Setup

Ten steps, in order. Nine of them are clicks, keys, a tag paste or a meeting. One is an engineering task with an app store release, and it is the one everything per user depends on.

2 of 10 complete8 outstanding

The most common misunderstanding: connecting the reporting APIs does not give per-user data. Reporting APIs return aggregates. Per-user revenue comes from the SDK, the web JS tag or the VAST tag, and from nowhere else.

Do these next

Steps you can act on today. Blocked steps are waiting on history or a vendor and are left out.

6 open

The asymmetry

Why this page exists.

7 steps take minutes and no engineering time: monitoring, properties, revenue access, cost access, web and video tags, attribution config, routing setup. 1 step takes weeks, because it needs a code change and a store release.

Start the slow one first. Everything else can be done while it ships.

Value before any grant

Step 1 needs nothing from you.

ads.txt and app-ads.txt are public files. We fetch and monitor them immediately, so the first finding can land before you have granted a single permission.

No access needed
SDK adoption
71%

71% of active users are on an app version carrying the SDK. Adoption ramps as users update their app, not on the release date, so per-user figures cover this share of users and no more. Everything above it is measured on that share, then extended.

  1. 1

    Supply chain monitoring

    Immediate
    No access neededComplete

    We fetch your ads.txt and app-ads.txt from the public web and start monitoring them. Nothing is granted, nothing is configured. This step can produce a finding before you have given us anything at all.

    How access is granted

    No access needed — ads.txt and app-ads.txt are public files

    Unlocks
    • Every seller line mapped and monitored daily
    • Alerts when a line disappears, including what it used to earn
    • sellers.json verification per line
    Does not unlock
    • Revenue per line — that needs revenue access (step 3)
    • Any write access. Hosting your ads.txt is a separate, explicit, opt-in permission

    One finding is already open: a unityads.com line vanished from app-ads.txt and no buyer can purchase that path right now.

    Open Supply ChainDone. Open it to check or change what is connected.
  2. 2

    Properties

    15 minutes
    Minutes, no engineeringComplete

    Declare every app by bundle ID and every web domain. Everything else in Publifter hangs off this list, including campaign mapping and ads.txt monitoring.

    How access is granted

    You type them in — bundle IDs and domains

    Unlocks
    • Property-level grouping across every other page
    • Campaign-to-property mapping on Acquisition
    • The right ads.txt / app-ads.txt files to watch
    Does not unlock
    • Any data at all on its own. This is a declaration, not a connection.
    Declare propertiesDone. Open it to check or change what is connected.
  3. 3

    Revenue access

    20–30 minutes, no engineering
    Minutes, no engineeringIn progress

    Read-only access to your ad revenue reporting. This is the step most publishers expect to give them per-user data. It does not.

    How access is granted

    OAuth click-through and key paste

    Unlocks
    • Revenue totals, by source, placement, geography
    • eCPM, fill rate and no-fill rate
    • Discrepancy checks between networks and your own numbers
    Does not unlock
    • Anything per user. Reporting APIs return aggregates only.
    • Tiers, scoring, routing or spend headroom — all of those need the SDK (step 5).
    • Google AdMob
      OAuth click-through
      Complete
    • Google Ad Manager
      OAuth click-through
      Complete
    • AppLovin MAX
      Key paste from the MAX console
      Server-to-server user-level postback must be switched on by your AppLovin account team. Allow a few days.
      Blocked
    • ironSource / Unity LevelPlay
      Key paste from the LevelPlay console
      Server-side API is next-day and retains 14 days.
      Complete
    • Meta Audience Network
      OAuth click-through
      Aggregate only. Placement x country x day. Never enters a user score.
      Complete
    Link revenue partnersThis is where the work happens.
  4. 4

    Acquisition cost

    20 minutes, no engineering
    Minutes, no engineeringIn progress

    Read-only access to what you spend. Your own credentials, free APIs, no MMP.

    How access is granted

    OAuth click-through, plus CSV upload for the rest

    Unlocks
    • Spend by channel and by campaign
    • Campaign-to-property mapping with naming-pattern suggestions
    Does not unlock
    • Cost joined to ad revenue. That join needs per-user revenue and install attribution — the SDK (step 5) and step 7.
    • Payback, margin or spend headroom.
    • Meta Ads
      OAuth click-through
      Complete
    • Google Ads
      OAuth click-through
      Complete
    • TikTok Business
      OAuth click-through
      In progress
    • Apple Ads
      OAuth click-through
      Not started
    • Influencer / offline
      CSV upload
      No per-user join is possible from a CSV.
      Not started
    Link cost partnersThis is where the work happens.
  5. 5

    SDK integration

    Weeks — an engineering task and an app store release
    Weeks, engineering + releaseIn progress

    This is the only slow step, and no permission grants it. Your engineers add the SDK, you ship a release, and adoption then ramps as users update. Everything per user in Publifter depends on this and on nothing else.

    How access is granted

    Code change in your app, then a store release

    Unlocks
    • Per-impression revenue tied to your own user id
    • User value tiers, deciles and scoring
    • Routing — the per-user ad unit decision
    • Deterministic install attribution on Android and Apple Ads
    Does not unlock
    • Meta Audience Network or AdX revenue per user. Those feeds carry no user id no matter what you ship.
    • Per-user revenue for users who have not updated their app yet.
    • Wordfall Android
      Released 22 Aug — adoption 78%
      Complete
    • Wordfall iOS
      Released 29 Aug — adoption 64%
      In progress
    • northlight.co web pixel
      Tag change, live same day
      Complete

    The SDK captures: impression revenue callbacks, your user ID, the CMP consent string, the Google Play install referrer, the Apple AdServices token, and the routing hook that requests the right ad unit per user.

    Get the snippetsThis is where the work happens.
  6. 6

    Tags and pixels for web and video

    Under an hour per tag, no app release
    Minutes, no engineeringIn progress

    Web and video inventory does not wait for an app release. Three tags cover it: a 1x1 impression pixel you attach to a Google Ad Manager creative, a JS tag for display slots, and a VAST wrapper for video and CTV. Each one reports the same fields as the SDK.

    How access is granted

    You paste a tag into your own ad server — Ad Manager creative or Prebid wrapper

    Unlocks
    • Impression counts and revenue for GAM-served display and video
    • Per-user revenue on web where your own user id is available
    • Discrepancy checks between your Ad Manager numbers and ours
    Does not unlock
    • Per-user revenue for AdX or AdSense demand. Those stay aggregate whichever tag you use.
    • Anything on inventory where no first-party user id exists — those impressions count, but never score.
    • Impression pixel (1x1)
      Third-party impression tracker on the GAM creative
      Complete
    • JS tag
      Pasted into your display slot or Prebid wrapper
      Reads your first-party user id from the page; without it the impression counts but does not score.
      In progress
    • VAST wrapper tag
      Wraps your existing VAST URL for video and CTV
      Macros must be left intact or the impression arrives without a price.
      Not started

    None of these change your Ad Manager configuration. They sit on the creative or in your own wrapper, and you can remove them yourself at any time.

    Copy tagsThis is where the work happens.
  7. 7

    Attribution and organic mapping

    30 minutes, per platform
    Minutes, no engineeringNot started

    Set the attribution method per platform and decide how organic is treated. Organic is identified by elimination, so it inherits every gap elsewhere.

    How access is granted

    Configuration, no new access

    Unlocks
    • Cost joined to revenue per channel
    • Payback and margin per channel
    • Organic separated from paid
    Does not unlock
    • Per-user attribution on iOS for Meta, Google or TikTok. SKAdNetwork is cohort-level for everyone, MMP included.
    Configure attributionThis is where the work happens.
  8. 8

    Baseline freeze

    A meeting, not a task
    Commercial sign-offNot started

    We agree a fixed pre-Publifter revenue-per-user baseline and freeze it. Every uplift figure and every fee is measured against that frozen number. It does not move when yield improves.

    How access is granted

    Joint commercial sign-off — both sides agree and sign

    Unlocks
    • The uplift figure on the dashboard
    • The fee calculation, with AdLynk-sourced revenue carved out
    Does not unlock
    • Anything technical. No data changes when the baseline is signed.
    Review what we readThis is where the work happens.
  9. 9

    Scoring unlock

    Automatic — roughly 30 days of history
    AutomaticBlocked

    User scoring needs about 30 days of per-user impressions. Revenue and concentration views populate within 48 hours; scoring waits. There is nothing to grant or configure here.

    How access is granted

    Nothing to do. It unlocks itself.

    Unlocks
    • Value tiers with live thresholds
    • Suggested floors per tier
    • Segment building on value tier
    Does not unlock
    • Scores for users below 30 days of history. They sit unscored in Core until they qualify.

    19 days of per-user history collected. 11 days to go on current adoption.

    See User ValueWaiting on history or a vendor. Nothing for you to do yet.
  10. 10

    Routing

    1 hour of setup, then a shadow test
    Minutes, no engineeringBlocked

    You create one ad unit per value tier in your own mediation, each with its own floor. Publifter then decides which unit to request per user. We shadow test first, comparing modelled against actual, before anything is enabled.

    How access is granted

    You create the ad units in your own mediation. We never change your config.

    Unlocks
    • Per-tier floors instead of one floor for everybody
    • Modelled versus actual lift, measured
    Does not unlock
    • Any change we make to your mediation. Every unit is created by you; we only choose which one to request.
    Open the floor simulatorWaiting on history or a vendor. Nothing for you to do yet.

Every permission in this sequence is read-only except one: hosting your ads.txt file, which is requested separately and flagged wherever it appears. Nothing here changes your mediation or ad server configuration.