Conversion tracking with signed postbacks and webhooks
Short answer: VibeFree measures conversions on your own site server to server. It adds an opaque vf_click_id to your landing URL; when the visitor converts, your server sends that id to VibeFree signed with HMAC-SHA256 in an X-VibeFree-Signature: t=…,v1=… header - the same scheme as Stripe's webhooks - within 5 minutes of the timestamp, and it counts once if the click was in the last 30 days. There is no pixel, SDK or cookie. Leads, survey responses, interview transcripts and campaign changes come the other way, as signed webhooks.
When you need a postback
- A CPA hybrid, where you pay per conversion your server reports.
- A promo code redeemed on your site.
- A verified trial, a "make one API call" offer or an offer on the earn page - see sponsored rewards.
- Everything VibeFree can see itself - views, clicks, completed videos, votes, leads, installs, survey completions - needs no postback at all.
Step 1: keep the click id
Each click on a postback-tracked ad lands on your URL with vf_click_id=<id> added. The id is random, unique to that click and says nothing about the person. Read it when the visitor lands and keep it with them until they convert - in a first-party cookie, your server session or a hidden form field - and send it back unchanged. An API-call offer carries it differently: your one-line command contains {{click_id}}, which becomes the id for each person who runs it.
Step 2: send the postback
| POST (recommended) | GET (for systems that can only fire a URL) | |
|---|---|---|
| Endpoint | https://api.vibefree.dev/api/ads/postback | https://api.vibefree.dev/api/ads/postback |
| Click id | JSON body: {"click_id": "<vf_click_id>", "event": "conversion"} | ?click_id=<vf_click_id> |
| Signature | X-VibeFree-Signature: t=<unix seconds>,v1=<hex> header | &t=<unix seconds>&sig=<hex> |
| What is signed | <t>.<raw body> | <t>.click_id=<vf_click_id> |
The signature is the lowercase hex HMAC-SHA256 of the signed string, keyed with your organisation's postback secret (it starts vfps_; create or rotate it in the console's Sandbox tab, where owners and admins can reveal it). event must be conversion, which is also what an omitted event means.
Step 3: read the answer
| Response | Meaning |
|---|---|
200, accepted | Counted - and billed, if the campaign is priced on it |
200, duplicate | Already counted for that click. Safe to retry |
| 400 | The body is not JSON, click_id is missing, or event is not conversion |
| 401 | The signature is missing, malformed or wrong, or t is more than 5 minutes from VibeFree's clock |
| 404 | Unknown click id - send the vf_click_id exactly as you received it |
| 409 | No click was recorded for that id, the click is older than 30 days, or the campaign no longer accepts conversions |
Send postbacks as soon as the conversion happens, and retry on a timeout or a 5xx: a click converts at most once, so a repeat is harmless. Each IP address can send up to 600 a minute.
Signing and verifying without surprises
- Sign the exact bytes you send. For a webhook you receive, verify against the raw request body before any JSON parsing - a body parsed and serialised again will not match.
- Use Unix seconds and a synced clock. The tolerance is 5 minutes either way, which is also what stops an old signed request being replayed.
- Compare in constant time.
hmac.compare_digestin Python; in Node, check the two lengths match and then usecrypto.timingSafeEqual. - De-duplicate webhooks on their
id. A retried delivery carries the same event id. - Copy-ready samples in Node, Python and curl sit beside the testers in the console.
Pass the test before you sell on conversions
- Create a postback secret in the Sandbox tab.
- Ask the postback tester for a test click id. It comes from a sandbox showing of one of your ad groups that needs a postback - draft and sandbox campaigns are fine - and works for 30 days.
- Fire a signed postback for it from your own server. The first signed test that passes marks your organisation as verified, which is what allows a CPA hybrid, a verified trial, an API-call offer or an offer to be submitted.
- Every request, live or test, is logged with its headers, body, signature check, outcome and latency, for 30 days. Replay re-runs a logged request's signature check against your current secret; it never records a conversion.
The CPA hybrid
Off-site CPA on VibeFree is always a hybrid: a click floor per click, plus your CPA bid for each conversion your postback reports. The floor must be at least the platform minimum shown in the ad group form and no more than the CPA bid itself. One block is 10 conversions. Paying a little per click is what keeps a campaign honest if reporting stops - VibeFree is not paid only when your own server says so.
The anomaly pause
Once an hour, every live campaign that is paid on postbacks is checked: after enough clicks in the last seven days (200 by default), a conversion rate below a quarter of the campaign's own history - or, with no history, of the format's baseline - pauses the campaign and you are told why. Clicks are not billed while it is paused, and it resumes once a person has checked your postback is reporting every conversion. On the earn page, a run of "I did it but was not rewarded" claims against one advertiser is reviewed as the same kind of signal.
Webhooks
| Event | Sent when |
|---|---|
lead.created | Someone submits a lead-gen card, after its consent step |
survey.response | A respondent completes one of your paid questionnaires |
interview.transcript | An AI chat interview finishes - with personal details already removed |
campaign.status | One of your campaigns changes status - approved, paused or finished, for example |
- Up to 5 endpoints per organisation, each subscribed to the events it wants, with its own secret (it starts
vfwh_). - HTTPS on port 443 to a public host name only - no IP addresses, no localhost, no credentials in the URL. The host is checked again on every delivery, and redirects are not followed, so give the final URL.
- Each delivery is a POST of
{"id", "type", "created", "test", "data"}withX-VibeFree-Event,X-VibeFree-Deliveryand anX-VibeFree-Signaturesigned exactly like a postback, with the webhook's secret. - Answer 2xx within 5 seconds. Otherwise the delivery is retried after 1 minute, 5 minutes, 30 minutes, 2 hours, 6 hours and 24 hours, then marked failed. A test delivery from the tester is tried once and its answer shown straight away.
Frequently asked questions
What is a conversion postback?
A server-to-server request your system sends when someone who clicked your ad converts. VibeFree adds an opaque vf_click_id to your landing URL; you keep it, and when the visitor signs up or buys, your server sends it back, signed. No pixel, cookie or script of VibeFree's runs on your site.
Do I need a tracking pixel to measure VibeFree ads?
No. VibeFree loads nothing from advertisers and asks you to load nothing from it. Views, clicks, completed videos, votes, leads and installs are measured inside VibeFree; conversions on your own site come back by signed postback.
How long is the attribution window?
30 days from the click. A postback for an older click is rejected, and each click converts at most once - a repeat is answered as a duplicate and not counted again.
Why was my postback rejected with a 401?
The signature did not check out: the header is missing or malformed, the HMAC was computed over something other than <t>.<raw body> with your postback secret, or the timestamp is more than 5 minutes from VibeFree's clock. The request log in the sandbox shows which, and replay re-checks a logged request against your current secret.
What happens if my webhook endpoint is down?
A delivery that does not get a 2xx answer within 5 seconds is tried again after 1 minute, 5 minutes, 30 minutes, 2 hours, 6 hours and 24 hours - seven attempts over about 33 hours - and then marked failed. Every attempt is in the delivery log for 30 days.
Open the console to create a secret, see how buying works from draft to live, or see the formats priced on conversions.
Related pages
- The conversational brand agent - A side chat answered from your reviewed docs, billed per first message.
- Sponsored installs and follow-up chips - Pinned packages and MCP servers, dry runs, and every safeguard.
- Sponsored rewards - Opt-in video, quizzes, paid surveys, interviews and trials on the earn page.
- Or browse every VibeFree guide.