Send conversions with an S2S postback
Report each conversion to Affilinext from your server so publishers get credited.
When a visitor arrives from an Affilinext tracking link, the landing URL carries a unique click ID. Store it, and when that visitor converts, call the Affilinext postback URL with the same click ID.
1. Capture the click ID
Your account manager sets your offer URL so that Affilinext appends the click ID, for example:
https://shop.example.com/landing?aff_click_id={click_id}Save the value (in a cookie, session or your order record) so you still have it when the conversion happens.
2. Call the postback URL
Your network gives you the exact URL to use. It looks like this:
https://click.affilinext.com/postback?click_id=CLICK_ID&txid=ORDER_ID&revenue=49.90¤cy=USD&event=sale&status=approved&token=YOUR_TOKEN| Parameter | Required | Meaning |
|---|---|---|
click_id | Yes* | The click ID you captured. |
txid | Recommended | Your order or transaction ID. Prevents duplicates. |
revenue | Optional | Sale amount. |
payout | Optional | Amount you pay for this conversion, if it varies. |
currency | Optional | ISO code, e.g. USD, EUR, INR. |
event | Optional | Goal name, e.g. install, lead, sale. |
status | Optional | approved (default), pending or rejected. |
token | Yes | Your security token. Keep it secret. |
\*For coupon or influencer campaigns without a click, send coupon=CODE instead of click_id.
Both GET and POST requests work.
3. Check the response
A 201 response means the conversion was recorded. A 200 means that txid was already recorded: "status": "duplicate" (nothing changed) or "updated" (you sent a new status or amount). Other responses tell you what went wrong:
| Code | Meaning |
|---|---|
400 | A required value is missing or invalid. |
401 / 403 | The token is wrong or the request isn't allowed. |
404 | The click ID wasn't found. |
422 | The click was rejected by fraud checks. |
For every parameter and response, see the S2S postback endpoint reference.
Signed webhooks
If you'd rather send signed JSON webhooks (HMAC-SHA256) instead of query-string postbacks, ask your account manager to enable them for your account and share your signing secret.