Skip to main content
Version: v2

Offer reward callbacks

RapidoReach sends reward events to the HTTPS callback endpoint configured on the placement. A user action, redirect, SDK message, or advertiser postback response is not enough to credit an account. Your reward service should credit from a verified callback and store the event ID or transaction ID for deduplication.

Setup​

  1. In Offer Placement V2 → Callbacks, enter an HTTPS endpoint. Select the callback families you handle: REWARD_PENDING, REWARD_CONFIRMED, and/or REWARD_REVERSED.
  2. Stage a callback secret. The rotation action returns the secret once; save it in protected server configuration and retain its keyId.
  3. Implement HMAC-SHA256 verification over timestamp.nonce.canonicalJsonBody using the matching key. Check the timestamp and nonce to prevent replay. Return a successful HTTP response only after persisting the event or safely recognizing a duplicate.
  4. Use Run sandbox test to inspect a signed preview. The current console test stays in memory (deliveredExternally: false); it does not send an HTTP request to your endpoint or move money. Send a separate development delivery through the full pipeline before launch.
  5. Request placement review and confirm callback deliveries and the publisher offer report during development verification.

The callback configuration can also include an IP allowlist and a failed redirect URL. Do not rely on IP alone as the signature check. Never put the callback secret in mobile code, browser code, screenshots, or support tickets.

Crediting rules​

EventPublisher action
REWARD_PENDINGShow progress without final credit unless your terms explicitly allow a provisional balance
REWARD_CONFIRMEDCredit once after signature, identity, and duplicate checks
REWARD_REVERSEDApply a compensating debit or hold according to your reward terms; retain the original transaction link

Use the callback deliveries view to diagnose repeated failures. An authorized replay needs an idempotency key and a reason; replays must not duplicate credit. During rotation, the next key becomes eligible after its stated validFrom time. Promote it only after your receiver accepts both the current and staged key and the rotation window has arrived.

See the publisher offer callback API reference for the console endpoints and error handling.