How to Test a New Broker Offer Before You Scale Traffic to It
A controlled testing framework for verifying a new broker offer's real payout, tracking accuracy, and compliance tolerance before committing meaningful traffic.
Also known as: Server-to-Server Postback, S2S Postback, Callback URL, Conversion Postback
A postback URL is a web address used for server-to-server (S2S) conversion tracking. When a qualifying event such as a deposit fires on the broker's servers, the broker sends an HTTP request to this URL, passing the click ID and event data straight to the affiliate's tracker.
Unlike cookie or pixel tracking, no browser is involved at conversion time. The broker's server talks directly to the affiliate's server, so ad-blockers, cleared caches, iOS restrictions, and privacy browsers cannot interfere. This makes S2S the most reliable attribution method available to partners.
The flow depends on a shared click ID. When a user clicks, the tracker generates a unique click ID and passes it to the broker inside the landing URL. The broker stores it against the new account. On conversion, the broker fires the postback URL with that click ID appended, for example https://track.affiliate.com/postback?cid=abc123&payout=250, and the tracker matches the ping to the original click. Example: an affiliate runs TikTok ads, configures a postback in the broker portal, and when a referred user deposits, the broker pings the URL, updating Voluum and relaying the conversion signal back to TikTok to sharpen ad targeting.
Because postbacks are essential for optimizing paid-media algorithms, professional media buyers treat broker support for S2S as a hard requirement before running any traffic.
The tracker generates a unique click ID at the moment of the click and passes it to the broker inside the destination URL as a parameter. The broker stores that click ID against the user's account when they register.
When the account later triggers a tracked event — first deposit, KYC approval, or a volume milestone — the broker's server sends an HTTP request to the affiliate's postback URL with the click ID and payout data attached. The tracker receives the ping, matches the click ID to the original click, records the conversion, and can then relay it onward to the ad network's conversion API. Because the whole exchange happens server-to-server, it is immune to browser-side blocking.
The tracker creates a unique click identifier when the user clicks your ad.
The click ID travels in the landing URL and is stored against the new registration.
You register your tracker's postback address and macros in the broker's partner portal.
On a deposit or milestone, the broker's server calls your postback URL with the click ID and payout.
The tracker matches the click ID, logs the conversion, and forwards the signal to the ad platform's API.
Why it matters for partnership: Postbacks are the most accurate, block-proof way to track CPA campaigns and to feed conversions back to ad platforms like TikTok, Meta, and Google. Serious media buyers will not run paid traffic to a broker that cannot support server-to-server postbacks.
An affiliate driving Google Ads to Exness sets a postback URL in the Exness partner portal pointing to their Keitaro tracker. A referred trader deposits $500; Exness fires the postback with the click ID and payout, Keitaro logs the CPA conversion, and relays it to Google's conversion API so the campaign optimizes toward similar high-value users.
| Attribute | Postback (S2S) | Pixel / cookie |
|---|---|---|
| Where it runs | Server-to-server | In the browser |
| Blocked by ad-blockers? | No | Often yes |
| Affected by iOS/ITP? | No | Yes |
| Setup difficulty | Higher | Lower |
| Best for | Paid CPA media buying | Simple link affiliates |
Pass a dynamic {click_id} macro in your landing URL so the postback can match the exact click to the exact deposit; without it, conversions arrive with nothing to attribute them to.
Misconfiguring the macros or parameters in the postback URL causes the tracker to reject the ping because the click ID is missing, so real conversions never register.
For reliability, yes. Server-to-server postback tracking operates independently of the user's browser, so ad-blockers, cleared cookies, and iOS restrictions cannot break it.
A click ID is a unique identifier generated at the click and passed to the broker. The postback uses it to match the conversion back to the exact click, so it is essential.
Practically yes. Tools like Voluum, Binom, or Keitaro receive the postback ping, log the conversion, and relay it to ad networks.
Yes. Trackers forward the server-side conversion to each platform's conversion API, which helps the ad algorithm optimize toward converting users.
The usual cause is a missing or mismatched click ID macro, so the tracker receives the ping but cannot match it to a recorded click.
Yes. The broker's server initiates the ping, so if the broker's portal does not offer S2S postback configuration, you cannot use it there.
A controlled testing framework for verifying a new broker offer's real payout, tracking accuracy, and compliance tolerance before committing meaningful traffic.
Most "CPA shaving" is actually cookie expiry and misconfigured tracking, not fraud. Here's how to build an attribution setup that resists both.
For performance affiliates, the broker offer is the biggest variable in your P&L. Here is how to evaluate EPC, qualification terms, clawback, tracking, and geo before …
Sub-ID tracking attaches a custom identifier to every affiliate link so you can see exactly which channel, campaign, or piece of content drove each conversion.
A practical guide to how postback URLs and server-to-server tracking report conversions reliably, the parameters that must match for them to fire, and how to test …
How to build one consistent tracking taxonomy, centralize reporting, and reconcile conversions across several broker, exchange, or prop-firm partnerships at once.