Watch And Earn docs
v3.0.0
Live demoConsole demo Get help
● Set up · Affiliate

Partner offers
signed postbacks credit points.

List offers from affiliate partners. When a user completes one, the partner's server calls your offerPostback function with an HMAC signature, and the user receives points. Your own payment from the partner is under your agreement with them.

HMAC-SHA256offerPostback

01How it works

  1. You create the offerConsole → Offers: title, description, URL (the partner's tracking link), points, partner name, order, optional image URL, active.
  2. The app opens the linkWhen the user taps the offer, the app opens your URL in the browser and adds sub_id=<uid> and offer_id=<offerId> to it (app/lib/ui/screens/offers_screen.dart). Ask your partner to pass sub_id back to you as uid.
  3. The partner calls your postbackAfter the user completes the offer, the partner's server calls the URL below with a signature.
  4. The function credits onceofferPostback (firebase/functions/src/offers.ts) checks the signature, ignores duplicates of the same tx, refuses inactive offers, banned users and switched-off offers, applies the daily cap (economy.offerDailyCap, default 10) and credits the offer's points.
Console Offers page with sample partner offers
Console → Offers, on sample data.

02The postback URL and its signature

https://REGION-PROJECT.cloudfunctions.net/offerPostback?offer={offerId}&uid={uid}&tx={tx}&sig={sig}
ParameterValue
offerThe offer id from the console.
uidThe user id (the sub_id the app added to the link).
txA unique transaction id from the partner. A repeated tx is ignored.
sighex(HMAC-SHA256(secret, offer:uid:tx))

The secret. Each offer gets its own 32-byte secret when you create it. The console shows it once; only an owner can create or rotate it. Give it to the partner over a private channel. Once you set Backend → Cloud Functions base URL, the console shows the postback URL with your values filled in.

Responses

StatusBodyMeaning
400bad requestA parameter is missing or malformed (sig must be 64 hex characters).
403bad signatureThe signature does not match the offer's secret.
200creditedPoints added.
200duplicate, unknown_user, inactive_offer, banned, offers_disabled, daily_capAccepted but not credited, so the partner stops retrying.

Test a signature on your computer (replace the values):

printf '%s' "OFFER_ID:USER_UID:TX123" | openssl dgst -sha256 -hmac "OFFER_SECRET" | awk '{print $2}'

03Before you list an offer

  • Offers credit points, never money. Do not promise users cash for completing offers.
  • Do not list offers that require a purchase or a deposit to be credited, or that drive app installs in ways your ad network or store forbids (incentivised installs). Read your partner's and Google Play's rules.
  • The commercial agreement with the partner, and any tracking it requires, are yours.