INOTrackfast, reliable, unapologetic

Quickstart: from install to the first conversion

The admin panel is currently available in Russian only; menu items and button labels in this guide are translated.

The whole path can be done in the panel: the "Getting started" checklist shows what is already done, and the "Launch campaign" wizard puts the offer, source, flow and domain together into one setup and gives you the link for the ad account and the postback URL for the affiliate network. The same path through the public API (curl, MCP server) is in the "Same path through the API" appendix at the end.

Instance not installed yet? Start with the install guide, which also covers the 7-day trial (if you have no key) and the free inotrack domains.

1. Sign in to the panel

Open the panel domain you gave the installer (or the free one it assigned) and sign in as the first administrator, using the login and password from the one-time summary at the end of the install.

2FA for the admin. If the administrator has not enabled a second factor yet, the panel opens the "Set up two-factor authentication" screen right after sign-in (QR code → code from the app → backup codes). It does not block sign-in, but the screen shows up on every sign-in until the second factor is set up (details: FAQ (in Russian)).

2. "Getting started": the launch checklist

While the tracker has no data, the dashboard shows a list of launch steps instead of a chart: what is already done (crossed out) and which step is next, with a button that takes you to where it is done. The empty report shows the same next step in one line. The steps:

Step Done when Where to do it
Traffic source there is at least one source "Sources" or the wizard
Offer there is at least one offer "Offers" or the wizard
Flow with an offer there is a flow that contains an offer the wizard, or "Flows" → "New flow"
Tracker domain a domain for clicks is connected "Domains"
First clicks clicks have come in through the flows the flow link in the ad
Advertiser postback a network connection exists in "Postbacks" "Postbacks" → "Connect network"
First conversions at least one conversion has arrived "Postbacks" (check, quarantine)

The "Tracker domain" and "Advertiser postback" steps are team-level setup done by an administrator; they are not shown to a buyer. The easiest way to get through every step up to the flow in one go is the wizard: the "Launch campaign" button is under the empty chart on the dashboard, in the sidebar and on the "Flows" page (hotkey g j).

3. The "Launch campaign" wizard (/launch)

Five steps; you can move back and forth between them, and the draft saves itself, so you can close the wizard and come back to it later.

  1. Offer — pick an existing one or create a new one right in the wizard (the advertiser is created in the same drawer). You can pick several offers; traffic is split between them by weight. The offer URL contains macros (macros reference (in Russian)); {clickid} is required: without it, a postback cannot be matched to a click.
  2. Source — where the traffic comes from. The source defines the platform's click id, the sub macros and the link template for the ad account; when you create a new one, the platform preset is filled in automatically. Without a template, the link has no platform macros, and the reports will not show its campaigns and ads.
  3. Flow — name, offer weights, optionally a landing page (the visitor sees it first, link /f/…) and a bot filter (filters out bots and moderation traffic; the administrator picks the rule set, right away or later on the flow page). ⚠️ The wizard field "Fallback URL (traffic-back)" and the smartlink picker next to it are saved into the flow's trafficback_url, which the click path does not read today — it is not a fallback for a click with no offer. Such clicks (another country, no offer matched) go to the flow's "Fallback", and if it is not set, to the instance-wide fallback. Set it after launch on the flow page: "Fallback URL and uniqueness" → "Fallback" (your own URL, a smartlink, a flow or an offer).
  4. Domain and region — which tracker domain to build the link on and which countries to accept traffic from; clicks from other countries go to the flow's fallback (see above). By default the link is built on the main domain of the pool ("Domains"); if the pool is empty, on INOTRACK_PUBLIC_URL from the installer's .env. If there is neither, the wizard says "Domain is not configured": add a domain in "Domains".
  5. Launch — the "Review and launch" summary; after you confirm, the wizard creates the flow.

The viewer role sees the wizard in read-only mode; only admin and buyer can create entities.

4. The link for the ad account

After the flow is created, the wizard shows the "Link for the platform's ad account": the full tracking link https://<tracker-domain>/go/<token> with the platform's macros from the source template already in it. Copy it in full and paste it into the ad. If the flow has a landing page, the link through the landing page is next to it; if regional edge nodes are connected, there are per-region links.

You can check where the visitor will end up with the "Check" button in the checklist (click check on the flow page) or by hand:

curl -sI "https://<tracker-domain>/go/<token>?sub1=test-site"
# HTTP/2 302, Location: <offer URL with macros substituted>

5. The postback for the affiliate network

Below the links is the "Postback URL for the network's account": the address https://<tracker-domain>/pb/<token> for each advertiser of the selected offers, and the parameters the tracker expects (click id, status, payout). Fill in the parameter values with the network's macros in its own account.

If the advertiser has no connection yet, the wizard says so. The connection is created by an administrator: "Postbacks" → "Connect network" — pick a network preset (the parameter mapping is filled in automatically) or set it up manually. ⚠️ Make sure the mapping has the amount parameter — without it the payout is recorded as zero. Details on formats, the status model and dedup: postbacks (in Russian).

You can make sure the postback is parsed correctly before the first real conversion: in the list of connections, the "Check" button sends a test postback without recording it — with the clickid of the latest real click on the network's offers — and shows the flow, the offer and the amount.

6. The launch checklist and the first conversion

Under the links is the "Launch checklist": the tracker checks some of the items itself (the platform's link template, bot filter, postback connection, sending conversions to the platform), and you tick the rest (link pasted into the ad account, postback URL pasted into the network's account, click check, first click, costs).

  • First click — the "Open in reports" button leads to the report for this flow. Clicks are written to ClickHouse in batches every 1–2 seconds: if the row is not there right away, refresh in a couple of seconds.
  • First conversion — shows up in the live "Conversions" feed and in the reports. If there are clicks but no conversions, the "Getting started" checklist highlights the "First conversions" step: check the postback (step 5) and the quarantine in "Postbacks" — that is where postbacks the tracker could not parse or match to a click end up.
  • Costs — cost-sync from the ad account or manual entry, from the source card.

Appendix: the same path through the API

All of this can be done with the public API — for scripts, bulk creation and the MCP server (working with the tracker from Claude Code, API guide (in Russian)). The easiest way to issue an API token is in the panel: "Settings" → "API tokens" (the "Write" permission is available to admin only); below is how to get one without the panel.

0. Sign in and get an API token

The first administrator was created by the installer (install guide); the login/password are in the one-time summary at the end of the install.

TRACKER=https://panel.example.com

# login — save the session cookie to a file
curl -s -c cookies.txt -X POST "$TRACKER/api/internal/auth/login" \
  -H 'Content-Type: application/json' \
  -d '{"email":"[email protected]","password":"<password from the installer summary>"}'

# issue an API token under this session (scope read+write, to manage entities)
curl -s -b cookies.txt -X POST "$TRACKER/api/v1/tokens" \
  -H 'Content-Type: application/json' \
  -d '{"name":"quickstart","scopes":["read","write"]}'

Save the value of the token field from the response — it is shown only once (after that only the hash is stored). All the examples below use it as $TOKEN.

2FA for the admin. If the administrator has not enabled a second factor yet, the /login response contains "must_setup_2fa": true, and right after sign-in the panel opens the "Set up two-factor authentication" screen (QR code → code from the app → backup codes). It does not block sign-in: the session is already issued, and the curl commands in this section work as usual. Through the API, the second factor is set up like this: POST /2fa/setup → POST /2fa/confirm (see the API guide (in Russian), FAQ (in Russian)). Until it is set up, the screen shows up on every sign-in.

1. Create an advertiser

curl -s -X POST "$TRACKER/api/v1/advertisers" \
  -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' \
  -d '{
    "name": "Test CPA network",
    "kind": "cpa_network",
    "currency": "USD",
    "hold_days": 30,
    "is_active": true
  }'

The response contains the advertiser's id; the offer needs it.

2. Create an offer

curl -s -X POST "$TRACKER/api/v1/offers" \
  -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' \
  -d '{
    "advertiser_id": 1,
    "name": "Test offer RU",
    "url": "https://advertiser.example.com/landing?clickid={clickid}&sub1={sub1}",
    "geo": ["RU"],
    "payout_model": "cpa",
    "payout": 25,
    "currency": "USD",
    "status": "active"
  }'

The offer URL contains macros (full list in the macros reference (in Russian)); {clickid} is required: without it, a postback cannot be matched to a click.

3. Create a traffic source

curl -s -X POST "$TRACKER/api/v1/sources" \
  -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' \
  -d '{
    "name": "My site",
    "kind": "seo_site",
    "sub_mapping": "{\"sub1\": \"site\", \"sub2\": \"page\"}"
  }'

⚠️ sub_mapping (like cost_credentials and pixel_config) is accepted only as JSON encoded as a string — not as a nested object. The endpoint rejects an object in this field (400 bad_request, json: cannot unmarshal object into Go struct field ... of type string). When you create or read a source, the response returns the same field as a regular nested object. This input/output asymmetry is a known rough edge of the API (internal/api/sources.go), not a typo in the example.

4. Create a flow and get the tracking link

A flow connects a source with offers. The flow token (token in the response) is the short link /{token} and the full /go/{token}.

curl -s -X POST "$TRACKER/api/v1/flows" \
  -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' \
  -d '{
    "name": "RU — test offer",
    "source_id": 1,
    "mode": "redirect_302",
    "default_url": "https://example.com/no-offer",
    "offers": [{"offer_id": 1, "weight": 100, "is_active": true}]
  }'

default_url is a required fallback: if no offer fits by geo/weights/caps, traffic goes here instead of a 404 (the traffic is paid for, so you cannot afford to lose it).

The resulting tracking link:

https://<tracker-domain>/go/<token>?sub1=<site>&sub2=<page>

Manual check:

curl -sI "https://<tracker-domain>/go/<token>?sub1=test-site"
# HTTP/2 302, Location: <offer URL with macros substituted>

5. Set up postback intake from the affiliate network

Details on formats, macros and network presets: postbacks (in Russian). The minimal step: create a postback endpoint with a token for a specific network (the postback CRUD endpoint is proxied through /api/v1/postback/...):

curl -s -X POST "$TRACKER/api/v1/postback/endpoints" \
  -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' \
  -d '{
    "AdvertiserID": 1,
    "Name": "Test CPA network",
    "Preset": "custom",
    "ParamMapping": {"clickid": "clickid", "status": "status", "sum": "sum",
      "status_values": {"lead": "lead", "approved": "approve", "reject": "reject"}},
    "IsActive": true
  }'

⚠️ Note the key case: the top level of the body (AdvertiserID, Name, Preset, ParamMapping, IsActive) is capitalized (Go struct field names without JSON tags), while the fields inside ParamMapping (clickid, status, sum, status_values) are lowercase. Two conventions in one body is a known rough edge of the API, not a typo in this example.

⚠️ Do not forget the amount parameter (sum) in the mapping — without it the payout is recorded as zero. Details and the safeguard against this: postbacks (in Russian).

The response contains the endpoint token in the Token field (the response, like the request body, uses capitalized keys: ID, Token, Name…; jq -r .token returns null). The link for the network:

https://<tracker-domain>/pb/<token>?clickid={clickid}&status=approved&sum=25

Put it (or the matching preset) into the network's account.

6. See the first click in the report

Open the tracking link from step 4 (or run curl a few times), then:

curl -s -X POST "$TRACKER/api/v1/reports/query" \
  -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' \
  -d '{
    "dimensions": ["flow_id", "offer_id"],
    "metrics": ["clicks", "uniques"],
    "date_from": "2026-09-24",
    "date_to": "2026-09-25"
  }'

⚠️ /reports/query accepts only POST with a JSON body (GET returns 405), and date_from/date_to (YYYY-MM-DD, inclusive) are required — without them you get 400 bad_request. The dimension names are flow_id/offer_id, not flow/offer (full list: GET /api/v1/reports/dims, list of metrics: GET /api/v1/reports/metrics).

Clicks go into a buffer and are batched into ClickHouse every 1–2 seconds — if the row does not show up right away, wait a couple of seconds and repeat the request. The exact list of reports module paths (/api/v1/reports/...) is in the API guide (in Russian) and internal/api/openapi.yaml.

Next

  • Full reference of offer link and postback macros: macros (in Russian).
  • Postback details (status model, dedup, network presets): postbacks (in Russian).
  • Public API and MCP server (working with the tracker from Claude Code): API (in Russian).
  • Instance maintenance: operations (in Russian).
  • Purchase, trial, USDT payment and free domains: FAQ (in Russian).
Support