Skip to main content
Version: v2

Tracking providers and callback variants

GET /performance-marketing/v2/providers/capabilities requires an advertiser dashboard bearer session and returns {contractVersion,items}. Each item describes its provider code, enablement, certification, supported platforms and events, required macros, callback authentication, and credential fields. Use this response to populate Campaign Studio; do not hardcode a provider merely because a backend adapter exists. A provider is selectable only when certified and enabled in that environment.

Custom S2S​

The current self-service direct path uses CUSTOM_S2S when enabled. Set the offer's tracking partner to that code, create a campaign key, preserve {click_id}, and send the signed campaign callback. GET /campaigns/{campaignId}/tracking gives the active callback endpoint, credential metadata, required parameters, and optional web-pixel capability. POST .../tracking/custom-s2s/credentials, /test, and /rotate are documented in the campaign endpoint reference.

Manual MMP callback​

The certified MMP codes in the current registry are ADJUST, APPSFLYER, AIRBRIDGE, SINGULAR, BRANCH, and KOCHAVA; they are selectable only when the manual MMP feature is enabled. Tracking setup reports GET_OR_POST, a campaign-specific /postbacks/mmp/{campaignId}/{provider} URL, CAMPAIGN_TOKEN authentication, and required click_id, transaction_id, goal_id, status, and occurred_at fields. Map your provider's names to those canonical parameters and test with RapidoReach before review.

Method and pathPurpose
POST /campaigns/{campaignId}/tracking/mmp/credentialsGenerate or retrieve a campaign MMP token; a new token is shown once.
POST /campaigns/{campaignId}/tracking/mmp/rotateReplace the token while the campaign is DRAFT or IN_REVIEW; clears prior MMP verification.
GET/POST /postbacks/mmp/{campaignId}/{provider}Receive a provider event; uses the campaign token and optional IP allowlist.

BRANCH and KOCHAVA also have a partner-configuration template mode subject to the provider's current capability. Do not use that mode unless Campaign Studio returns it for your campaign. An MMP campaign cannot be approved without the required credential, and launch requires administrator live-test verification of the active revision. The administrator-only verification route is intentionally absent from the advertiser endpoint index. A new revision or credential rotation can invalidate that verification.

Managed and legacy paths​

GET/POST /postbacks/direct is for older DIRECT token campaigns when their Tracking setup returns that endpoint. GET/POST /postbacks/cint is for a managed Cint integration. Both are offer-delivery gated and rate limited, and their tokens do not authenticate Custom S2S. Other PROVIDER_MANAGED integrations are configured by RapidoReach operations. The legacy offerwall user delivery endpoints under /performance-marketing/v2/offerwall/* are a separate delivery surface; use the Offers V2 SDK session reference for a new publisher placement integration.

The provider callback rate limit is 120 requests per minute per source IP. Preserve transaction IDs on retry, record pending and reversal state changes, and investigate rejected provider events with the selected campaign's Tracking setup. Never send a provider credential in a browser or public URL when a server POST is available.

Development callback receiver​

POST /performance-marketing/v2/sandbox/callbacks accepts a validated provider callback fixture and Idempotency-Key only when the sandbox callback feature is enabled in a non-production environment. It rejects external callback or destination URLs. A first accepted fixture returns 202 with sandbox: true, duplicate: false, and eventId; an identical retry returns 200 with duplicate: true. This receiver is for contract tests, not a way to record a paid conversion. Production returns 404.