Setup
Ten steps, in order. Nine of them are clicks, keys, a tag paste or a meeting. One is an engineering task with an app store release, and it is the one everything per user depends on.
The most common misunderstanding: connecting the reporting APIs does not give per-user data. Reporting APIs return aggregates. Per-user revenue comes from the SDK, the web JS tag or the VAST tag, and from nowhere else.
Do these next
Steps you can act on today. Blocked steps are waiting on history or a vendor and are left out.
- 3Revenue access20–30 minutes, no engineeringLink revenue partners →
- 4Acquisition cost20 minutes, no engineeringLink cost partners →
- 5SDK integrationWeeks — an engineering task and an app store releaseGet the snippets →
- 6Tags and pixels for web and videoUnder an hour per tag, no app releaseCopy tags →
- 7Attribution and organic mapping30 minutes, per platformConfigure attribution →
- 8Baseline freezeA meeting, not a taskReview what we read →
The asymmetry
Why this page exists.
7 steps take minutes and no engineering time: monitoring, properties, revenue access, cost access, web and video tags, attribution config, routing setup. 1 step takes weeks, because it needs a code change and a store release.
Start the slow one first. Everything else can be done while it ships.
Value before any grant
Step 1 needs nothing from you.
ads.txt and app-ads.txt are public files. We fetch and monitor them immediately, so the first finding can land before you have granted a single permission.
71% of active users are on an app version carrying the SDK. Adoption ramps as users update their app, not on the release date, so per-user figures cover this share of users and no more. Everything above it is measured on that share, then extended.
- 1
Supply chain monitoring
ImmediateNo access neededCompleteWe fetch your ads.txt and app-ads.txt from the public web and start monitoring them. Nothing is granted, nothing is configured. This step can produce a finding before you have given us anything at all.
How access is grantedNo access needed — ads.txt and app-ads.txt are public files
Unlocks- — Every seller line mapped and monitored daily
- — Alerts when a line disappears, including what it used to earn
- — sellers.json verification per line
Does not unlock- — Revenue per line — that needs revenue access (step 3)
- — Any write access. Hosting your ads.txt is a separate, explicit, opt-in permission
One finding is already open: a unityads.com line vanished from app-ads.txt and no buyer can purchase that path right now.
Open Supply Chain →Done. Open it to check or change what is connected. - 2
Properties
15 minutesMinutes, no engineeringCompleteDeclare every app by bundle ID and every web domain. Everything else in Publifter hangs off this list, including campaign mapping and ads.txt monitoring.
How access is grantedYou type them in — bundle IDs and domains
Unlocks- — Property-level grouping across every other page
- — Campaign-to-property mapping on Acquisition
- — The right ads.txt / app-ads.txt files to watch
Does not unlock- — Any data at all on its own. This is a declaration, not a connection.
Declare properties →Done. Open it to check or change what is connected. - 3
Revenue access
20–30 minutes, no engineeringMinutes, no engineeringIn progressRead-only access to your ad revenue reporting. This is the step most publishers expect to give them per-user data. It does not.
How access is grantedOAuth click-through and key paste
Unlocks- — Revenue totals, by source, placement, geography
- — eCPM, fill rate and no-fill rate
- — Discrepancy checks between networks and your own numbers
Does not unlock- — Anything per user. Reporting APIs return aggregates only.
- — Tiers, scoring, routing or spend headroom — all of those need the SDK (step 5).
- CompleteGoogle AdMobOAuth click-through
- CompleteGoogle Ad ManagerOAuth click-through
- BlockedAppLovin MAXKey paste from the MAX consoleServer-to-server user-level postback must be switched on by your AppLovin account team. Allow a few days.
- CompleteironSource / Unity LevelPlayKey paste from the LevelPlay consoleServer-side API is next-day and retains 14 days.
- CompleteMeta Audience NetworkOAuth click-throughAggregate only. Placement x country x day. Never enters a user score.
Link revenue partners →This is where the work happens. - 4
Acquisition cost
20 minutes, no engineeringMinutes, no engineeringIn progressRead-only access to what you spend. Your own credentials, free APIs, no MMP.
How access is grantedOAuth click-through, plus CSV upload for the rest
Unlocks- — Spend by channel and by campaign
- — Campaign-to-property mapping with naming-pattern suggestions
Does not unlock- — Cost joined to ad revenue. That join needs per-user revenue and install attribution — the SDK (step 5) and step 7.
- — Payback, margin or spend headroom.
- CompleteMeta AdsOAuth click-through
- CompleteGoogle AdsOAuth click-through
- In progressTikTok BusinessOAuth click-through
- Not startedApple AdsOAuth click-through
- Not startedInfluencer / offlineCSV uploadNo per-user join is possible from a CSV.
Link cost partners →This is where the work happens. - 5
SDK integration
Weeks — an engineering task and an app store releaseWeeks, engineering + releaseIn progressThis is the only slow step, and no permission grants it. Your engineers add the SDK, you ship a release, and adoption then ramps as users update. Everything per user in Publifter depends on this and on nothing else.
How access is grantedCode change in your app, then a store release
Unlocks- — Per-impression revenue tied to your own user id
- — User value tiers, deciles and scoring
- — Routing — the per-user ad unit decision
- — Deterministic install attribution on Android and Apple Ads
Does not unlock- — Meta Audience Network or AdX revenue per user. Those feeds carry no user id no matter what you ship.
- — Per-user revenue for users who have not updated their app yet.
- CompleteWordfall AndroidReleased 22 Aug — adoption 78%
- In progressWordfall iOSReleased 29 Aug — adoption 64%
- Completenorthlight.co web pixelTag change, live same day
The SDK captures: impression revenue callbacks, your user ID, the CMP consent string, the Google Play install referrer, the Apple AdServices token, and the routing hook that requests the right ad unit per user.
Get the snippets →This is where the work happens. - 6
Tags and pixels for web and video
Under an hour per tag, no app releaseMinutes, no engineeringIn progressWeb and video inventory does not wait for an app release. Three tags cover it: a 1x1 impression pixel you attach to a Google Ad Manager creative, a JS tag for display slots, and a VAST wrapper for video and CTV. Each one reports the same fields as the SDK.
How access is grantedYou paste a tag into your own ad server — Ad Manager creative or Prebid wrapper
Unlocks- — Impression counts and revenue for GAM-served display and video
- — Per-user revenue on web where your own user id is available
- — Discrepancy checks between your Ad Manager numbers and ours
Does not unlock- — Per-user revenue for AdX or AdSense demand. Those stay aggregate whichever tag you use.
- — Anything on inventory where no first-party user id exists — those impressions count, but never score.
- CompleteImpression pixel (1x1)Third-party impression tracker on the GAM creative
- In progressJS tagPasted into your display slot or Prebid wrapperReads your first-party user id from the page; without it the impression counts but does not score.
- Not startedVAST wrapper tagWraps your existing VAST URL for video and CTVMacros must be left intact or the impression arrives without a price.
None of these change your Ad Manager configuration. They sit on the creative or in your own wrapper, and you can remove them yourself at any time.
Copy tags →This is where the work happens. - 7
Attribution and organic mapping
30 minutes, per platformMinutes, no engineeringNot startedSet the attribution method per platform and decide how organic is treated. Organic is identified by elimination, so it inherits every gap elsewhere.
How access is grantedConfiguration, no new access
Unlocks- — Cost joined to revenue per channel
- — Payback and margin per channel
- — Organic separated from paid
Does not unlock- — Per-user attribution on iOS for Meta, Google or TikTok. SKAdNetwork is cohort-level for everyone, MMP included.
Configure attribution →This is where the work happens. - 8
Baseline freeze
A meeting, not a taskCommercial sign-offNot startedWe agree a fixed pre-Publifter revenue-per-user baseline and freeze it. Every uplift figure and every fee is measured against that frozen number. It does not move when yield improves.
How access is grantedJoint commercial sign-off — both sides agree and sign
Unlocks- — The uplift figure on the dashboard
- — The fee calculation, with AdLynk-sourced revenue carved out
Does not unlock- — Anything technical. No data changes when the baseline is signed.
Review what we read →This is where the work happens. - 9
Scoring unlock
Automatic — roughly 30 days of historyAutomaticBlockedUser scoring needs about 30 days of per-user impressions. Revenue and concentration views populate within 48 hours; scoring waits. There is nothing to grant or configure here.
How access is grantedNothing to do. It unlocks itself.
Unlocks- — Value tiers with live thresholds
- — Suggested floors per tier
- — Segment building on value tier
Does not unlock- — Scores for users below 30 days of history. They sit unscored in Core until they qualify.
19 days of per-user history collected. 11 days to go on current adoption.
See User Value →Waiting on history or a vendor. Nothing for you to do yet. - 10
Routing
1 hour of setup, then a shadow testMinutes, no engineeringBlockedYou create one ad unit per value tier in your own mediation, each with its own floor. Publifter then decides which unit to request per user. We shadow test first, comparing modelled against actual, before anything is enabled.
How access is grantedYou create the ad units in your own mediation. We never change your config.
Unlocks- — Per-tier floors instead of one floor for everybody
- — Modelled versus actual lift, measured
Does not unlock- — Any change we make to your mediation. Every unit is created by you; we only choose which one to request.
Open the floor simulator →Waiting on history or a vendor. Nothing for you to do yet.
Every permission in this sequence is read-only except one: hosting your ads.txt file, which is requested separately and flagged wherever it appears. Nothing here changes your mediation or ad server configuration.