Skip to content

Glossary

Postback URL (S2S Postback)

A URL on your tracker that another system calls, server to server, when a conversion happens, filling in the click ID and the conversion details. It reports a sale, a deposit or an install without anything running in the visitor's browser.

Summarise this article with AI

Opens the page with a ready prompt in:

Nothing is sent until you pick a service.

In short

A postback URL is an address on your tracker that another system requests when a conversion happens on its side. The affiliate network, the operator's partner program or the app's measurement partner calls it from its own server, with the click ID you handed over at the click and the conversion's details filled into the URL. Because the call goes from one server to another, it is also called an S2S postback or server-to-server postback.

It exists for the conversions you cannot see. The sale happens on the merchant's checkout, the deposit in an operator's cashier, the purchase inside an app. You cannot put a script on any of them, so the system that can see the conversion tells you about it instead.

How a Postback Works

Every postback setup has the same four steps, whatever the vertical. The click ID is the thread through all of them: it leaves with the visitor and comes back with the conversion.

  1. The click is recorded. Your tracker logs the visit and gives it a unique click ID.
  2. The click ID is handed over. The tracking link to the offer, operator or app store carries it in a sub-ID parameter the other side provides for exactly this.
  3. The other side stores it. The network, program or measurement partner keeps the click ID on the order, the player or the install.
  4. The conversion calls back. When the conversion happens, the other side requests your postback URL with the click ID and the details filled in. Your tracker matches the ID to the click, and the conversion lands on the source, campaign and ad that sent it.

Step four can happen minutes or weeks after step one. Nothing about it depends on the visitor's browser still holding a cookie, which is the whole point.

Click IDs, Macros and Tokens

You give the other side a template, and it fills in the blanks. The blanks are called macros, tokens or placeholders, and each platform writes them its own way: in curly braces, square brackets or between percent signs. A template on your side might read:

Postback template, as pasted into the program
https://track.yourdomain.com/postback?cid={clickid}&event={event}&amount={amount}&txid={transaction_id}

And the request that arrives when a player deposits:

The same postback, fired
https://track.yourdomain.com/postback?cid=8f3a2c71e0&event=ftd&amount=50.00&txid=dep-118204
  • The click ID is the one value every postback needs. Without it the conversion is a count with no source. Voluum, for example, makes its `cid` parameter mandatory and everything else optional.
  • The event names what happened: a lead, a sale, a registration, a first deposit, an install.
  • The amount carries the payout or the order value, so revenue lands on the click with the conversion.
  • The transaction ID names this conversion, so a second, different conversion on the same click can be told apart from the same one sent twice.

The parameter names on the left are your tracker's; the macros on the right are the sender's. Getting a macro name wrong is the most common postback bug: the sender sends the literal text `{clickid}` and nothing matches.

S2S Postback vs. Pixel

The alternative to a postback is a conversion pixel: a script or image tag on the thank-you page that fires in the visitor's browser and reads the click from a cookie. It is easier to set up and it fails in every place the postback does not.

The pixel's one advantage is that it needs nothing from the other side. Where you own the conversion page, recording the visit and the conversion server-side on your own domain gets the same robustness without a third party; see server-side tracking.

Events: More Than One Postback per Click

A single click can earn several conversions, and a good setup reports each one as its own event on the same click rather than as separate counts.

  • iGaming

    Registration, first-time deposit, qualified FTD, every redeposit after it. The FTD is what a CPA deal pays on.

  • E-commerce offers

    Sale, upsell, refund. A refund arrives as its own postback with a negative or reversed status.

  • Lead generation

    Lead submitted, lead approved, lead rejected. The approval is what the network pays on, often days later.

  • Apps

    Install, registration, first purchase, subscription renewal, each reported by the measurement partner as it happens.

Some senders fire one postback URL with an event macro; others want one URL per event. Either works as long as each event can be told apart when it arrives.

Deduplication and Retries

A postback is an HTTP request, and HTTP requests get lost, time out and get sent again. The receiving end has to be built so that a repeated request does no harm and a lost one can be noticed.

  • Deduplicate on click ID plus transaction IDThe same pair twice is the same conversion. Voluum documents exactly this: a duplicated click ID is discarded by default, unless it arrives with a new transaction ID, and the same click ID and transaction ID combination is counted once.
  • Expect retries, and their schedule to varyWhether a sender retries after a timeout or an error, and how often, differs by platform. Answer quickly with a 200, and ask the program or network what it does on failure.
  • Keep a log of every postbackEvery request with its payload, the click it matched and the reason it was rejected. When the network's statement and your count disagree, the log is the evidence.
  • Fire a test before going liveMost programs and networks have a test postback in their settings. Send one and confirm it matched a click before any traffic runs.

Examples Beyond iGaming

The term is most at home in affiliate marketing, but the same pattern runs anywhere the conversion happens on somebody else's system.

  • Affiliate networks. Everflow, CAKE, Affise and their peers fire a postback to the affiliate's tracker when an offer converts, with the payout. A media buyer running paid traffic to network offers reads profit per campaign from it. See affiliate networks and paid traffic affiliates.
  • CPA offers. A solar lead, an insurance quote or a software trial bought on a cost per action basis is confirmed by postback once the advertiser approves it, which is how a rejected lead stops counting.
  • Apps. A mobile measurement partner such as AppsFlyer or Adjust sends postbacks to the ad networks on installs and in-app events, and Apple's SKAdNetwork calls its own attribution message a postback.
  • Ad platforms. Sending a conversion to Google Ads as an offline conversion or to Meta through the Conversions API is the same idea in the other direction: your server tells the platform about a conversion on its click.

In iGaming the sender is the operator's partner program and the events are reg, FTD and deposits; the setup, program by program, is in iGaming affiliate postbacks, and the trackers that receive them are compared in the best iGaming tracking software.

Conclusion

A postback URL lets the system that sees the conversion tell the system that saw the click. Pass the click ID out in the link, give the other side a template with the right macros, accept each event on the same click, and treat duplicates and retries as normal. Done that way, a conversion on a checkout, cashier or app you will never put a script on lands on the campaign that earned it. Every postback LeadJourney receives is visible in its logs, and the iGaming setup is on the iGaming tracking software page.

95%+ data accuracy, even with ad blockers and iOS

See which ads really created your leads

Connect your ad accounts and your CRM once, and every lead arrives with the campaign that created it already attached.

LeadJourney dashboard showing lead sources, campaign performance and attributed revenue side by side