Create a tracking link
Choose an approved campaign and preserve the generated Trakio Click ID through the user journey.

Trakio Docs provides production contracts for tracking links, S2S conversion reporting, SDK ingestion, attribution, and partner postbacks.
Connect the click, identity, and conversion without changing the identifiers Trakio issues.
Choose an approved campaign and preserve the generated Trakio Click ID through the user journey.
Keep production API and SDK credentials isolated. Never expose an S2S key inside a client application.
Let the SDK own install, bind the new account, and report later outcomes only after backend-confirmed success.
Send a valid Click ID, approved external account binding, or qualifying-action proof. Reuse one idempotency key for every retry of the same logical event.
POST https://api.trakiommp.com/v1/conversions
Authorization: Bearer YOUR_PRODUCTION_KEY
Content-Type: application/json
{
"campaign_id": "cmp_xxxxxxxxx",
"event_name": "user_registered",
"click_id": "clk_xxxxxxxxx",
"external_user_id": "user_123",
"browser_id": "first_party_browser_cookie_value",
"user_ip": "203.0.113.10",
"idempotency_key": "registered_user_123",
"event_time": "2026-08-22T10:30:00+05:30"
}Optional browser_id and user_ip values provide risk context only. Use an opaque first-party browser identifier and the real end-user IP where legally permitted; Trakio stores keyed hashes, not raw values. Do not send the advertiser server IP as user_ip.
installCreated automatically once for the SDK installation identity after initialization and analytics consent. Never call it manually. S2S-only advertisers may report their own install.
user_registeredSuccessful account creation after the backend confirms a genuinely new user. Never send it on login, OTP request, reopen, or failure.
application_submittedA lead, order, application, or other qualifying action began on the current device. Capture one-time proof and persist it with the advertiser’s business record.
application_approvedA later verified outcome reported by the trusted advertiser backend. It can arrive while the app is closed by using the saved account, device, and qualifying-action proof.
qualified_action_completedA universal final business outcome such as an approved lead, funded account, purchase, trade, or another campaign-specific success.
Stable external accountSet a stable, opaque advertiser-generated user ID after login or session restoration. Clear active identity before logout. Never use a phone number, email, OTP, token, or government ID.
Immutable acquisitionA new account can bind to its original acquisition click and SDK installation. Logging back into the same account preserves that history; another account never inherits it.
Security modesMONITOR_ONLY records risk, ACCOUNT_ONLY validates account ownership, and ACCOUNT_AND_DEVICE requires the original account and device. Mismatches become pending review, not deleted.
Privacy-safe device proofTrakio exposes an opaque dbn_… binding. Supporting App Set ID and permitted Advertising ID signals are scoped and hashed; raw device identifiers are never shown to advertisers.
Capture proof when a qualifying business action begins and store it with the lead, order, or application. The advertiser backend can then report the outcome after the app closes.
final proof = await Trakio.captureQualifyingAction(
'application_submitted',
advertiserActionId: 'application:${application.id}',
);
// Persist proof.qualifyingActionId (qac_…)
// and proof.deviceBindingId (dbn_…) with the record.POST https://api.trakiommp.com/v1/conversions
Authorization: Bearer YOUR_PRODUCTION_KEY
X-Trakio-Timestamp: 1787918400
X-Trakio-Nonce: nonce_example_7rN2kP4v
X-Trakio-Signature: sha256=YOUR_HMAC_SHA256
Content-Type: application/json
{
"schema_version": "2026-08",
"campaign_id": "cmp_xxxxxxxxx",
"event_name": "application_approved",
"external_user_id": "user_123",
"qualifying_action_id": "qac_xxxxxxxxx",
"device_binding_id": "dbn_xxxxxxxxx",
"advertiser_conversion_id": "application:456",
"idempotency_key": "application_approved_456",
"event_time": "2026-08-27T12:30:00+05:30"
}advertiser_conversion_id must match the action ID used to issue the proof. Pending conversions create no payout or partner postback until an advertiser approves them.
Protected requests sign timestamp + "\n" + nonce + "\n" + sha256(canonical JSON) with the Bearer API key. Use a new URL-safe nonce for every attempt and keep server clocks synchronized.
Trakio creates the Click ID. Partners may pass pcid and pid; advertisers must preserve trk_id unchanged. Legacy integrations may continue sending trk_click_id during migration.
Download the reviewed bundle, extract it under your app's vendor directory, and use the Production SDK key only in the Production build. The current Android release requires Dart 3.10+, Flutter 3.44+, Android API 24+, and Java 17. Native iOS ingestion remains coming soon; use S2S for iOS meanwhile.
Download SDK 1.1.0-rc.1dependencies:
trakio_flutter:
path: vendor/trakio-sdk/trakio_flutter
await Trakio.setExternalUserId(user.attributionId);
await Trakio.trackEvent(
'user_registered',
advertiserEventId: 'registered_${user.attributionId}',
);
await Trakio.clearExternalUserId();Original acquisitionA reinstall or later campaign click never overwrites the immutable original acquisition. Re-engagement and retargeting history are stored separately.
Different deviceIn strict mode, the same account on another device—or another account on the original device—moves the event to pending review with an explicit reason code.
Permanent migrationApproving one suspicious conversion does not permanently move the account. Permanent rebinding requires a separate audited device-migration approval.
Attribution typeConfigure each event to use ORIGINAL_ACQUISITION, LATEST_REENGAGEMENT, or LATEST_ELIGIBLE_CLICK.
1 · App signingCopy the App signing key certificate SHA-256 from Play Console → Setup → App integrity. Remove colons and save the 64-character value on the Production SDK key.
2 · ReferrerOpen a Trakio tracking link before installing from Play. The destination carries an encoded trk_id through Google Play Install Referrer.
3 · Important distinctionThe signing-certificate SHA-256 is not the AAB file checksum. A new AAB normally keeps the same Play app-signing certificate.
4 · App Links and disclosureAdd an Android autoVerify intent filter for your application-owned HTTPS host and publish /.well-known/assetlinks.json without a redirect. The package name and Play app-signing certificate must match. Complete the host app’s privacy notice and Play Data safety disclosure before release.
Data minimizationSend only stable opaque account IDs and campaign evidence. Never send passwords, OTPs, bank details, government IDs, email addresses, or phone numbers to Trakio.
Device signalsApp Set ID and a consented Advertising ID are scoped to the advertiser, application, and environment and stored only as one-way hashes. Raw values are excluded from reports, exports, postbacks, and advertiser-facing APIs.
Consent withdrawalApply changes with Trakio.setConsent(). Advertising withdrawal removes its retained signal; analytics withdrawal also clears retained device observations and the active external identity. Collection remains off until the host app enables it again lawfully.
Identifier resetAdvertising ID may be unavailable, limited, zeroed, or reset. App Set ID may change after reinstall, restore, signing changes, or extended inactivity. Neither identifier is sole proof of account ownership.
Deletion and retentionVerified deletion requests remove or pseudonymize account identity. Restricted non-identifying audit evidence may be retained only for configured security, dispute, legal, or preservation requirements. See the Data Retention Policy for default periods.
Store disclosureKeep the host app privacy notice and Google Play Data safety and Advertising ID declarations aligned with the production SDK configuration and actual purposes of collection.
GET endpoints support query-value macros including {pcid}, {partner_id}, {event}, {conversion_id}, {click_id}, {order_id}, {payout}, and {currency}. POST endpoints receive JSON and an X-Trakio-Signature. Non-2xx responses and timeouts retry with exponential backoff; configure 1–10 attempts and a 1–15 second timeout.
A URL containing {pcid} requires every promoted link to supply a real pcid. For verification, read X-Trakio-Timestamp and X-Trakio-Signature-Input. Sign the raw POST body or, for GET, the exact path and query. The expected value is v1=HMAC_SHA256(secret, timestamp + "." + input). Compare in constant time and reject stale timestamps.
IdentityUse only a stable non-sensitive external user ID, set it after login and consent, and clear it before logout completes.
DeduplicationReuse one deterministic advertiserEventId for SDK retries and one idempotency_key for S2S retries.
End-to-endTracking link → Play install → SDK install → new account → qualifying-action proof → closed-app S2S outcome → partner postback. Verify every hop in Live debugger, protected attribution, reports, and the delivery monitor.
Financial eventsSend payout-driving events from the trusted advertiser backend through S2S. Do not treat a client-only SDK event as financial proof. Pending events produce neither payout nor postback.
Attribution statesAutomatic lifecycle events with a missing or stale Click ID are retained as unattributed. Payable or custom business events keep strict validation and reject an invalid supplied Click ID.
Consent and resetApply privacy changes with Trakio.setConsent() and call Trakio.reset() for account deletion or an explicit shared-device reset. Trakio does not require a separate analytics-settings screen; the host app owns its lawful notice and consent experience.
ReinstallAn uninstall may create a new installation identity. Preserve the immutable account acquisition, evaluate the submitteddbn_… binding, and use stable advertiser IDs and idempotency keys. Do not rely on permanent device fingerprinting.
Event sequencingConfigure optional event order. Out-of-order events are retained as pending review with a reason code instead of being silently discarded.
Install is unattributedConfirm the user opened a fresh Trakio tracking link before installing from Google Play, the package matches, and the encoded trk_id reached Play Install Referrer. A direct APK or ADB install cannot prove that deferred path.
Protected event is pendingInspect the reason code and compare the submitted account and opaque device binding with the original acquisition. Missing, revoked, expired, or mismatched evidence is retained for advertiser review and produces no payout or postback.
Closed-app S2S is rejectedReuse the saved qac_… and dbn_…, the same stable external user, and the advertiser action ID used when proof was captured. Sign the canonical request with a fresh nonce while preserving the same idempotency key.
Duplicate or out-of-order eventReuse one deterministic SDK event ID or S2S idempotency key for the logical event. Verify the configured sequence and do not generate a new identifier for a network retry.
Postback keeps retryingCheck the delivery monitor, signature input, response status, and latency. Return a 2xx response within the configured timeout, then manually retry only after fixing the receiver.