Skip to main content
The click action of the Advertising API validates impression tokens, records clicks, handles fraud detection, and redirects users to the creative destination. This page explains the request format, behavior, and security model.

Request

string
required
Must be click
string
required
A 256-bit opaque impression token. Raw tokens are never stored; they are hashed with SHA-256 before validation.

Behavior

1

Token hashing

The API hashes the provided token and looks up the matching impression record.
2

One click per impression

At most one click is recorded per impression. Duplicate click attempts are flagged.
3

Fraud detection

Sub-350ms clicks and duplicate clicks are flagged as suspicious and non-billable.
4

CPC debit

For eligible unique clicks, the API atomically debits CPC spend and the organization balance in a single transaction.
5

Safe redirect

The API redirects only to a validated public HTTPS creative URL stored in the database. Non-HTTPS or unvalidated URLs are rejected.

Example

The -L flag follows the redirect to the creative destination.
Replace <your-orbit-functions-host> with your actual Orbit Functions host. The token value is illustrative.