> ## Documentation Index
> Fetch the complete documentation index at: https://documentation.orbitdev.org/llms.txt
> Use this file to discover all available pages before exploring further.

# Track Ad Clicks with the Advertising API

> Use the Advertising API click action to track eligible clicks. Learn about token validation, fraud detection, CPC charging, and safe redirects.

The `click` action of the Advertising API validates impression tokens, records clicks, handles fraud detection, and redirects users to the creative destination. This page explains the request format, behavior, and security model.

## Request

<ParamField query="action" type="string" required>
  Must be `click`
</ParamField>

<ParamField query="token" type="string" required>
  A 256-bit opaque impression token. Raw tokens are never stored; they are hashed with SHA-256 before validation.
</ParamField>

```text theme={"dark"}
GET https://<your-orbit-functions-host>/functions/v1/advertising-api?action=click&token=<token>
```

## Behavior

<Steps>
  <Step title="Token hashing">
    The API hashes the provided token and looks up the matching impression record.
  </Step>

  <Step title="One click per impression">
    At most one click is recorded per impression. Duplicate click attempts are flagged.
  </Step>

  <Step title="Fraud detection">
    Sub-350ms clicks and duplicate clicks are flagged as suspicious and non-billable.
  </Step>

  <Step title="CPC debit">
    For eligible unique clicks, the API atomically debits CPC spend and the organization balance in a single transaction.
  </Step>

  <Step title="Safe redirect">
    The API redirects only to a validated public HTTPS creative URL stored in the database. Non-HTTPS or unvalidated URLs are rejected.
  </Step>
</Steps>

## Example

```bash theme={"dark"}
curl -L "https://<your-orbit-functions-host>/functions/v1/advertising-api?action=click&token=abc123..."
```

The `-L` flag follows the redirect to the creative destination.

<Note>
  Replace `<your-orbit-functions-host>` with your actual Orbit Functions host. The token value is illustrative.
</Note>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.