AppsFlyer
Mobile measurement platform that attributes app installs and in-app events to the ad campaigns that caused them.
You can absolutely build a click tracker: log clicks, generate deep links, receive install pings from your own SDK, join them in SQLite. What you cannot build is the reason AppsFlyer exists, which is that Meta, Google, TikTok and Apple do not hand raw attribution data to random self-hosted endpoints. Those self-attributing networks report only to certified measurement partners, and SKAdNetwork/AdAttributionKit postbacks are aggregated and privacy-thresholded by design. Add install fraud detection, which is a data problem across billions of devices rather than a code problem, and the gap stops being about engineering effort. The honest consolation build is a first-party attribution tracker for channels you control: your own links, emails, influencer codes, organic web to app.
Build verification: not recorded. How we judge buildability
What you give up
- Self-attributing network data from Meta, Google, TikTok and Apple Search Ads, which is restricted to certified measurement partners
- SKAdNetwork and AdAttributionKit postback handling, decoding and conversion value modeling
- Install and click fraud detection, which depends on cross-advertiser device data you will never have
- Postbacks and audience syncs to thousands of ad partners and MMP-only integrations
- A maintained SDK that survives every OS release, ATT prompt change and privacy policy update
- Deterministic cross-device and cross-platform identity resolution
Why people still pay
Because attribution is not a computation, it is an entitlement. The moment a meaningful slice of your spend goes to Meta or Google or TikTok, your homegrown tracker sees a blob of untagged traffic and shrugs, while the ad networks themselves only talk to partners they have certified. On top of that, media buyers want a neutral scorekeeper both sides accept, finance wants one number, and nobody wants to argue with a partner about whose SQL is right. The price is the referee, not the dashboard.
Your build guide
The stack, security requirements, and agent rules for a focused replacement.
Before you start
- A server with a public HTTPS domain for click and postback endpoints
- Ability to add a small SDK or HTTP call to your own iOS/Android app
- Apple App Site Association and Android assetlinks.json files served for deep linking
- Your own ad account exports if you want spend numbers next to installs
Use these project rules and optional skill references alongside the prompt. Review each skill before adding it to your agent; the AGENTS.md export includes the same guidance.
Project rule, data: Model data sources, dated observations, derived metrics, and report snapshots; keep stable source IDs and timestamps.
Project rule, behavior: Link service: POST /api/links creates a tracked link with campaign, source, medium, and an optional destination path in my app. Each link gets a short id served at GET /l/:id.
Project rule, recovery: On click, /l/:id records a click row: timestamp, short id, user agent, platform guess from UA, referrer, IP truncated to /24 for IPv4 and /48 for IPv6, and a random click token set as a cookie. Then 302 to a universal link if the platform is iOS or Android, otherwise to a configured web fallback.
Implementation plan
Phase 1, architecture and data
Build a self-hosted first-party mobile attribution tracker. TypeScript, Fastify, SQLite via better-sqlite3, Vite plus React for the dashboard, Docker Compose for deployment. No accounts, no cloud services, no telemetry. Model data sources, dated observations, derived metrics, and report snapshots; keep stable source IDs and timestamps.
Phase 2, implement
Link service: POST /api/links creates a tracked link with campaign, source, medium, and an optional destination path in my app. Each link gets a short id served at GET /l/:id.
Phase 3, implement
Ingest endpoint: POST /api/events accepts { deviceId, eventName, clickToken?, platform, appVersion, ts, value? } authenticated by a shared secret in APP_INGEST_KEY. Store raw events untouched in an events table.
Phase 4, review and output
Attribution job: for each first_open event, attribute deterministically if clickToken matches a click. Otherwise do a probabilistic match against clicks in the last 24 hours on the same truncated IP and platform, and mark it as probabilistic with a confidence field. Never overwrite a deterministic match. Store results in an attributions table so the logic can be re-run idempotently. Dashboard at /: table of campaigns with clicks, installs, deterministic versus probabilistic split, and any named post-install events. Date range picker. CSV export.
Phase 5, recovery and acceptance
On click, /l/:id records a click row: timestamp, short id, user agent, platform guess from UA, referrer, IP truncated to /24 for IPv4 and /48 for IPv6, and a random click token set as a cookie. Then 302 to a universal link if the platform is iOS or Android, otherwise to a configured web fallback. Verify this invariant with a saved fixture: A replayed batch cannot double-count events; missing or late data must be labelled in the report. State the practical limit: Self-attributing network data from Meta, Google, TikTok and Apple Search Ads, which is restricted to certified measurement partners.
Build a self-hosted first-party mobile attribution tracker. TypeScript, Fastify, SQLite via better-sqlite3, Vite plus React for the dashboard, Docker Compose for deployment. No accounts, no cloud services, no telemetry.
What it does:
1. Link service: POST /api/links creates a tracked link with campaign, source, medium, and an optional destination path in my app. Each link gets a short id served at GET /l/:id.
2. On click, /l/:id records a click row: timestamp, short id, user agent, platform guess from UA, referrer, IP truncated to /24 for IPv4 and /48 for IPv6, and a random click token set as a cookie. Then 302 to a universal link if the platform is iOS or Android, otherwise to a configured web fallback.
3. Serve /.well-known/apple-app-site-association and /.well-known/assetlinks.json from files in ./public so real deep links work.
4. Ingest endpoint: POST /api/events accepts { deviceId, eventName, clickToken?, platform, appVersion, ts, value? } authenticated by a shared secret in APP_INGEST_KEY. Store raw events untouched in an events table.
5. Attribution job: for each first_open event, attribute deterministically if clickToken matches a click. Otherwise do a probabilistic match against clicks in the last 24 hours on the same truncated IP and platform, and mark it as probabilistic with a confidence field. Never overwrite a deterministic match. Store results in an attributions table so the logic can be re-run idempotently.
6. Dashboard at /: table of campaigns with clicks, installs, deterministic versus probabilistic split, and any named post-install events. Date range picker. CSV export.
7. CLI script: npm run import-spend that loads a CSV of campaign,date,spend so the dashboard can show cost per install for channels I bought myself.
Explicitly out of scope, and say so in the README: SKAdNetwork and AdAttributionKit postbacks, any integration with Meta, Google, TikTok or Apple Search Ads, fraud detection, audience syncing, and a native SDK. The client side is a documented HTTP contract only.
Secrets in .env: APP_INGEST_KEY, PUBLIC_BASE_URL, WEB_FALLBACK_URL. Include a seed script with fake clicks and installs, and vitest tests covering deterministic match, probabilistic match, and the no-double-attribution rule.$ open in your agent (prompt prefilled, you press enter), copy the prompt or copy AGENTS.md · generated from this app's build plan
prompt copied. want to know what dies next week?
new verdicts + top votes, weekly. free. one-click out.
No prior-art project is listed yet. Compare the scoped build with the paid product before choosing.
Questions about AppsFlyer
Can you build your own AppsFlyer with AI?
A full replacement is not the recommended project. You can absolutely build a click tracker: log clicks, generate deep links, receive install pings from your own SDK, join them in SQLite. What you cannot build is the reason AppsFlyer exists, which is that Meta, Google, TikTok and Apple do not hand raw attribution data to random self-hosted endpoints. Those self-attributing networks report only to certified measurement partners, and SKAdNetwork/AdAttributionKit postbacks are aggregated and privacy-thresholded by design. Add install fraud detection, which is a data problem across billions of devices rather than a code problem, and the gap stops being about engineering effort. The honest consolation build is a first-party attribution tracker for channels you control: your own links, emails, influencer codes, organic web to app.
What does the AppsFlyer build prompt cover?
The prompt starts with this scope: A self-hosted link tracker that issues tagged deep links, logs clicks, and matches them to install and event pings from your own app SDK to give you first-party attribution for channels you control. Full-product capabilities excluded from the comparison include: Self-attributing network data from Meta, Google, TikTok and Apple Search Ads, which is restricted to certified measurement partners; SKAdNetwork and AdAttributionKit postback handling, decoding and conversion value modeling; Install and click fraud detection, which depends on cross-advertiser device data you will never have. Follow the implementation plan and its prerequisites before expanding the build.
How do I use the prompt, AGENTS.md and agent skills?
Start with the AppsFlyer prerequisites and stack, then copy the prompt into your coding agent. Save the project rules as AGENTS.md in the project root. Linked skills are optional packages or source instructions for specific tasks; review their current contents and install only those matching the chosen stack. A skill does not supply API credentials or verify the finished app.
How long will this AppsFlyer project take?
The catalogue estimate is multi-day for the limited scope. Setup, integration approvals, debugging, deployment and ongoing maintenance can add time. This is an estimate, not a delivery guarantee.
What would I give up by replacing AppsFlyer?
Self-attributing network data from Meta, Google, TikTok and Apple Search Ads, which is restricted to certified measurement partners; SKAdNetwork and AdAttributionKit postback handling, decoding and conversion value modeling; Install and click fraud detection, which depends on cross-advertiser device data you will never have; Postbacks and audience syncs to thousands of ad partners and MMP-only integrations; A maintained SDK that survives every OS release, ATT prompt change and privacy policy update; Deterministic cross-device and cross-platform identity resolution. Because attribution is not a computation, it is an entitlement. The moment a meaningful slice of your spend goes to Meta or Google or TikTok, your homegrown tracker sees a blob of untagged traffic and shrugs, while the ad networks themselves only talk to partners they have certified. On top of that, media buyers want a neutral scorekeeper both sides accept, finance wants one number, and nobody wants to argue with a partner about whose SQL is right. The price is the referee, not the dashboard.
What can I use instead of building AppsFlyer?
No alternative is listed in this entry yet. That is a gap in this catalogue, not proof that no suitable product exists. Compare the paid product and the proposed scope before committing to a build.