Webhooks push a JSON payload to a URL you choose the moment something happens — a link gets clicked, or a conversion comes in — instead of you having to poll the dashboard or API for updates.
Setting one up
- Go to Webhooks in your account menu.
- Enter your endpoint URL. It must be HTTPS, and can't point at a private or internal address (localhost, an internal IP, etc.) — we validate this both when you save it and again on every delivery.
- Save. Every click and conversion on your links now POSTs to that URL automatically.
Verifying a request actually came from us
Every request includes an X-Affilink-Signature header — an HMAC-SHA256 hash of the raw request body, keyed with your signing secret (shown on the same page). Recompute that hash yourself with your secret and compare it to the header; if they don't match, discard the request. Click Regenerate secret if you ever need to invalidate the old one — do this immediately if you suspect it's leaked, since anything still checking against the old secret will start failing until you update it.
Events
link.clicked— fires on a tracked click (the same ones that count toward your monthly click total).link.converted— fires when an affiliate network reports a sale via your postback URL.
Both event types are sent to the same URL; the payload's event field tells you which one it is.
If your endpoint is slow or down
A delivery that fails retries automatically a few times before giving up. Check Recent deliveries on the Webhooks page to see every attempt, its response status, and whether it ultimately succeeded — useful for debugging an integration without needing your own logging.
Webhooks are available on Business (see plan comparison).