Access & Permissions
This page is the source of truth for what Publifter can see. Every permission below is read-only except one, marked clearly. Toggling one off dims and blocks the pages that depend on it in the sidebar — everything else keeps working.
5 of 7 permissions currently granted. Declining a permission never breaks Publifter as a whole, only the specific pages that read it.
Permissions
Grouped in the order they were requested.
Aggregate ad revenue
Read onlyRequiredVendors: AdMob, Ad Manager, AppLovin MAX, Unity LevelPlay, Meta Audience Network
Scope: adsense.readonly, admanager.readonly, report.read
Reads: Revenue, impressions, fill rate and eCPM by placement, country and day.
Per-impression revenue callbacks
Read onlyVendors: Your app build (AdMob / MAX / LevelPlay SDK), Prebid.js on web
Scope: SDK paid-event listener, client-side only
Reads: Revenue value, precision label and placement for each impression, keyed to your own user id.
Acquisition spend
Read onlyVendors: Meta Marketing API, Google Ads API, TikTok Business API, Apple Ads API
Scope: ads_read, adwords (read-only), Ad Account: read
Reads: Spend, installs and campaign names. Never creatives, audiences or billing details.
Install attribution
Read onlyVendors: Google Play Install Referrer, Apple AdServices, SKAdNetwork postbacks
Scope: Client-side referrer / attribution token
Reads: Which campaign a user came from, where the platform allows it.
Bid landscape (web)
Read onlyVendors: Prebid.js
Scope: Client-side auction event listener
Reads: Every bid, no-bid, timeout and win price. Bidder identity, never buyer identity.
ads.txt / app-ads.txt hosting
Write — the only oneVendors: Your domain (CNAME delegation to Publifter)
Scope: Serve the file at /ads.txt and /app-ads.txt
Reads: Writes the file contents. This is the only write permission in the product.
Cross-publisher benchmarking
Read onlyOff by defaultVendors: Publifter aggregate pool
Scope: Contributes your anonymised eCPM and fill medians
Reads: Sends aggregated metrics out of your account. Off unless you turn it on.
Cross-publisher benchmarking
Shown separately because it sends data out of your account, not just reads it.
If you opt in, Publifter contributes your anonymised eCPM and fill medians to a pool and shows you peer medians in return. It ships off by default and stays off until you flip the switch above.
Never requested
Publifter does not ask for any of the following, on any plan.
- Payment, banking or payout details
- Write access to mediation, waterfall or ad server configuration
- Your end users' names, emails, phone numbers or advertising identifiers
- Creative assets, audience lists or campaign structures in your ad accounts
- Any ability to spend money on your behalf
What you lose by declining
Read this before you decline anything — declining is meant to be a safe, ordinary choice.
| Permission | If you decline it, you lose |
|---|---|
| Aggregate ad revenue |
|
| Per-impression revenue callbacks |
|
| Acquisition spend |
|
| Install attribution |
|
| Bid landscape (web) |
|
| ads.txt / app-ads.txt hosting |
|
| Cross-publisher benchmarking |
|
Right now
Live, based on the switches above.
Based on your current toggles, 2 permissions are declined. The pages that need them are dimmed in the nav and show a plain explanation instead of loading — nothing else in Publifter is affected.
- UnavailableAutomatic dropped-line recovery
- UnavailableChange log authorship (monitoring still works)
- UnavailablePeer median columns