Base URL
<your-orbit-functions-host> with your actual Orbit Functions host.
Two actions
The Advertising API supports two query actions:Authentication models
Opaque impression token (clicks)
Opaque impression token (clicks)
Click requests use a 256-bit opaque impression token passed in the query string. The token is hashed with SHA-256 before storage or validation. Raw tokens are never stored.
x-advertiser-token (conversions)
x-advertiser-token (conversions)
Conversion requests require the
x-advertiser-token header. Tokens are stored as SHA-256 hashes. Never send service-role keys to clients.CORS and security
Production CORS uses the comma-separatedORBIT_APP_ORIGINS allowlist. The Edge Function is public because clicks use signed opaque tokens and conversions use hashed advertiser tokens. All billing RPCs are executable only by service_role.
Idempotency
Conversion requests accept anidempotency-key header. Duplicate external_id values or idempotency keys return an accepted duplicate response without a second charge.