Getting Started with Wildfire API's and JSON feeds - Wildfire Support Center
Getting Started with Wildfire API's and JSON feeds
Wildfire API & JSON feeds allow partners to access Wildfire's data-rich affiliate network coupons and cashback opportunities, for partners building their own offer walls, extensions, marketing efforts, and more.
Ensure you read through the essential information:
Regarding our API & JSON structures:
How to Handle Multiple Countries:
How to build links and tracking codes for cashback:
Feel free to reference this checklist:
Preparation & Setup Logic
If paying out users, install the Postman Collection: Use the pre-built collection with the included pre-request script to automatically generate the required HMAC authentication headers for API testing.
Ingest Sample Data: If live traffic is not yet active, ingest the Public Commission Sample Data (where ApplicationID is 0) to validate your dashboard’s ability to parse and display status changes.
Coupon Data Feed Logic
Because the Coupon Data Feed provides raw data, the following logic must be implemented in the partner application:
- Coupon Data Feed - Normalize Descriptions: If the Code field is null, parse the Description field to extract coupon code patterns.
- Coupon Data Feed - Manual Country Filtering: The feed is not pre-filtered by region. Partners must filter coupons using the provided country codes to match the user's location.
- Coupons Data Feed - Date Validity Management:
- Suppress expired promotions.
- Handle "coming soon" promotions (future start dates).
- Interpret "Year 3000" end dates as "No Expiration."
- Coupons Data Feed - Language Handling: Filter or translate coupons if the merchant passes codes in a language not supported by your UI (e.g., US merchants passing Spanish coupons).
Merchant & Rate Logic Feed
- Identify rate types: PERCENTAGE vs. FLAT. If a rate is FLAT, check the Currency field (e.g., USD, CAD, EUR).
- Cache Refresh Rate: Implement a scheduled task to refresh the Merchant Data Feed at least once every 24 hours. Optional: Refresh Coupon Data Feeds every 6 hours to capture short-lived offers.
- Disclaimer Logic: Your UI must display "Up to [X]%" and include disclaimers that rates are subject to change.
Link Construction
- Device ID Generation: Your system must call POST /device to generate a Device ID for each unique user context before constructing links.
- If doing Cashback - User Attribution (tc parameter): To attribute a sale to a specific user in your system, you must append &tc=[Your_User_UUID] to the tracking link. Wildfire will return this value in the commission report.
- Deep Linking: When linking to a specific product page, you must URL-encode the target URL and append it as the last parameter (&url=...) to prevent truncation by browsers.
- Multi-Country Override: If your application serves users in multiple countries but uses a single App ID, you must detect the user's location and append &pc=[CountryCode] (e.g., &pc=CA) to tracking links to force the correct merchant program.
Compliance Logic
- Accommodate Stand-down Logic: Regularly ingest the stand-down-policy JSON feed. This contains a list of domains and URL parameters (e.g., afsrc=1) that indicate a user is already affiliated with another publisher.
- Accommodate Session Suppression: If a user visits a URL matching the Stand-Down list, your application (extension) must suppress all activation prompts for the duration of the user's session (typically 1 hour).
Commission Reporting & Payout Logic
- Signature Verification: When receiving a Callback (webhook), calculate the SHA-256 HMAC of the request body using your Callback Key, then compare it to the X-Wf-Signature header to verify authenticity.
- De-Duplication: Callbacks fire on every status change. Your system must upsert (update or insert) records by CommissionID to avoid creating duplicate entries for the same transaction.
- Reconciliation (Failsafe): Callbacks are "fire and forget" (no retries). You must implement a nightly batch job that uses the Commission API to fetch records modified in the last 24 hours and ensure any missed webhooks are captured.
- Status Management: Do not release funds to users while the status is PENDING or CONFIRMED. Wait for the status to change to PAID (or READY if you assume the risk) before crediting user wallets.
- Split Handling (v4 API): They need to handle the split payout and Offer presentation. You will see two SplitPart values: APPLICATION (your share) and DEVICE (the user's share).
Updated 16 Jun 2026