Modify the code below to suit your needs.


using Sitecore.Analytics;
using Sitecore.Analytics.Model;
using Sitecore.Analytics.Model.Entities;
using Sitecore.Analytics.Pipelines.CreateVisits;
using Sitecore.XConnect;
using Sitecore.XConnect.Client;
using Sitecore.XConnect.Collection.Model;
using System.Linq;
using System.Net;
namespace Client.Foundation.xConnectPoc.Pipelines.CreateVisit
public class SpoofVisit : CreateVisitProcessor
public override void Process(CreateVisitArgs args)
// We're using an email in the query string as the primary identification mechanism
var email = args.Request.Params["email"];
if (string.IsNullOrWhitespace(email))
var firstName = args.Request.Params["firstName"];
var lastName = args.Request.Params["lastName"];
// IP address info, if you want
if (!string.IsNullOrWhitespace(args.Request.Params["geoIp"]))
var geoip = args.Request.Params["geoIp"];
var ipAddress = IPAddress.Parse(geoIp);
args.Interaction.Ip = ipAddress.GetAddressBytes();
args.Session.IdentifyAs("Email", email);
var manager = Sitecore.Configuration.Factory.CreateObject("tracking/contactManager", true) as Sitecore.Analytics.Tracking.ContactManager;
if (manager == null)
if (Tracker.Current.Contact.IsNew)
// Save contact to xConnect; at this point, a contact has an anonymous
// TRACKER IDENTIFIER, which follows a specific format. Do not use the contactId overload
// and make sure you set the ContactSaveMode as demonstrated
Tracker.Current.Contact.ContactSaveMode = ContactSaveMode.AlwaysSave;
// Now that the contact is saved, you can retrieve it using the tracker identifier
var trackerIdentifier = new IdentifiedContactReference(Sitecore.Analytics.XConnect.DataAccess.Constants.IdentifierSource, Tracker.Current.Contact.ContactId.ToString("N"));
// Get contact from xConnect, update and save the facet
using (XConnectClient client = Sitecore.XConnect.Client.Configuration.SitecoreXConnectClientConfiguration.GetClient())
var contact = client.Get(trackerIdentifier, new Sitecore.XConnect.ContactExpandOptions());
if (contact == null)
// Handle it
client.SetFacet(contact, PersonalInformation.DefaultFacetKey, new PersonalInformation()
FirstName = firstName,
LastName = lastName
var emails = new EmailAddressList(new EmailAddress(email, true), "Home");
client.SetFacet(contact, emails);
// Remove contact data from shared session state - contact will be re-loaded
// during subsequent request with updated facets
Tracker.Current.Session.Contact = manager.LoadContact(Tracker.Current.Contact.ContactId);
catch (XdbExecutionException ex)
// Manage conflicts / exceptions
Sitecore.Diagnostics.Log.Error(ex.Message, ex, this);
var anyIdentifier = Tracker.Current.Contact.Identifiers.FirstOrDefault();
// Get contact from xConnect, update and save the facet
using (XConnectClient client = Sitecore.XConnect.Client.Configuration.SitecoreXConnectClientConfiguration.GetClient())
var contact = client.Get(new IdentifiedContactReference(anyIdentifier.Source, anyIdentifier.Identifier), new ContactExpandOptions(PersonalInformation.DefaultFacetKey));
if (contact == null)
// Handle it
if (contact.Personal() != null)
if (!string.IsNullOrEmpty(firstName))
contact.Personal().FirstName = firstName;
if (!string.IsNullOrEmpty(lastName))
contact.Personal().LastName = lastName;
client.SetFacet(contact, PersonalInformation.DefaultFacetKey, contact.Personal());
client.SetFacet(contact, PersonalInformation.DefaultFacetKey, new PersonalInformation()
FirstName = firstName,
LastName = lastName
var emailAddressList = contact.GetFacet<EmailAddressList>(EmailAddressList.DefaultFacetKey);
if (emailAddressList != null)
// Change facet properties
emailAddressList.PreferredEmail = new EmailAddress(email, true);
emailAddressList.PreferredKey = "Home";
// Set the updated facet
client.SetFacet(contact, EmailAddressList.DefaultFacetKey, emailAddressList);
// Facet is new
var emails = new EmailAddressList(new EmailAddress(email, true), "Home");
client.SetFacet(contact, EmailAddressList.DefaultFacetKey, emails);
// Remove contact data from shared session state - contact will be re-loaded
// during subsequent request with updated facets
Tracker.Current.Session.Contact = manager.LoadContact(Tracker.Current.Contact.ContactId);
catch (XdbExecutionException ex)
// Manage conflicts / exceptions
Sitecore.Diagnostics.Log.Error(ex.Message, ex, this);


<configuration xmlns:patch="http://www.sitecore.net/xmlconfig/">
<!-- Make sure to disable this in PROD -->
<processor type="Client.Foundation.xConnectPoc.Pipelines.CreateVisit.SpoofVisit, Client.Foundation.xConnectPoc" patch:after="processor[@type='Sitecore.Analytics.Pipelines.CreateVisits.XForwardedFor, Sitecore.Analytics']" />

I also found a browser extension for analytics testing that may be worth trying out.

Keep on building,


More Stories

Cover Image for On Mentorship and Community Contributions

On Mentorship and Community Contributions

> Reflections and what I learned as an MVP mentor

Cover Image for On Sitecore Stack Exchange (SSE)

On Sitecore Stack Exchange (SSE)

> What I've learned, what I see, what I want to see

Cover Image for Critical Security Bulletin SC2024-001-619349 Announced

Critical Security Bulletin SC2024-001-619349 Announced

> And other scintillating commentary

Cover Image for Azure PaaS Cache Optimization

Azure PaaS Cache Optimization

> App Services benefit greatly from proper configuration

Cover Image for Troubleshooting 502 Responses in Azure App Services

Troubleshooting 502 Responses in Azure App Services

> App Services don't support all libraries

Cover Image for JSS + TypeScript Sitecore Project Tips

JSS + TypeScript Sitecore Project Tips

> New tech, new challenges

Cover Image for Symposium 2022 Reflections

Symposium 2022 Reflections

> Sitecore is making big changes

Cover Image for Ideas For Docker up.ps1 Scripts

Ideas For Docker up.ps1 Scripts

> Because Docker can be brittle

Cover Image for Year in Review: 2022

Year in Review: 2022

> Full steam ahead

Cover Image for How to Run Old Versions of Solr in a Docker Container

How to Run Old Versions of Solr in a Docker Container

> Please don't make me install another version of Solr on my local...

Cover Image for On Sitecore Development

On Sitecore Development

> Broadly speaking

Cover Image for NextJS/JSS Edit Frames Before JSS v21.1.0

NextJS/JSS Edit Frames Before JSS v21.1.0

> It is possible. We have the technology.

Cover Image for NextJS: Unable to Verify the First Certificate

NextJS: Unable to Verify the First Certificate


Cover Image for SPE Script Performance & Troubleshooting

SPE Script Performance & Troubleshooting

> Script never ends or runs too slow? Get in here.

Cover Image for Security Series: App Service IP Restrictions

Security Series: App Service IP Restrictions

> How to manage IP rules "at scale" using the Azure CLI

Cover Image for Content Editor Search Bar Not Working

Content Editor Search Bar Not Working

> Sometimes it works, sometimes not

Cover Image for Sitecore Symposium 2022

Sitecore Symposium 2022

> What I'm Watching 👀

Cover Image for Tips for New Sitecore Developers

Tips for New Sitecore Developers

> If I had more time, I would have written a shorter letter

Cover Image for Super Fast Project Builds with Visual Studio Publish

Super Fast Project Builds with Visual Studio Publish

> For when solution builds take too long

Cover Image for Tips for Forms Implementations

Tips for Forms Implementations

> And other pro tips

Cover Image for Add TypeScript Type Checks to RouteData fields

Add TypeScript Type Checks to RouteData fields

> Inspired by error: Conversion of type may be a mistake because neither type sufficiently overlaps with the other.

Cover Image for Tips for Applying Cumulative Sitecore XM/XP Patches and Hotfixes

Tips for Applying Cumulative Sitecore XM/XP Patches and Hotfixes

> It's probably time to overhaul your processes

Cover Image for JSS: Reducing Bloat in Multilist Field Serialization

JSS: Reducing Bloat in Multilist Field Serialization

> Because: performance, security, and error-avoidance

Cover Image for Hello World

Hello World

> Welcome to the show

Cover Image for NextJS: Short URL for Viewing Layout Service Response

NextJS: Short URL for Viewing Layout Service Response

> Because the default URL is 2long4me

Cover Image for Don't Ignore the HttpRequestValidationException

Don't Ignore the HttpRequestValidationException

> Doing so could be... potentially dangerous

Cover Image for Script: Boost SIF Certificate Expiry Days

Script: Boost SIF Certificate Expiry Days

> One simple script that definitely won't delete your system32 folder

Cover Image for Early Returns in React Components

Early Returns in React Components

> When and how should you return early in a React component?

Cover Image for NextJS: Access has been blocked by CORS policy

NextJS: Access has been blocked by CORS policy

> CORS is almost as much of a nuisance as GDPR popups