Postback

Whenever a user completes an offer, we will make a call to the Postback URL that you indicated in your app attaching all the information that you will need to credit your users.

Our server will make a HTTP GET request to your server including all the following parameters.

Parameter Description
subId This is the unique identifier code of the user who completed action on your platform.
transId Unique identification code of the transaction made by your user on Tplayad.
reward The exact amount of your virtual currency to be credited to your user.
payout The offer payout in $.
signature MD5 hash that can be used to verify that the call has been made from our servers.
status Determines whether to add or subtract the amount of the reward. "1" is when the virtual currency should be added to the user and "2" when it should be subtracted. This may be because the advertiser has canceled the user's transaction, either because he/she committed fraud or because it has been a mistake entering the data needed to complete the campaign.
userIp The user's IP address who completed the action.
campaign_id Id of the offer completed.
country Country (ISO2 form) from the lead comes
uuid Unique identification code of the click made by your user on Tplayad
"reward" and "payout" parameters are always absolute values, you will need to check status parameter to see if you need to add or subtract that amount from your users.

Security

You should verify the signature received in the postback to ensure that the call comes from our servers. Signature parameter should match MD5 of SUBID TRANSACTIONID REWARD SECRET
You can find your secret key in My Websites section.

The formula to be checked is as follows:

<?php
        $secret = ''; // Get your secret key from Tplayad
        $subId = isset($_REQUEST['subId']) ? $_REQUEST['subId'] : null;
        $transId = isset($_REQUEST['transId']) ? $_REQUEST['transId'] : null;
        $reward = isset($_REQUEST['reward']) ? $_REQUEST['reward'] : null;
        $signature = isset($_REQUEST['signature']) ? $_REQUEST['signature'] : null;
        // Validate Signature
        if (md5($subId . $transId . $reward . $secret) != $signature) {
        echo "ERROR: Signature doesn't match";
        return;
        }
?>

Postback Response

Our server will expect the following answers:

  • "OK" when you receive a new transaction.
  • "DUP" when you receive a duplicate transaction. In this case, our server will stop further attempts for that transaction.

Our servers wait for a response for a maximum time of 60 seconds before the 'timeout'. In this case, it will be retried sending the same transaction up to 5 occasions during the following hours. Please, check if the transaction ID sent to you was already entered in your database. This will prevent giving twice the same amount of virtual currency to the user because of the timeout.