Skip to content

S2S impression API ​

Report affiliate ad impressions server-to-server for view-through attribution

Affiliate partners use this endpoint to report an ad impression from their server, so Linkrunner can credit a view-through install. For the setup guide and the attribution rules, see Server-to-Server Impressions.

Endpoint ​

GET https://s2s.linkrunner.io/v1/impression/{app_id}
GET https://s2s.linkrunner.io/v1/impression?app_id={app_id}
GET https://s2s.linkrunner.io/v1/impression?d={domain}

The advertiser is identified by the app ID (or the tracking link's domain) and the campaign by c. The campaign must belong to your partner account, and the advertiser must have turned on S2S traffic and view-through for you.

Authentication ​

Every request must carry your partner token. Send it in a header:

X-Linkrunner-Token: <your_token>

If your ad server can only fire URLs, send it as the lr_token query parameter instead: &lr_token=<your_token>. Linkrunner removes lr_token before it stores the impression, so it never appears in reports or postbacks.

Generate the token in your affiliate dashboard under Settings → S2S Credentials. It is shown once, so store it as a secret. One token covers every app you're connected to, for both S2S clicks and impressions. A request without a valid token is rejected with 401. For rotation and revocation, see Authenticate your requests.

Parameters ​

Send all parameters as URL-encoded query parameters. Each value is limited to 256 characters.

ParameterAliasRequiredDescription
app_idpathOne of app_id or dThe app's Android package name (com.example.app) or App Store ID (id1234567890 or 1234567890). Can also be sent in the path: /v1/impression/{app_id}.
dOne of app_id or dDomain of your Linkrunner tracking link, for example app.example.com. Wins over app_id when both are sent.
cYesCampaign code, the c value of your tracking link. Must match a campaign of that app or domain exactly.
lr_tokenOnly without the headerYour partner token, for ad servers that can't set the X-Linkrunner-Token header. Removed before the request is stored.
tidclickidYesYour unique impression ID. Returned in the {click_id} and {tid} postback macros.
gaidadvertising_idOne of gaid or idfaGoogle Advertising ID, as a UUID.
idfaOne of gaid or idfaApple IDFA, as a UUID.
impression_timeNoUnix timestamp of the impression, in milliseconds or seconds. Defaults to the time of the request.
vt_lookbackaf_viewthrough_lookbackNoYour view-through window for this impression: 1h to 24h, a bare number of hours (6), or 1d. Longer values are capped at 24 hours. It can only shorten the window the advertiser set for you.
ipaf_ipNoThe user's device IP. Stored for reporting, never used for matching. Only public addresses are kept.
uaaf_uaNoThe user's device user agent. Stored for reporting.
s2af_sub1NoPassthrough value, returned in {s2}.
s3af_sub2NoPassthrough value, returned in {s3}.
s4af_sub3NoPassthrough value, returned in {s4}.

Every impression needs a gaid or an idfa. View-through attribution matches on device ID only, so unlike S2S clicks, an IP address alone is rejected.

If both a name and its alias are sent, the name wins. click_time is ignored on this endpoint; use impression_time. pid, af_siteid and af_lang are ignored, so an AppsFlyer impression template works once the host and c are changed and your token is added.

Responses ​

The response is always JSON.

json
{
  "status": "accepted",
  "impression_id": "dfa5b5ed-54c2-5f5b-bc48-2385c336fed8"
}
json
{
  "status": "rejected",
  "reason": "missing_device_id"
}
json
{
  "status": "rejected",
  "reason": "invalid_token"
}

impression_id is Linkrunner's ID for the impression. It is the same for every retry of the same tid on the same campaign.

Status codes ​

StatusReasonMeaningRetry
200Impression recorded.
400missing_appNeither app_id nor d was sent.No
400missing_c, missing_tidA required parameter is missing or empty.No
400missing_device_idNo gaid and no idfa. An all-zero ID counts as missing.No
400invalid_device_idgaid or idfa is not a UUID, for example null or unknown.No
400unreplaced_macroA value still contains a macro, such as {gaid} or %7Bgaid%7D.No
400value_too_longA value is longer than 256 characters.No
400invalid_impression_timeimpression_time is not a Unix timestamp.No
400impression_too_oldimpression_time is more than 24 hours ago. A time in the future is treated as now.No
400invalid_viewthrough_lookbackvt_lookback is 0, negative, fractional, or not in hours or days.No
400unknown_appNo Linkrunner project has this app ID.No
400ambiguous_appMore than one of the advertiser's projects with S2S on for you has this app ID and campaign code (for example test and live). Send d instead.No
400unknown_domaind is not a Linkrunner click domain.No
400unknown_campaignc does not match a campaign of that app or domain.No
401missing_tokenNo X-Linkrunner-Token header and no lr_token parameter.No
401invalid_tokenThe token is wrong, revoked, or was rotated more than 24 hours ago, or your partner account is suspended.No
403partner_not_enabledThe advertiser hasn't turned on S2S traffic for the partner that owns campaign c.No
403view_through_disabledS2S traffic is on, but the advertiser hasn't turned on view-through for this partner.No
404s2s_disabledThe S2S impression API is turned off.No
429rate_limitedToo many impressions for this campaign.Yes, after Retry-After
503unavailableA temporary error.Yes, after Retry-After

Examples ​

The examples read your token from the LINKRUNNER_S2S_TOKEN environment variable.

bash
curl -G "https://s2s.linkrunner.io/v1/impression/com.example.app" \
  -H "X-Linkrunner-Token: $LINKRUNNER_S2S_TOKEN" \
  --data-urlencode "c=OgWmhiSXhG" \
  --data-urlencode "tid=imp-7f3a91" \
  --data-urlencode "gaid=38400000-8cf0-11bd-b23e-10b96e40000d" \
  --data-urlencode "impression_time=1790585271181" \
  --data-urlencode "vt_lookback=6h" \
  --data-urlencode "s2=banner_top"
javascript
const params = new URLSearchParams({
  c: "OgWmhiSXhG",
  tid: impressionId,
  gaid: advertisingId,
  impression_time: String(Date.now()),
  vt_lookback: "6h",
  s2: "banner_top",
});

const res = await fetch(`https://s2s.linkrunner.io/v1/impression/com.example.app?${params}`, {
  headers: { "X-Linkrunner-Token": process.env.LINKRUNNER_S2S_TOKEN },
});
const body = await res.json(); // { status: "accepted", impression_id: "..." }
python
import os, time, requests

res = requests.get("https://s2s.linkrunner.io/v1/impression/com.example.app", params={
    "c": "OgWmhiSXhG",
    "tid": impression_id,
    "gaid": advertising_id,
    "impression_time": int(time.time() * 1000),
    "vt_lookback": "6h",
    "s2": "banner_top",
}, headers={"X-Linkrunner-Token": os.environ["LINKRUNNER_S2S_TOKEN"]}, timeout=5)
body = res.json()  # {"status": "accepted", "impression_id": "..."}

An iOS impression, with the advertiser's default window:

http
GET https://s2s.linkrunner.io/v1/impression/id1234567890?c=OgWmhiSXhG&tid=imp-7f3a92&idfa=6D92078A-8246-4BA4-AE5B-76104861E7DC
X-Linkrunner-Token: <your_token>

Retries and deduplication ​

The same tid on the same campaign always maps to the same impression_id, and the impression is stored once, so it is safe to retry. Retry only 429 and 503, after the delay in the Retry-After header. Keep tid unique per impression: a reused tid is treated as a retry of the earlier impression, so the new one is not recorded.