API overview and authentication
Base URL, API keys, your first request and how responses are shaped.
The Affilinext REST API lets you pull campaigns, clicks, conversions and reports into your own tools, and send clicks and conversions from your server.
Base URL
https://app.affilinext.com/api/v1If your network runs Affilinext on its own domain, use that domain instead. Every endpoint is served over HTTPS and returns JSON.
Get an API key
| You are | How to get a key |
|---|---|
| Publisher | My Profile → Tracking Setup → API keys & tokens. You can hold up to 5 keys. |
| Advertiser | Ask your network admin — advertiser keys are issued by the network. |
| Network admin | Integrations page. Choose the key type and, for publisher or advertiser keys, the account it belongs to. |
The full key starts with ak_ and is shown only once, when it's created. Store it in a secret manager, not in source code. See Create and use API keys for more.
What a key can see
Every key is tied to an account, and the API only ever returns that account's data:
| Key type | Can access |
|---|---|
| Publisher | Campaigns you can run (with your own payout terms), and your own clicks, conversions and stats |
| Advertiser | Your own campaigns and their clicks, conversions and stats |
| Admin | Everything in the network, plus admin-only endpoints |
| Read-only | Everything in the network, read only (GET). No API call logs. |
| Reports | /api/v1/me and /api/v1/reports/* only, network-wide |
A key stops working immediately if it's revoked or if its account is deactivated.
Authenticate
Send the key in a header on every request:
Authorization: Bearer ak_your_keyx-api-key: ak_your_key works too. You can also pass ?apiKey= in the URL, but avoid it — URLs end up in proxy logs and browser history.
Your first request
Check that your key works and see which account it belongs to:
curl https://app.affilinext.com/api/v1/me \
-H "Authorization: Bearer ak_your_key"{
"success": true,
"message": "OK",
"apiKey": { "id": "key_8f2c", "name": "Reporting sync", "role": "affiliate" },
"advertiserId": null,
"affiliateId": "aff_102"
}role is affiliate for publisher keys, advertiser for advertiser keys, and admin, readonly or reports for network keys.
Response format
Every response is JSON with a success flag. Errors also carry an error message — see Errors, rate limits and retries.
List endpoints are paginated and return:
{
"success": true,
"total": 1284,
"limit": 50,
"offset": 0,
"rows": [ ... ]
}| Parameter | Default | Notes |
|---|---|---|
limit | 50 | Maximum 500 |
page | 1 | 1-based page number |
offset | 0 | Use instead of page if you prefer; it takes priority |
Dates in filters (from, to) are YYYY-MM-DD in UTC and include the whole day. Timestamps in responses are ISO 8601 in UTC.
Endpoints
| Method | Path | Who |
|---|---|---|
GET | /api/v1/health | Anyone. Record counts only with an admin, read-only or reports key. |
GET | /api/v1/me | Any key |
GET | /api/v1/campaigns | Any key |
GET POST | /api/v1/clicks | Any key |
GET POST | /api/v1/impressions | Any key |
GET | /api/v1/conversions | Any key |
POST | /api/v1/conversions | Advertiser, admin |
PATCH | /api/v1/conversions/{id} | Admin |
GET | /api/v1/reports/summary | Any key |
GET | /api/v1/reports/events | Any key |
GET | /api/v1/calls | Admin |