Send your conversions from your server
Oriva's server API receives your conversions straight from your backend, with a secret key: one HTTP call per sale. Nothing depends on the visitor's browser. It is also the only path that triggers affiliate postbacks, because it guarantees the sale really comes from you.
What does a call look like?
A POST to your tracking subdomain, with your secret key in the X-Oriva-Key header, and the sale as JSON:
POST https://t.<your-domain>/api/v1/collect
X-Oriva-Key: sk_…
Content-Type: application/json
{
"event_id": "order-1001",
"name": "purchase",
"source": "server",
"occurred_at": "2026-09-18T12:00:00Z",
"value": 49.9,
"currency": "EUR",
"visitor_id": "<or_vid if known>",
"consent": { "ads": true },
"user_data": { "email": "jane@example.com" }
}Oriva answers 202 with the event identifier and whether it was a duplicate.
The fields that matter
event_id: your order reference, stable. If the same sale also goes through the browser, give both the same reference: Oriva will keep it only once.value: in units, not cents.49.9means €49.90.visitor_id: Oriva's identifier for the visitor (theor_vidcookie), if your site passes it to your server. Without it, the sale is counted but not tied to the ad that brought it.consent:{ "ads": true }only if the visitor accepted advertising. Without this field, Oriva assumes they refused: it records no email and no click ID, and nothing goes to Meta, TikTok, Google Ads or OpenAI.ip,user_agent: the visitor's, not your server's. Meta, TikTok and OpenAI use them to recognize the buyer.click_ids: if your server kept an affiliate's click ID (aff_click_id), you can pass it here, withvisitor_idand the consent: without a visitor, Oriva has nothing to attach the click to.occurred_at: up to 7 days in the past.
What happens if Oriva is unavailable?
A valid sale is never lost for a reason on Oriva's side. If the database doesn't answer, the event is set aside and replayed as soon as it comes back, and your server still receives 202.
Possible errors
400if the request is malformed: the field at fault is named in the response;401if the key doesn't match;429beyond the rate limit, with aRetry-Afterheader that says when to retry.
Your secret key
It is shown once, when you create it. Store it in an environment variable, never in code or in the browser. You can revoke it at any time from your domain's page: it stops working immediately.
Try Oriva for free.
14 days to connect your site and watch your sales reach your platforms.
Start free trial