Skip to main content
The Advertising API is a public Edge Function that handles click tracking and conversion reporting for Orbit Audience Engine. It is hosted at your Orbit Functions instance.

Base URL

Replace <your-orbit-functions-host> with your actual Orbit Functions host.

Two actions

The Advertising API supports two query actions:

Authentication models

Click requests use a 256-bit opaque impression token passed in the query string. The token is hashed with SHA-256 before storage or validation. Raw tokens are never stored.
Conversion requests require the x-advertiser-token header. Tokens are stored as SHA-256 hashes. Never send service-role keys to clients.

CORS and security

Production CORS uses the comma-separated ORBIT_APP_ORIGINS allowlist. The Edge Function is public because clicks use signed opaque tokens and conversions use hashed advertiser tokens. All billing RPCs are executable only by service_role.

Idempotency

Conversion requests accept an idempotency-key header. Duplicate external_id values or idempotency keys return an accepted duplicate response without a second charge.

Never expose service-role keys

Service-role keys are for server-side use only. Never include them in client-side code, mobile apps, or browser requests.