Skip to content
For casino and affiliate-platform developers

Postbackintegration

We add our click id to your affiliate link, and when that player makes a first deposit, your tracker calls one URL on our side with the same id. No SDK and no pixel, just one shared secret.

Endpoint
https://highrollers.club/api/postback
Methods
GET or POST
Auth
X-Postback-Secret header
Event
first deposit

Step 1 · outbound

How our click idreaches you

  1. 01

    A player presses the registration button on our site and goes through our redirect, /api/go/<casino>.

  2. 02

    We record the click and give it an id: a UUID v4, 36 characters, lower case.

  3. 03

    A 302 redirect sends the player to your affiliate link, with that id in the parameter you named.

The parameter name is yours

Use whatever your tracker reports on: sub_id, subid, sub1, click_id, var1. Tell us the name and we set it for your brand. Until a name is set, your link goes out exactly as you gave it, with nothing appended. The same happens on the rare click we fail to record: that visit reaches you without an id.

Your link, the parameter sub1, and what the player actually opens:

Your link

https://track.your-casino.example/r/AFF123

The player opens

https://track.your-casino.example/r/AFF123?sub1=9b1deb4d-3b7d-4bad-9bdd-2b0d7b3dcb6d
  • Macros get filled

    If the parameter is already in your link with a macro such as {click_id}, [subid] or <sub>, we replace the macro with the click id.

    https://track.your-casino.example/r/AFF123?sub1={click_id}
    https://track.your-casino.example/r/AFF123?sub1=9b1deb4d-3b7d-4bad-9bdd-2b0d7b3dcb6d

  • Real values stay

    If the parameter already carries a real value, usually your own affiliate tag, the link goes out untouched and without a click id. Pick a parameter your affiliate code does not use.

    https://track.your-casino.example/r/AFF123?sub1=AFF123
    https://track.your-casino.example/r/AFF123?sub1=AFF123

  • One click, one id

    Every click gets a new id, so a player who clicks twice arrives with two. Send back the one that came with the registration, exactly as you received it; the match is case-sensitive.

Step 2 · inbound

Send usthe deposit

https://highrollers.club/api/postback

GET with a query string, or POST with a JSON or form-encoded body. For POST we read the body, and the query string counts only when there is no body we can parse.

Authentication

We share one secret with you privately; it is never on this page. Send it in the X-Postback-Secret header.

If your tracker cannot set headers, pass it as a secret parameter instead. That works, but the secret then lands in every access log along the way, and we may switch the parameter off once all partners use the header.

Requests carry no signature, which makes the secret the only check: the call has to come from your server, never from a pixel in the browser.

Parameters

  • clickIdrequired

    The click id we added to your link, as received. 8 to 100 characters.

  • amountoptional

    The deposit amount. For reference: we store the number and convert no currencies.

  • revenueoptional

    Your payout to us for this player, CPA or revenue share. It tells us which traffic pays off.

  • eventoptional

    A label of up to 50 characters. We accept it and ignore it for now.

  • secretoptional

    Only when the header is not an option, see above.

The name is clickId, in camelCase. We do not read click_id or clickid, and such a request fails with 400.

Numbers take digits and a dot for decimals: 2500 or 2500.50, not 2,500 or $2500. Anything from zero to 100,000,000.

An empty value such as amount= from an unfilled macro counts as not sent rather than as zero. Parameters we do not know are ignored.

Send first deposits only

Every accepted postback marks the click as a deposit, whatever event says. A registration postback would count as a deposit too, so point only your first-deposit event at this URL.

Examples

GET, secret in the header

curl -G 'https://highrollers.club/api/postback' \
  -H 'X-Postback-Secret: YOUR_SECRET' \
  --data-urlencode 'clickId=9b1deb4d-3b7d-4bad-9bdd-2b0d7b3dcb6d' \
  --data-urlencode 'amount=2500' \
  --data-urlencode 'revenue=750'

POST, JSON body

curl -X POST 'https://highrollers.club/api/postback' \
  -H 'Content-Type: application/json' \
  -H 'X-Postback-Secret: YOUR_SECRET' \
  -d '{"clickId":"9b1deb4d-3b7d-4bad-9bdd-2b0d7b3dcb6d","amount":2500,"revenue":750}'

Tracker template, when headers are not an option

https://highrollers.club/api/postback?clickId={sub1}&amount={deposit_amount}&revenue={payout}&secret=YOUR_SECRET

Swap the {…} macros for the ones your tracker uses.

YOUR_SECRET and the click id are placeholders. Use the secret we sent you and a click id from a real click.

What comes back

Responsesand retries

  • 200{"ok":true}

    Deposit recorded.

  • 200{"ok":true,"idempotent":true}

    This click already had a deposit. Nothing changed.

  • 400{"error":"invalid parameters"}

    clickId is missing, shorter than 8 or longer than 100 characters; a number is not a number, is negative or above the cap; or event runs past 50 characters.

  • 401{"error":"unauthorized"}

    The secret is missing or wrong.

  • 404{"error":"unknown clickId"}

    We have no click with that id. Check that you send the value you received, taken from the parameter we filled.

  • 500{"error":"internal error"}

    Something failed on our side. Retry later with the same parameters.

  • 503{"error":"postback disabled"}

    The endpoint is switched off on our side. Write to us.

We check the secret first, then the parameters, and only then look the click up.

Retry on 500, 503 and network errors: a repeated postback cannot create a second deposit. A 400, 401 or 404 will keep coming back until you change the request.

Duplicates

The first postbackwins

  • The first accepted postback for a click records the deposit: amount, revenue and the time it arrived. Our team gets one notification.

  • Any later postback for the same click returns 200 with "idempotent": true and changes nothing, even if the amount or revenue differ. Two calls landing at the same moment still leave a single record.

  • So send the amount and revenue with the first call. Repeat deposits by the same player are not recorded here.

  • A click id does not expire: a deposit made weeks after the click still matches.

Getting connected

Four stepsto go live

  1. 01

    Tell us the name of the sub-id parameter your tracker reports on.

  2. 02

    We set it for your brand and send you the secret privately.

  3. 03

    Check the secret without touching any data: send a postback with a made-up clickId of 8 characters or more. 404 unknown clickId means the secret passed, and 401 means it did not.

  4. 04

    Point your first-deposit postback at the endpoint. The first real deposit shows up on our side at once.

Questions about the integration: