Skip to content
Mobile SDK

The same wall, wrapped for a phone.

A thin native wrapper that opens the hosted wall in a managed webview, carries your user id, and hands control back when the user closes it. It is a convenience layer over the URL — not a second integration path with different rules.

Working today

  • Nothing of the SDK is released. This page is the specification we are building to.
  • The hosted wall works in a webview today, and your placement's page has the Android and iOS code for it. The first SDK release will do exactly that.

Still being built

  • iOS and Android packages, distributed through the usual channels.
  • A single call to present the wall, plus a close callback.
  • An optional in-app reward notice, with the server postback remaining the source of truth.

How to read this page

Sections marked Planned describe a contract we are building to, published early so you can design against it. Sections with no badge are running today, exactly as written. We will tell you in writing before anything marked Planned changes.

What the call will look like

Planned

Two values configure it, the same two the URL needs: the placement id and a signed wall URL your server builds for the user. The signature below is the shape we are designing against, and we will publish the released one before anyone has to write against it.

Planned — not yet released
// Configure once, at start-up.
OpusWall.configure(
  placementId: "fbefb48b-df2e-4102-9e05-f48c4083edc2"
)

// Present the wall for the signed-in user, with the URL your server signed.
OpusWall.presentWall(
  signedWallUrl: urlFromYourServer,
  onClose: { /* refresh the user's balance */ }
)

Where the reward actually comes from

An app may want to tell a user that something was completed. That notice is a convenience and nothing more. The money is decided by the server postback described below, which your backend receives directly from us and can verify.

Never credit a user from a client-side signal alone. A phone is not a trustworthy source of truth about money, and treating it as one is how reward systems get drained.

What the SDK will and will not collect

Planned

The SDK is designed to take an opaque user id from you and nothing else. It does not ask for contacts, location or an advertising identifier, and it is not an analytics package wearing a different hat.

The postback you receive

When a conversion from your wall settles — the advertiser confirmed it and the money moved — we call the postback URL on your placement, https only. When a settled conversion is reversed, we call it again so you can take the reward back. GET appends the parameters to your URL's query; POST sends them as a form body. Your placement's page shows every attempt with your server's answer, and sends test postbacks.

All fifteen parameters are always present, empty when there is nothing to send, followed by signature: the HMAC of the fifteen, in the order above, with your placement's postback secret. Verify it, and refuse a timestamp more than an hour old — we sign every attempt as it leaves.

  • Acknowledge with any 2xx status and a body of exactly OK or 1. Anything else — another body, a redirect, an error, no answer within 10 seconds — is a failed attempt.
  • A failed attempt is retried after 1 minute, 5 and 15 minutes, 1, 3, 6 and 12 hours, then 24 hours twice: ten attempts over about three days. An abandoned notice can be re-queued from your panel for 30 days.
  • Credit once per (transaction_id, status), under a unique constraint in the same transaction as the credit. On a reversal, take back only what you credited; if you never did, answer OK and do nothing.
  • We never send a credit after its reversal, or a reversal for a credit that never left us.
  • We call only public addresses: your hostname is resolved once per attempt and refused if any address it resolves to is private, loopback, link-local or reserved. We connect to the address we checked, follow no redirect and read at most 16 KiB.
Example request (an example secret and illustrative values)
GET https://example.com/opuswall/postback?site=main
  &amount=1750
  &campaign_id=4a3a4905-900d-4fb1-b719-432d3e292085
  &campaign_name=Example%20campaign
  &goal_id=0f5b8d2e-6c1a-4e9b-b3d7-5a2c8e4f1b90
  &goal_name=Example%20goal
  &placement_id=fbefb48b-df2e-4102-9e05-f48c4083edc2
  &share_usd_cents=175
  &status=credit
  &sub_id1=summer-2026&sub_id2=&sub_id3=
  &test=0
  &timestamp=1790000000
  &transaction_id=c8e1b0d4-7a2f-4c6e-9b3d-1e5f7a9c2b4d
  &user_id=player%2048213
  &signature=60996fe5750f91e727d8d1acbb1afc765f4284d6fecf377f941e900d8eab91ab

Secret e1d2c3b4a5968778695a4b3c2d1e0f1a2b3c4d5e6f708192a3b4c5d6e7f80912 (an example).
Broken over lines for reading; sent as one. Your own site=main is not signed.

Postback parameters

  • amount

    Meaning
    What to credit, or take back, in whole units of your currency: floor(share_usd_cents × coins_per_usd ÷ 100). It can be 0.
  • campaign_id, campaign_name

    Meaning
    The campaign, and its name as it stood when the conversion was recorded.
  • goal_id, goal_name

    Meaning
    The completed goal.
  • placement_id

    Meaning
    Your placement.
  • share_usd_cents

    Meaning
    Your earnings for this conversion, in US cents — already split.
  • status

    Meaning
    credit, or reversal.
  • sub_id1, sub_id2, sub_id3

    Meaning
    As they arrived on the wall URL, empty if they did not.
  • test

    Meaning
    1 for a test postback, 0 for a real one. Never credit a 1.
  • timestamp

    Meaning
    Unix seconds when this attempt was signed.
  • transaction_id

    Meaning
    Our id for the conversion — identical on every attempt, and on its credit and its reversal.
  • user_id

    Meaning
    The user_id from your wall URL.
  • signature

    Meaning
    Lower-case hex HMAC of the other fifteen, with your postback secret.

What to do until it ships

Open the signed wall URL in a webview, and open offers outside it. When the SDK arrives it will do exactly this, with the presentation details handled for you, and your placement, your postback and your user ids will not change.

Nothing to migrate later

The SDK is a wrapper around the same URL and the same postback. Integrating with the URL today is not throwaway work.
Mobile SDK

Building an app and want to be early?

Tell us the platform you are on when you apply. Publishers who are waiting on the SDK get the first release and a direct line while it settles.