Developers
Yousie SDK documentation
The Yousie SDK tells Yousie which installs and subscriptions came through a creator’s link. This page takes you from your SDK key to a tested integration, on Android, on Flutter, or with plain HTTP calls. It also says how installs are counted on iPhone.
Last updated: . SDK version 1.0.0, MIT licence.
1. What the SDK does
Yousie is a platform where brands list a mobile app and creators promote it. Each creator gets a personal tracking link to the app’s store page. The Yousie SDK (software development kit) is a small library inside your app. It tells Yousie which installs and which subscriptions came through those links, in two steps:
- The install. On the first launch the SDK reads the Google Play install referrer: the text Google Play hands to an app that was installed from a link. If the install came through a creator’s link, the referrer carries a click ID (
yclid), and the SDK reports the install to Yousie once. Yousie then attributes it: it credits the install to that click, and so to the creator. - The subscription. When that install buys a subscription, the SDK reports it. Yousie books it as pending.
Confirming subscriptions stays your job. A pending subscription counts only once you confirm it: by hand on the page of your campaign (the offer creators join for your app), or from your server with your postback secret, a key only your server holds (section 4). The SDK never holds that secret.
An install that did not come through a Yousie link costs one referrer read on the first launch and nothing afterwards: no network call, no billing connection.
2. Before you start
Your SDK key
The SDK key says which app is reporting. It starts with ysk_. In your dashboard, open My Apps, open your app, and copy SDK key from the Tracking keys panel. The key is public, so it is safe to ship inside your app.
No app on Yousie yet? Create a brand account, then add your app in My Apps.
Your other key is the postback secret, which starts with yss_. Yousie shows it once, when the app is added, and again only when you create a new one in the same panel. It stays on your server, never inside the app.
Your Android package
The Android package of your app on Yousie must be your app’s real package: the application ID it has on Google Play, such as com.example.app. A creator’s link sends people to the Google Play page of that package, and Google Play hands the referrer only to the app installed from that page. With a wrong package the link opens the wrong page, and no install is attributed.
Check it on your app’s page in My Apps, under App details, in the field Android package. It cannot be changed once the app is added.
Requirements
- Android 5.0 (API 21) or newer.
- Android only. On iOS the Flutter calls do nothing.
- Automatic purchase tracking needs Google Play Billing Library 7 or newer in your app (Google’s library for in-app purchases). With an older one, or to send the price and the trial, call
trackSubscriptionyourself. - For the Flutter plugin: Flutter 3.47 or newer, and Android 7.0 (API 24) or newer.
3. Add tracking to your app
Choose how your app talks to Yousie. With the SDK there are five steps: install, start, consent, subscriptions, test. On iPhone there is no SDK: the iPhone tab says how installs are counted there.
Android (Kotlin)
1. Install
The library is published through JitPack, a public repository that builds a library from its GitHub source. Add JitPack to the repositories of settings.gradle.kts:
dependencyResolutionManagement {
repositories {
google()
mavenCentral()
maven { url = uri("https://jitpack.io") }
}
}Then add the SDK to your app module, in app/build.gradle.kts:
dependencies {
implementation("com.github.Yousie-com:yousie-sdk:1.0.0")
}2. Start
Start the SDK once, in Application.onCreate, with your SDK key:
import android.app.Application
import com.yousie.sdk.Yousie
import com.yousie.sdk.YousieConsent
class MyApp : Application() {
override fun onCreate() {
super.onCreate()
Yousie.init(this, "ysk_your_sdk_key", YousieConsent.GRANTED)
}
}The third argument is the consent state. With YousieConsent.GRANTED the SDK reports at once.
3. Consent
If your app asks its users for consent, start with UNKNOWN and state the answer when you have it:
// App with a consent form: start with UNKNOWN, then state the answer.
Yousie.init(this, "ysk_your_sdk_key", YousieConsent.UNKNOWN)
// later, when the user has answered:
Yousie.setConsent(YousieConsent.GRANTED) // or YousieConsent.DENIEDWhat each state does is in section 5.
4. Subscriptions
Automatic, by default. The SDK reads your app’s Google Play Billing purchases, only on installs that came through a creator’s link. An automatic report carries the product ID and the order ID. It does not carry the price, or whether the purchase is a trial.
Manual. To send the price and the trial, report the purchase yourself:
Yousie.trackSubscription(
productId = "premium_yearly",
orderId = purchase.orderId,
purchaseToken = purchase.purchaseToken,
price = 29.99,
currency = "EUR",
trial = true,
)Reporting the same purchase twice is safe: Yousie keeps one. The purchase token is only hashed on the phone, never stored or sent.
The price your app reports is shown to you when you confirm. It never sets what you pay.
The options of init, all optional, with their defaults:
import com.yousie.sdk.YousieOptions
Yousie.init(
this, "ysk_your_sdk_key", YousieConsent.GRANTED,
YousieOptions(
autoTrackPurchases = true, // false: only trackSubscription() reports purchases
logging = false, // true: prints what the SDK does under the logcat tag "Yousie"
),
)If you report purchases yourself, set autoTrackPurchases to false. Yousie keeps the first report it receives for a purchase, and an automatic one, without the price, could arrive first.
5. Test your integration
A build you install yourself, from Android Studio, with adb or from a file, is sideloaded: it gets no referrer from Google Play. In a debuggable build (a debug build, not the one you release) you can hand the SDK one. A release build ignores these options.
import com.yousie.sdk.YousieOptions
Yousie.init(
this, "ysk_your_sdk_key", YousieConsent.GRANTED,
YousieOptions(
logging = true,
debugReferrer = "utm_source=yousie&utm_medium=affiliate&utm_campaign=<code>&yclid=<click id>",
debugReset = true, // forget the SDK's saved state at each start, so the flow replays
),
)Replace <code> and <click id> with a real link code and a real click ID. Get a click ID for your test says where to find them.
Then start the app and watch what the SDK does:
adb logcat -s YousieIt shows lines such as install: attributed ins_…. A refusal is printed with its reason, for example install: not attributed (click_used).
debugReset makes the SDK forget what it saved at each start, so the flow replays. The same click ID can be replayed on the same phone, and Yousie repeats its first answer. Another click ID counts as another install.
Flutter
1. Install
Add the plugin to pubspec.yaml. It comes from the SDK’s Git repository, at the tag 1.0.0:
dependencies:
yousie:
git:
url: https://github.com/Yousie-com/yousie-sdk.git
path: flutter
ref: 1.0.0There is nothing to add in the Android folder: the plugin brings the Kotlin code and its own manifest lines.
2. Start
Start the SDK once, in main, with your SDK key:
import 'package:yousie/yousie.dart';
void main() {
WidgetsFlutterBinding.ensureInitialized();
Yousie.init(sdkKey: 'ysk_your_sdk_key', consent: YousieConsent.granted);
runApp(const MyApp());
}consent is the consent state. With YousieConsent.granted the SDK reports at once. On iOS the calls do nothing.
3. Consent
If your app asks its users for consent, pass YousieConsent.unknown to init and state the answer when you have it:
Yousie.setConsent(YousieConsent.granted); // or YousieConsent.denied / YousieConsent.unknownWhat each state does is in section 5.
4. Subscriptions
Automatic, by default. The SDK reads your app’s Google Play Billing purchases, only on installs that came through a creator’s link. An automatic report carries the product ID and the order ID. It does not carry the price, or whether the purchase is a trial.
Manual. To send the price and the trial, report the purchase yourself:
Yousie.trackSubscription(
productId: purchase.productID,
orderId: purchase.purchaseID,
purchaseToken: purchase.verificationData.serverVerificationData,
price: 29.99,
currency: 'EUR',
trial: true,
);Reporting the same purchase twice is safe: Yousie keeps one. The purchase token is only hashed on the phone, never stored or sent.
The price your app reports is shown to you when you confirm. It never sets what you pay.
Options are named parameters of init: autoTrackPurchases (default true), logging (default false), debugReferrer and debugReset (debug builds only).
If you report purchases yourself, pass autoTrackPurchases: false. Yousie keeps the first report it receives for a purchase, and an automatic one, without the price, could arrive first.
5. Test your integration
A build you install yourself, with flutter run, with adb or from a file, is sideloaded: it gets no referrer from Google Play. In a debug build you can hand the SDK one. A release build ignores these options.
Yousie.init(
sdkKey: 'ysk_your_sdk_key',
consent: YousieConsent.granted,
logging: true,
debugReferrer: 'utm_source=yousie&utm_medium=affiliate&utm_campaign=<code>&yclid=<click id>',
debugReset: true,
);Replace <code> and <click id> with a real link code and a real click ID. Get a click ID for your test says where to find them.
Then start the app and watch what the SDK does:
adb logcat -s YousieIt shows lines such as install: attributed ins_…. A refusal is printed with its reason, for example install: not attributed (click_used).
debugReset makes the SDK forget what it saved at each start, so the flow replays. The same click ID can be replayed on the same phone, and Yousie repeats its first answer. Another click ID counts as another install.
iPhone (iOS)
On iPhone there is nothing to install. The App Store gives an app no install referrer, so no SDK can tell which link an install came from. Yousie uses Apple’s own campaign links instead: Apple counts the installs of each creator’s link, and you read them in App Store Connect.
1. Give Yousie your App Store details
On your app’s page in My Apps, under App details, fill in two fields:
- App Store ID. The number in your app’s App Store address, after
id. - App Store provider ID. The number of your App Store Connect account. You find it in App Store Connect, under Users and Access.
Without the App Store ID an iPhone is sent to Google Play. Without the provider ID Apple does not count the links.
2. What a creator’s link does on an iPhone
Yousie records the tap, then opens your App Store page with two values Apple reads: pt, your provider ID, and ct, the name of the campaign. Each creator’s link has its own code, so each creator is one campaign:
https://apps.apple.com/app/id<App Store ID>?pt=<provider ID>&ct=yousie_<link code>&mt=83. Read the installs in App Store Connect
Apple lists each creator as a campaign named yousie_<link code>. You find the campaigns in App Store Connect, under Analytics, in Acquisition. The Creators table on your campaign’s page in Yousie gives the link code of each creator.
Apple’s analytics reports carry the same campaign name next to downloads and purchases.
4. What Yousie books
Yousie counts the taps that come from iPhones. It does not book iPhone installs or subscriptions yet: they do not show in your campaign, and no payout is booked for them. Until that changes, App Store Connect is where you read them.
- Apple gives totals for each link, never single installs.
- The figures are complete about two days later.
- Apple applies privacy rules to these figures: small numbers can be left out, so a creator with few installs may show nothing.
- On an iPhone the Flutter calls do nothing: there is nothing for the app to report.
HTTP API (no SDK)
The SDK makes two HTTP calls. An app that cannot take the SDK can make them itself: any Android code that reads the Play install referrer and sends an HTTPS request will do. Each request carries JSON, and what is left in <angle brackets> is yours to fill.
1. Report the install
On first launch, read the Play install referrer. An install that came through a creator’s link carries a yclid value:
utm_source=yousie&utm_medium=affiliate&utm_campaign=<code>&yclid=<click id>Create an ID for this install (a UUID works), keep it, and send both once. Without a yclid, send nothing.
POST https://yousie.com/api/v1/installs
Content-Type: application/json
{
"sdk_key": "ysk_your_sdk_key",
"click_id": "<the yclid value of the install referrer>",
"install_id": "<an ID you create once for this install>",
"platform": "android",
"app_version": "<your app version>"
}app_version is optional. A 200 answer is final, whether the install was attributed or not. If the call fails, try again on a later launch.
Send this request from the app itself, not through your server. A campaign can pay a different price for an install in each country, and the country is the one the request comes from.
{ "attributed": true, "install": "ins_…" }
{ "attributed": false, "reason": "…" }2. Report a subscription
When someone subscribes, send the purchase with the same install ID. It is booked as pending.
POST https://yousie.com/api/v1/events
Content-Type: application/json
{
"sdk_key": "ysk_your_sdk_key",
"install_id": "<the same install ID>",
"event": "subscription",
"external_id": "<the order ID from the store>",
"product_id": "<the product ID>",
"price_micros": <the price in millionths: 4.99 is 4990000>,
"currency": "<the currency of the price, like EUR>",
"trial": <true or false>
}product_id, price_micros, currency and trial are optional. The price is shown to you when you confirm. It never sets what you pay. The same purchase sent again gets the first answer again, so a retry is safe.
{ "recorded": true, "conversion": "cnv_…", "status": "pending" }
{ "recorded": false, "reason": "…" }3. Consent
The API has no consent state: it records what it receives. If your app asks its users for consent, send nothing until their answer allows it.
4. Test your integration
Send the install request by hand with a real click ID. Get a click ID for your test says where to find one. The answer says whether the install was attributed and, when it was not, why (section 9).
Get a click ID for your test
A click ID is the 22 letters and digits Yousie gives each click on a creator’s link. A test needs a real one.
- Check that your campaign is live. A link records clicks only while its campaign is live.
- Take a link of your campaign. Its address is
https://yousie.com/c/<code>, and the Creators table on the campaign’s page lists the link code of each creator who joined. - Open the link in a desktop browser. Yousie records the click and sends you to your app’s Google Play page. The address of that page ends with the referrer: the click ID is the 22 characters after
yclid%3D. - Start your app, or send the request, with that click ID. A click counts for one install.
A test install is a real one
Yousie cannot tell a test from a real install. It shows in your campaign and counts at the campaign’s install payout, for the creator whose link you used.
If you cannot get a click ID, write to us.
4. Confirm subscriptions from your server
A subscription your app reports is booked as pending. Once the payment is real, confirm it with your postback secret. You pay for confirmed subscriptions only.
The confirmation is a postback: a request your own server sends to Yousie, with the secret in its Authorization header.
POST https://yousie.com/api/v1/postback
Authorization: Bearer <your postback secret>
Content-Type: application/json
{
"event": "subscription",
"action": "confirm",
"external_id": "<the same order ID>"
}external_idis the order ID the app reported. You can name the purchase by the app’s install ID instead (install_id), or send both.- Send
rejectas the action to turn one down. - If your campaign pays a share of the subscription price, the confirmation states that price, in the campaign’s currency and in millionths: 4.99 is 4990000.
POST https://yousie.com/api/v1/postback
Authorization: Bearer <your postback secret>
Content-Type: application/json
{
"event": "subscription",
"action": "confirm",
"external_id": "<the same order ID>",
"amount_micros": <the subscription price in your campaign’s currency, in millionths>
}You can also confirm or reject each one by hand, on the campaign’s page under Campaigns in your dashboard.
Keep the secret on your server, never inside the app. If it may have leaked, create a new one in the Tracking keys panel: the old one stops working at once.
5. Consent
Consent is your user’s answer when your app asks whether it may share data about them. The SDK sends nothing until it knows that answer. You give it to init and change it with setConsent. It has three states:
| Kotlin | Flutter | What the SDK does |
|---|---|---|
UNKNOWN | unknown | No answer yet. The click ID waits on the phone, for 7 days at most. Nothing is sent. |
GRANTED | granted | The install is reported. |
DENIED | denied | The click ID is deleted and nothing is sent. A later GRANTED sends nothing for this install. |
The attribution window is the number of days after a click during which an install still counts. Yousie counts it from the click, whenever the answer comes: an install reported after the window is answered expired (section 7).
Whether your app has to ask, and how, depends on the law that applies to it. This page does not decide that for you.
6. Privacy
What leaves the phone
| Report | What it carries |
|---|---|
| Install | The SDK key, the click ID, a random install ID made for Yousie only (a UUID), the word android for the platform, and the app version. |
| Subscription | The SDK key, the same install ID, the store’s order ID (or tok: and a hash of the purchase token when there is no order ID), the product ID, the price and its currency when given, and the trial flag. |
What never leaves it
The SDK never reads or sends the advertising ID, the Android ID, the device model, the purchase token itself, or any account or contact data.
What Yousie keeps
- For an attributed install: the install ID, the click ID and, through the click, the app, the campaign and the creator’s link. Then the platform, the app version, the time of the click and the time of the report.
- Where an install report came from: the two-letter country of the request, and a keyed hash of its network address (the IP address). The hash is a fingerprint made with a secret key. Yousie uses it to cap repeated installs from one address. The address itself is not stored.
- For a refused install report: the app, the click ID, the install ID, the reason, the same hash and the time. It is kept for fraud review.
- For a subscription: the order ID, the product ID, the trial flag, the price and currency as reported. Then your decision, its time, and the price you state when a confirmation needs one.
The click comes first, in a browser and outside your app: when someone follows a creator’s link, Yousie records the click ID, the platform, the country, the same keyed hash and the browser’s user agent. How long records are kept is in the privacy policy.
What you have to declare
The SDK sends this data from your users’ phones, so declaring it is your job as the app’s developer.
- Google Play’s Data safety form. The form covers what the libraries inside your app send, not only your own code. Look at two of its data types: “Device or other IDs” for the install ID, and “Purchase history” for a subscription report. Google’s instructions for the form (opened October 9, 2026) define each type.
- Your app’s privacy policy. Say that your app tells Yousie about the installs and the subscriptions that come through a creator’s link, and list the data above.
The Terms of Sale make informing your users your responsibility, and the privacy policy says what Yousie does with the data. This section is practical guidance, not legal advice.
7. Limits today
- Android only. Installs are tracked on Android today. A tap from an iPhone is counted and sent to the App Store when the brand has given its App Store ID; the install that follows is not attributed yet.
- One subscription per install. Yousie books one subscription for an attributed install. A second purchase by the same install is answered
duplicate. - One install per click. A click counts for one install, and an install is attributed once.
- The attribution window. An install counts when your app reports it within the campaign’s attribution window, counted from the click. The window is 7 days by default. You set it on the campaign’s page, in Attribution window (days), from 1 to 30 days.
- Waiting for consent. While consent is
UNKNOWN, the SDK keeps a click ID for 7 days at most, whatever the window.
8. Coming next
Integrations with other platforms and with measurement partners will be documented on this page.
- iPhone: attributing each install to its link, and bringing Apple’s totals into your campaign.
- Other platforms: React Native and Unity.
- Partners: a mobile measurement partner (MMP) is a company whose code inside your app records where installs come from. AppsFlyer, Adjust, Branch and RevenueCat are examples of the partners we will add here.
Need one of them for your app? Write to us.
9. Troubleshooting
The API answers every report it accepts with a 200 and says what it did with it. The answers below are its own words.
Answers to an install report
| Answer | What it means | What to do |
|---|---|---|
attributed: true | The install is attributed to the click. | Nothing. The same install reporting the same click again gets the same answer. |
unknown_click | No click has this ID. | Check the 22 characters of the click ID. A link records a click only while its campaign is live, and not for a visit it takes for a program or a link preview. |
wrong_app | The click is on another app’s link. | Check the SDK key: it must be the key of the app the link leads to. |
already_attributed | This install already belongs to another click. | Nothing. An install is attributed once. |
click_used | The click already counted for another install. | A click counts for one install. A test that starts over as a new install needs a new click ID. |
too_fast | The report came implausibly soon after the click: the store, the download and the install sit in between. | In a test, let a moment pass between opening the link and starting the app. |
expired | The campaign’s attribution window had passed when the report arrived. | In a test, take a new click ID. To count later installs, set a longer window on the campaign’s page. |
ip_cap | Too many installs came from the same network address on this link within a day. | In a test, use another network or wait a day. |
Answers to a subscription report
| Answer | What it means | What to do |
|---|---|---|
recorded: true | The subscription is booked. Its status is pending until you decide. | Confirm it or reject it. The same purchase reported again gets the first answer again. |
not_attributed | No attributed install has this install ID. Yousie books subscriptions only for installs that came through a creator’s link. | In a test, check that the install was attributed first, with the same install ID. |
duplicate | The install already has a subscription under another order ID, or the order ID is booked for another install. | Nothing. One subscription is booked per install. |
unsupported_event | The event is not a subscription, the only event this version knows. | Send subscription as the event. |
Errors
A call the API does not accept gets an error status, with the reason in the body’s error.
| Error | Call | What it means |
|---|---|---|
401 unknown_key | Install and subscription reports | The SDK key does not belong to an app. Copy it again from the Tracking keys panel. |
422 invalid | Every call | A value failed a check. The answer names it in field and says what is expected in message. |
400 bad_json | Every call | The body is not a JSON object. |
413 too_large | Every call | The body is larger than 8 KB. |
401 unknown_secret | Confirmation | The postback secret does not belong to an app. A secret stops working when a new one is created. |
404 not_found | Confirmation | No subscription matches the order ID or the install ID, for the app the secret belongs to. |
422 amount_required | Confirmation | The campaign pays a share of the price: state the price in amount_micros. |
409 already_decided | Confirmation | The subscription already carries the other decision. The first decision stands. |
A sideloaded build gets no referrer
Google Play hands the referrer only to an app installed from its store page. A build installed from Android Studio, with adb or from a file has none, so the SDK finds no click ID and reports nothing. In a debuggable build, hand it one with debugReferrer, as the test step of section 3 shows. The path through the store itself can only be checked with a build installed from Google Play through a creator’s link.
Nothing in logcat
- Logging is off by default. Turn it on with the
loggingoption. - Filter on the SDK’s tag:
adb logcat -s Yousie. - Check that
Yousie.initruns: on Android inApplication.onCreate, in the Application class your manifest names, and on Flutter inmain. debugReferreranddebugResetwork in a debuggable build only. A release build ignores them.- On an iPhone the Flutter calls do nothing.
Still stuck? Write to us with your app’s package and what the API answered.