click action of the Advertising API validates impression tokens, records clicks, handles fraud detection, and redirects users to the creative destination. This page explains the request format, behavior, and security model.
Request
string
required
Must be
clickstring
required
A 256-bit opaque impression token. Raw tokens are never stored; they are hashed with SHA-256 before validation.
Behavior
1
Token hashing
The API hashes the provided token and looks up the matching impression record.
2
One click per impression
At most one click is recorded per impression. Duplicate click attempts are flagged.
3
Fraud detection
Sub-350ms clicks and duplicate clicks are flagged as suspicious and non-billable.
4
CPC debit
For eligible unique clicks, the API atomically debits CPC spend and the organization balance in a single transaction.
5
Safe redirect
The API redirects only to a validated public HTTPS creative URL stored in the database. Non-HTTPS or unvalidated URLs are rejected.
Example
-L flag follows the redirect to the creative destination.
Replace
<your-orbit-functions-host> with your actual Orbit Functions host. The token value is illustrative.