Tracking & analytics · Glossary

Postback Server-to-server (S2S) conversion tracking

In plain words

A postback is a message one server sends to another to say: this click just turned into a conversion. Instead of relying on a pixel in the user’s browser, the advertiser’s system calls a URL on your tracker or network the moment the action happens. The user never sees it, ad blockers cannot stop it, and it works even if the user closed the page.

Definition

A postback (also server-to-server or S2S conversion tracking) is an HTTP request that a server fires to a predefined URL when a conversion is recorded. The URL carries parameters: usually a click ID issued when the click happened, plus optional fields such as payout, currency, event name or status. The receiving system, a tracker or an affiliate network, matches the click ID to the original click and attributes the conversion to the campaign, source, placement and creative that produced it.

The flow has three steps. First, the click: the tracker generates a unique click ID and appends it to the offer URL, typically in a sub-ID parameter. Second, the action: the advertiser stores that ID together with the user. Third, the postback: when the action is recorded or approved, the advertiser’s server requests the postback URL with the ID filled in. Most trackers also accept a follow-up postback that changes the status of an existing conversion, which is how holds, approvals and rejections flow back into your dashboard.

Postbacks replaced browser pixels as the default in performance marketing because they do not depend on the user’s device. Apple’s App Tracking Transparency (iOS 14.5, April 2021) made cross-app identifiers opt-in, ad blockers strip tracking pixels, and browsers restrict third-party cookies; a server-to-server call is unaffected by all of that. In mobile attribution the same mechanism is how measurement partners such as AppsFlyer send install and in-app events to ad networks, and Meta’s Conversions API is the server-side counterpart of its pixel.

The weak points are integration errors, not the method. A click ID that is not passed through the funnel, a macro named differently on each side ({clickid} versus {subid}), a postback that fires on form submit when the payable event is approval, or duplicate calls that count one sale twice. Good trackers log every incoming postback with its parameters and response code, which is the first place to look when numbers do not match.

In practice

Case from the industry

Why the industry moved from pixels to postbacks

On April 26, 2021 Apple shipped iOS 14.5 with App Tracking Transparency: every app had to ask permission before tracking users across other apps and sites. Flurry Analytics, measuring daily opt-in rates after launch, reported that only about 4% of US iPhone users and roughly 12% worldwide allowed tracking in the first weeks. Attribution that relied on the device identifier lost most of its signal overnight.

The response across the industry was server-side. Meta promoted its Conversions API alongside the pixel, mobile measurement partners leaned on postbacks to report installs and events to ad networks, and affiliate trackers that had supported S2S for years became the standard setup rather than the advanced option. On the web the direction was the same: after years of announced deprecation, Google said in July 2024 that it would not phase out third-party cookies in Chrome and confirmed in April 2025 that no new standalone choice prompt would ship, but the lesson of the back-and-forth was that any tracking tied to the browser is a dependency you do not control. A postback is a request between two servers you or your partner operate, which is why it survived every one of these changes untouched.

Common mistakes

  • Not passing the click ID all the way to the advertiser. If the offer link has no click ID parameter, the postback has nothing to match and conversions arrive as unattributed.
  • Mismatched macros. Your tracker expects {clickid}, the network sends {subid}; the call arrives, the value is empty, the conversion is dropped.
  • Testing with fake conversions on a live offer. Use the network’s test postback or a test offer; manufactured conversions on a real campaign get flagged as fraud.
  • Ignoring status postbacks. If you only record the initial conversion and never the approval or rejection update, your dashboard shows revenue you will never be paid.
  • Leaving the postback endpoint unprotected. Without a secret token or IP whitelist, anyone who learns the URL can inject conversions into your stats.

Go deeper

FAQ

What is the difference between a postback and a pixel?

A pixel is a piece of code that runs in the user’s browser on the thank-you page and reports the conversion from there; a postback is a request sent between servers without the browser involved. Pixels are easier to install but break with ad blockers, closed tabs and cookie restrictions. Postbacks require passing a click ID through the funnel but report every approved conversion reliably.

What is a postback URL and where do I get it?

It is the address your tracker exposes to receive conversions, with placeholders for the parameters the sender should fill in, such as the click ID and the payout. You copy it from your tracker and paste it into the network’s postback settings, mapping the network’s macro names to your tracker’s placeholders.

Why does my tracker show clicks but zero conversions?

In most cases the click ID is missing or renamed somewhere between the click and the postback. Check that the offer URL contains the click ID parameter, that the network stores it in the sub-ID it uses for postbacks, and that the postback URL uses the same macro name. Then look at the tracker’s postback log for incoming requests with empty values.

Can postbacks be faked?

Yes, if the endpoint is open. That is why trackers support a security token in the postback URL, IP whitelisting for the sending server and deduplication by click ID. Networks apply the same protections on their side, so a conversion that appears in your tracker but not in the network dashboard is usually a sign that something fired a postback it should not have.

Sources

  1. What is a postback? — AppsFlyer glossary (appsflyer.com)
  2. iOS 14.5 opt-in rate: daily updates since launch — Flurry Analytics blog (flurry.com, 2021)
  3. Apple’s App Tracking Transparency feature has arrived: here’s what you need to know — TechCrunch (techcrunch.com, 2021)
  4. About the Conversions API — Meta Business Help Center (facebook.com)
  5. Next steps for Privacy Sandbox and tracking protections in Chrome — Google Privacy Sandbox (privacysandbox.com, 2025)

References are listed as plain text on purpose; look them up by title and publisher. Updated: 2026-10-02.

Terms are the easy part.

Run them inside a network with real tracking, roughly 48-hour payouts and a dedicated manager.

Join the network