# Affiliate · Public

Part of AppEngine API Documentation. Full index: https://appengine.appmint.io/documentation.md
## GET /affiliate/public/resolve/{code}

**Resolve a referral code**

`operationId: AffiliatePublicController_resolveCode`

Resolves a referral code to its affiliate and destination — what a landing page calls to confirm a code before applying it. Public, so it confirms which codes exist; codes are not secrets, but rate-limit brute-force enumeration.

#### Signature

```http
GET /affiliate/public/resolve/{code} (code: string) -> The resolved code
```

#### Access

Public — no credentials required.

#### Errors

Plus the standard platform errors: `429`, `500`.

#### See also

- `POST /affiliate/public/track`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |
| `code` | path | string | yes | Referral code. |

### Responses

| Status | Meaning |
| --- | --- |
| `200` | The resolved code |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## POST /affiliate/public/track

**Track a referral click**

`operationId: AffiliatePublicController_trackClick`

Records a click on an affiliate link, starting the attribution window. **Public and unauthenticated**, which is inherent — the visitor has no account yet.

That also means anyone can post clicks. Rate-limit it and treat inflated click counts from a single affiliate as a signal worth auditing.

#### Signature

```http
POST /affiliate/public/track (body) -> The tracking result
```

#### Access

Public — no credentials required.

#### Notes

- Unauthenticated — click counts are self-reported by whoever calls it.

#### Errors

Plus the standard platform errors: `429`, `500`.

#### See also

- `POST /affiliate/public/apply-code`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |

### Request body

The click.

```json
{
  "code": "GRACE10",
  "source": "link"
}
```

### Responses

| Status | Meaning |
| --- | --- |
| `201` | The tracking result |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## POST /affiliate/public/apply-code

**Apply a referral code at checkout**

`operationId: AffiliatePublicController_applyCode`

Attaches a referral code to a checkout session, so a resulting order is attributed to the affiliate. Public — the shopper is applying it themselves, usually without an account.

#### Signature

```http
POST /affiliate/public/apply-code (body) -> The result
```

#### Access

Public — no credentials required.

#### Errors

Plus the standard platform errors: `429`, `500`.

#### See also

- `POST /affiliate/test/attribute-order`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |

### Request body

The code to apply.

```json
{
  "code": "GRACE10",
  "email": "ada@example.com"
}
```

### Responses

| Status | Meaning |
| --- | --- |
| `201` | The result |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

