# Affiliate · My account

Part of AppEngine API Documentation. Full index: https://appengine.appmint.io/documentation.md
## POST /client/affiliate/join

**Join an affiliate program**

`operationId: AffiliateClientController_join`

Enrols the signed-in customer as an affiliate. Their email must be resolvable from their profile — that is what the affiliate record is keyed on.

#### Signature

```http
POST /client/affiliate/join (body) -> The affiliate record
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`).

#### Errors

| Status | Code | Message | When | What to do |
| --- | --- | --- | --- | --- |
| `404` | PROGRAM_NOT_FOUND | Program not found | No affiliate program has that name. | List programs with `GET /affiliate/programs`. |
| `400` | NO_EMAIL | Could not determine your email. Please ensure your profile is complete. | The caller has no email on their profile. | Complete the profile first. |

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `GET /client/affiliate/me`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |

### Request body

Which program to join.

```json
{
  "program": "partner-2026"
}
```

### Responses

| Status | Meaning |
| --- | --- |
| `201` | The affiliate record |
| `400` | Could not determine your email. Please ensure your profile is complete. — The caller has no email on their profile. |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `404` | Program not found — No affiliate program has that name. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## GET /client/affiliate/me

**Get my affiliate account**

`operationId: AffiliateClientController_getMyProfile`

The caller's own affiliate record — their code, status and program.

#### Signature

```http
GET /client/affiliate/me () -> The affiliate account
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`).

#### Errors

| Status | Code | Message | When | What to do |
| --- | --- | --- | --- | --- |
| `404` | NOT_ENROLLED | You are not enrolled in this affiliate program | The caller has no affiliate record. | Join with `POST /client/affiliate/join`. |

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `GET /client/affiliate/me/earnings`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |

### Responses

| Status | Meaning |
| --- | --- |
| `200` | The affiliate account |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `404` | You are not enrolled in this affiliate program — The caller has no affiliate record. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## GET /client/affiliate/me/link

**Get my affiliate link**

`operationId: AffiliateClientController_getMyLink`

The calling affiliate's default tracking link.

#### Signature

```http
GET /client/affiliate/me/link (program?: string) -> The tracking link
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`).

#### Errors

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `POST /client/affiliate/me/link`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |
| `program` | query | string | — | Affiliate program name; omit for the caller's default program. |

### Responses

| Status | Meaning |
| --- | --- |
| `200` | The tracking link |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## POST /client/affiliate/me/link

**Create my affiliate link**

`operationId: AffiliateClientController_generateMyLink`

Generates a tracking link for the calling affiliate — what they share to earn commission.

#### Signature

```http
POST /client/affiliate/me/link (program?: string, body) -> The tracking link
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`).

#### Errors

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `GET /client/affiliate/me/link`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |
| `program` | query | string | — | Affiliate program name; omit for the caller's default program. |

### Request body

Optional destination.

```json
{
  "productSlug": "cola-330ml"
}
```

### Responses

| Status | Meaning |
| --- | --- |
| `201` | The tracking link |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## GET /client/affiliate/me/referrals

**Get my referrals**

`operationId: AffiliateClientController_getMyReferrals`

The calling affiliate's own referrals and their status — what they have driven and what is still pending approval.

#### Signature

```http
GET /client/affiliate/me/referrals (program?: string, pageSize?: string, status?: string, page?: integer) -> Referrals
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`).

#### Errors

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `GET /client/affiliate/me/earnings`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |
| `program` | query | string | — | Affiliate program name; omit for the caller's default program. |
| `status` | query | string | — |  |
| `page` | query | integer | — |  |
| `pageSize` | query | string | — | Rows per page. |

### Responses

| Status | Meaning |
| --- | --- |
| `200` | Referrals |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## GET /client/affiliate/me/earnings

**Get my earnings**

`operationId: AffiliateClientController_getMyEarnings`

The calling affiliate's commission — earned, pending and paid. Pending amounts are not guaranteed: a referral can still be reversed if the underlying order is refunded.

#### Signature

```http
GET /client/affiliate/me/earnings (program?: string, page?: string, pageSize?: string) -> Earnings
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`).

#### Notes

- Pending commission can still be reversed.

#### Errors

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `GET /client/affiliate/me/referrals`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |
| `program` | query | string | — | Affiliate program name; omit for the caller's default program. |
| `page` | query | string | — | Page number (1-based). |
| `pageSize` | query | string | — | Rows per page. |

### Responses

| Status | Meaning |
| --- | --- |
| `200` | Earnings |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## GET /client/affiliate/programs

**List joinable programs**

`operationId: AffiliateClientController_getAffiliatePrograms`

Affiliate programs the caller can join, with their commission terms.

#### Signature

```http
GET /client/affiliate/programs () -> Programs
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`).

#### Errors

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `POST /client/affiliate/join`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |

### Responses

| Status | Meaning |
| --- | --- |
| `200` | Programs |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

