Authorization: Bearer <access_token> and JSON. Never place OAuth credentials in browser code. Both permissions are required: link el cdp behavior identity AND restful post el_cdp_api_customer_resource. Domain registration gates browser collection, not this authenticated server API.source=web, visitor_id, identifications, body; total body at most 8192 bytes. Identities: list of 1–20 non-empty string key/value pairs using configured identity definitions. body must be a non-empty object using configured customer-property IDs. Unknown profile properties are filtered by the shared Customer API; known invalid identity/property values return 400. session_id, request customer_id/customer_uuid, singular identification, and content_tag_ids are unsupported top-level fields. No public auto_merge/allow_empty switches: the service fixes automatic merging and empty-value overwrites to false. Profile values do not become verified identities merely by appearing in body.(source,visitor_id) is durable across domains and raw-event cleanup; one customer can have multiple visitor links. Backend UUID checks prevent an old numeric customer ID from silently attaching to a different customer after an ID reset. Customer merging follows the normal merge-target resolution.{code:200,data:{...}} envelope: encoded customer_id, linked=true, plus the shared Customer API save result (is_new, new/conflicting identifications, merged_customer_ids). Errors use {code,message} and optional structured errors. 400 invalid input/profile; 401 missing/invalid authentication; 403 insufficient permission; 409 visitor association conflict/unavailable target; 413 more than 8 KiB; 429 configured global versioned-API concurrency protection; 500 unexpected failure, including a visitor-lock timeout. Framework-level media-type/JSON routing errors may be returned before the resource runs.link el cdp behavior identity 和 restful post el_cdp_api_customer_resource 两项权限。网站域名登记用于浏览器采集入口,不作为此后端 API 的认证条件。source=web、visitor_id、identifications、body,请求最多 8192 字节。身份列表 1–20 项,每项 key/value 为非空字符串并使用已配置的身份定义;body 是非空客户属性对象。未知客户属性由现有客户 API 过滤,已知身份/属性值无效返回 400。body 中的手机号、邮箱不会仅因提交而自动成为已验证身份。不支持 session_id、请求客户 ID/UUID、单数 identification、内容标签字段,也没有自动合并/空值覆盖选项;两项行为均固定关闭。(source,visitor_id) 关联长期保留,可跨已登记网站;同一客户可有多个访客关联。服务内部保存客户 UUID 防止 ID 重用误关联,正常合并时解析当前目标客户。返回 200 只确认资料写入及关联成功,不代表历史事件已经转化。