A postback is a message one server sends to another to say: this click just turned into a conversion. Instead of relying on a pixel in the user’s browser, the advertiser’s system calls a URL on your tracker or network the moment the action happens. The user never sees it, ad blockers cannot stop it, and it works even if the user closed the page.
A postback (also server-to-server or S2S conversion tracking) is an HTTP request that a server fires to a predefined URL when a conversion is recorded. The URL carries parameters: usually a click ID issued when the click happened, plus optional fields such as payout, currency, event name or status. The receiving system, a tracker or an affiliate network, matches the click ID to the original click and attributes the conversion to the campaign, source, placement and creative that produced it.
The flow has three steps. First, the click: the tracker generates a unique click ID and appends it to the offer URL, typically in a sub-ID parameter. Second, the action: the advertiser stores that ID together with the user. Third, the postback: when the action is recorded or approved, the advertiser’s server requests the postback URL with the ID filled in. Most trackers also accept a follow-up postback that changes the status of an existing conversion, which is how holds, approvals and rejections flow back into your dashboard.
Postbacks replaced browser pixels as the default in performance marketing because they do not depend on the user’s device. Apple’s App Tracking Transparency (iOS 14.5, April 2021) made cross-app identifiers opt-in, ad blockers strip tracking pixels, and browsers restrict third-party cookies; a server-to-server call is unaffected by all of that. In mobile attribution the same mechanism is how measurement partners such as AppsFlyer send install and in-app events to ad networks, and Meta’s Conversions API is the server-side counterpart of its pixel.
The weak points are integration errors, not the method. A click ID that is not passed through the funnel, a macro named differently on each side ({clickid} versus {subid}), a postback that fires on form submit when the payable event is approval, or duplicate calls that count one sale twice. Good trackers log every incoming postback with its parameters and response code, which is the first place to look when numbers do not match.
On April 26, 2021 Apple shipped iOS 14.5 with App Tracking Transparency: every app had to ask permission before tracking users across other apps and sites. Flurry Analytics, measuring daily opt-in rates after launch, reported that only about 4% of US iPhone users and roughly 12% worldwide allowed tracking in the first weeks. Attribution that relied on the device identifier lost most of its signal overnight.
The response across the industry was server-side. Meta promoted its Conversions API alongside the pixel, mobile measurement partners leaned on postbacks to report installs and events to ad networks, and affiliate trackers that had supported S2S for years became the standard setup rather than the advanced option. On the web the direction was the same: after years of announced deprecation, Google said in July 2024 that it would not phase out third-party cookies in Chrome and confirmed in April 2025 that no new standalone choice prompt would ship, but the lesson of the back-and-forth was that any tracking tied to the browser is a dependency you do not control. A postback is a request between two servers you or your partner operate, which is why it survived every one of these changes untouched.
How S2S postback tracking works: click ID, macros, where the postback URL goes, testing, deduplication, and why server-side is the durable standard...
Beginner · 6 min readHow affiliate tracking really works: clicks, click IDs, postbacks, server-to-server flows and why clean attribution is the foundation of a profitab...
Core · 10 min readWhat a tracking pixel is, how it fires in the browser, how it differs from server-to-server tracking, and where the Meta Pixel, the Conversions API...
Advanced · 11 min readHow to diagnose affiliate tracking problems: which tracker, network and platform discrepancies are normal and which are alarming, plus broken postb...
A pixel is a piece of code that runs in the user’s browser on the thank-you page and reports the conversion from there; a postback is a request sent between servers without the browser involved. Pixels are easier to install but break with ad blockers, closed tabs and cookie restrictions. Postbacks require passing a click ID through the funnel but report every approved conversion reliably.
It is the address your tracker exposes to receive conversions, with placeholders for the parameters the sender should fill in, such as the click ID and the payout. You copy it from your tracker and paste it into the network’s postback settings, mapping the network’s macro names to your tracker’s placeholders.
In most cases the click ID is missing or renamed somewhere between the click and the postback. Check that the offer URL contains the click ID parameter, that the network stores it in the sub-ID it uses for postbacks, and that the postback URL uses the same macro name. Then look at the tracker’s postback log for incoming requests with empty values.
Yes, if the endpoint is open. That is why trackers support a security token in the postback URL, IP whitelisting for the sending server and deduplication by click ID. Networks apply the same protections on their side, so a conversion that appears in your tracker but not in the network dashboard is usually a sign that something fired a postback it should not have.
References are listed as plain text on purpose; look them up by title and publisher. Updated: 2026-10-02.
Run them inside a network with real tracking, roughly 48-hour payouts and a dedicated manager.
Join the network