Set Up Your MaxBounty Postback URL: The Complete Guide (2026)

Most MaxBounty affiliates have a postback URL pasted into the network somewhere, and most of those postbacks are quietly broken. The conversion fires inside MaxBounty's dashboard, the tracker dashboard shows nothing, and the buyer spends three days debugging a Meta CAPI integration when the actual problem is a click ID parameter that never got passed forward.

I've been buying CPA traffic for nineteen years and I have walked dozens of buyers through this same fix. The MaxBounty postback URL setup itself is not complicated. Where people lose hours is in the four places the configuration silently drops the click ID without warning. Below is the exact setup, end to end, with the failure modes called out.

Disclosure: ClickerVolt is our product. We aim for fairness in every comparison: we credit competitors where they excel and only highlight genuine gaps. All pricing and features are verified against live sources.

What This Tutorial Covers

By the end of this guide, your MaxBounty offer clicks carry your tracker's click ID forward through the entire funnel, your conversions fire as server-side events into your tracker the moment MaxBounty registers the lead or sale, and the s2 parameter is feeding ad platform CAPI integrations downstream.

You will need:

  • A MaxBounty affiliate account in good standing
  • A tracker that supports inbound postback URLs (RedTrack, ClickMagick, FunnelFlux Pro, Voluum, Bemob, ClickerVolt, or a custom S2S endpoint)
  • The campaign offer you want to track inside MaxBounty
  • Access to your tracker's campaign settings

I will use ClickerVolt as the reference tracker for the URL examples because it ships native MaxBounty postback parsing on every plan, including the free tier. The same configuration works on RedTrack, Voluum, and FunnelFlux Pro with their tracker-specific click ID token. I will call out the divergences when they matter.


The Architecture You Are Building

Before pasting URLs into MaxBounty, the picture helps. The whole flow has five moving parts.

MaxBounty Postback: The Click-ID Loop 1. Ad Click fbclid / gclid / ttclid 2. Tracker Redirect Capture click ID, assign tracker ID 3. MaxBounty Offer s2={tracker_click_id} 4. Lead / Sale Fires MaxBounty registers conversion 5. Postback to Tracker GET /postback?cid=#S2#&payout=#RATE# Tracker matches cid back to click 6. Downstream CAPI Fire Meta / Google / TikTok server event Reversal on Day 14: MaxBounty fires reversal postback -> Tracker rolls back conversion -> CAPI correction Result: Ad platforms train on real net conversions, not gross leads that get scrubbed

The six-step loop. Steps 1-3 are the click side. Steps 4-6 are the server side. The reversal row is what most setups skip on CPA networks.

The s2 parameter is the carrier. It is the one variable that ties everything together. Lose s2 and the entire pipeline collapses into anonymous conversions you cannot attribute.


Step 1: Get Your Tracker's Postback URL Template

Before you log into MaxBounty, you need the postback URL your tracker exposes. Every tracker uses a slightly different format, but the structure is always the same: a base URL, a click ID parameter, and optional payout and event-type parameters.

ClickerVolt postback template:

https://your-subdomain.clickervolt.com/postback?cid={cid}&payout={payout}&event=lead

RedTrack postback template:

https://your-subdomain.rdtk.io/postback?clickid={clickid}&sum={payout}&type=lead

ClickMagick postback template:

https://www.clickmagick.com/api/conversion/?u={cid}&revenue={payout}&action=lead

FunnelFlux Pro postback template:

https://your-subdomain.ffmagic.com/postback.php?hit_id={cid}&payout={payout}&txid={transaction_id}

Voluum postback template:

https://your-subdomain.voluumtrk2.com/postback?cid={cid}&payout={payout}&txid={transaction_id}

Copy your tracker's template into a notes file. The {cid} (or {clickid} / {hit_id}) placeholder is the one you will replace with MaxBounty's #S2# token in Step 3.


Step 2: Configure Your Tracker Campaign

Inside your tracker, create the campaign that will route traffic to the MaxBounty offer.

  1. Set the traffic source. Facebook, Google, TikTok, native, push, whatever you are running. The traffic source tells the tracker which click ID parameter to capture from the inbound URL (fbclid, gclid, ttclid).
  2. Set the offer URL. This is the MaxBounty affiliate link, which we will modify in Step 4 to include the s2 macro.
  3. Set the payout type. Most MaxBounty offers fire on a lead or sale. Match the tracker setting to the offer payout model so the dashboard reports cleanly.
  4. Note the tracker's click ID token. ClickerVolt uses {visitor_id} or {click_id}. RedTrack uses {clickid}. FunnelFlux Pro uses {hit-id}. ClickMagick uses [CLICK_ID]. This token is what you will paste into MaxBounty's s2 field in Step 4.

If your tracker auto-generates an offer URL template when you select MaxBounty as a network, accept it. The template usually pre-fills the s2 parameter correctly. If it does not, build the URL manually in Step 4.


Step 3: Set the Global Postback URL in MaxBounty

MaxBounty calls the postback a "Global Postback URL". One setting, applied to every campaign in your account. This is where most affiliates lose half an hour because the menu name has changed twice in the last four years.

In MaxBounty:

  1. Log in to your affiliate account.
  2. Click your username top right, then Account Settings.
  3. Scroll to the Global Postback Settings section.
  4. Set Type to URL (this is the option that fires a server-side GET request on every conversion).
  5. Paste your tracker's postback URL into the URL field, with MaxBounty's tokens in place of the tracker placeholders.

The MaxBounty-formatted URL you paste looks like:

https://your-subdomain.clickervolt.com/postback?cid=#S2#&payout=#RATE#

Replace your-subdomain.clickervolt.com with your tracker's actual postback domain. The #S2# and #RATE# tokens are MaxBounty's variables. They get replaced with the actual click ID and payout amount when MaxBounty fires the postback.

MaxBounty's full token list:

  • #S1#: your sub ID 1
  • #S2#: your sub ID 2 (this is the slot we use for the tracker click ID)
  • #S3#: your sub ID 3
  • #S4#: your sub ID 4
  • #S5#: your sub ID 5
  • #RATE#: the affiliate payout
  • #OID#: the MaxBounty offer ID
  • #TID#: the transaction ID
  • #CTYPE#: the conversion type (Lead, Sale, etc.)

If your tracker supports it, pass #TID# as the transaction ID parameter. This is what lets the tracker deduplicate if MaxBounty re-fires the postback (which happens on retries) and what lets you reconcile against MaxBounty's reporting at the end of the month.

Click Save Global Postback. You are done on the MaxBounty side.


Step 4: Pass Your Tracker's Click ID Into MaxBounty's s2

This is the step that breaks more setups than any other. Your tracker captures a click ID on the ad click. You have to forward that click ID into MaxBounty's s2 sub ID field on the outbound link, so MaxBounty stores it with the conversion and returns it as #S2# in the postback.

The MaxBounty affiliate link pattern:

https://www.mb01.com/lnk.asp?o=14732&c=918277&a=YOURAFFID&s2={tracker_click_id}

Replace {tracker_click_id} with your tracker's click ID token:

  • ClickerVolt: {visitor_id} or {click_id}
  • RedTrack: {clickid}
  • FunnelFlux Pro: {hit-id}
  • ClickMagick: [CLICK_ID]
  • Voluum: {clickid}
  • Bemob: {externalid}

Worked example with RedTrack:

https://www.mb01.com/lnk.asp?o=14732&c=918277&a=YOURAFFID&s2={clickid}

When a user clicks through your tracker, RedTrack assigns a click ID like f7a3c891b2e5. The tracker substitutes that value into {clickid} before redirecting, so the outbound URL becomes:

https://www.mb01.com/lnk.asp?o=14732&c=918277&a=YOURAFFID&s2=f7a3c891b2e5

MaxBounty stores f7a3c891b2e5 against this click. When the conversion fires, MaxBounty fires your global postback with cid=f7a3c891b2e5, which the tracker matches back to the original click record.

Paste this URL into your tracker as the offer URL. That is the click ID round trip.


Step 5: Verify the Loop Works

Before scaling traffic, fire a test conversion to confirm the pipeline. Skipping this step is how affiliates discover four days later that their s2 was URL-encoded twice and every conversion landed as anonymous.

The verification sequence:

  1. Click your own tracker campaign URL with the traffic source query parameter. For Facebook, the URL looks like https://your-tracker-domain.com/?campaign=mb-offer-1&fbclid=TEST123.
  2. Confirm the redirect to MaxBounty includes your s2. Right-click the network tab in your browser dev tools, watch for the redirect chain. The final URL should be the MaxBounty lnk.asp with s2=<some-tracker-click-id> populated.
  3. Complete the offer. Whatever MaxBounty's offer page asks for, fill it out as a test lead. Most offers are email opt-ins or short forms.
  4. Check MaxBounty's reporting within 5 minutes. The conversion should appear in your MaxBounty dashboard with the s2 value visible in the column drill-down.
  5. Check your tracker dashboard. Within 30 to 60 seconds of MaxBounty registering the conversion, your tracker should show a conversion attributed to the original test click.

If the MaxBounty dashboard shows the conversion but your tracker does not, the postback URL is misconfigured. Check the URL field in Global Postback Settings for typos and confirm the tracker postback domain resolves.

If the conversion appears in your tracker but without the original click attribution, the s2 was lost somewhere in the redirect chain. Walk the redirect chain in dev tools and find the hop where s2 stopped propagating.


Step 6: Handle Reversals

MaxBounty scrubs leads and reverses conversions for a window after the original fire. Fraudulent leads, duplicate submissions, leads that fail the advertiser's quality check. The reversal window varies by offer, from same-day to 30 days out.

When MaxBounty reverses a conversion, it fires a second postback to your global postback URL with a specific token indicating the reversal. The token is the #CTYPE# field, which on a reversal contains values like Reversal or Adjustment depending on the offer.

The reversal-aware postback URL:

https://your-subdomain.clickervolt.com/postback?cid=#S2#&payout=#RATE#&type=#CTYPE#

Pass #CTYPE# as a parameter your tracker can read. Trackers that support reversal handling will roll back the original conversion when they receive the reversal postback. Trackers that do not will record the reversal as a separate conversion and inflate your reporting.

For CAPI integration downstream, the reversal is the trigger for a Meta CAPI negative-value Purchase event, a Google Ads RETRACT signal, or a TikTok Events API CancelOrder event. This is the loop most affiliates skip because their tracker logs the reversal but does not fire it to the ad platform. The optimizer keeps prospecting toward customer profiles that got scrubbed.

If your tracker does not auto-fire reversal corrections to ad platforms, you have three options:

  1. Build a custom serverless function that reads your tracker's reversal events and fires the CAPI correction. About 50 lines of code per ad platform.
  2. Run a daily batch reconciliation that pulls reversals from your tracker API and uploads correction events to Meta, Google, and TikTok in batch.
  3. Switch to a tracker that auto-fires reversal corrections. ClickerVolt's Refund Sync auto-fires Meta CAPI negative Purchase, Google RETRACT, and TikTok CancelOrder within seconds of receiving the MaxBounty reversal postback.

Common Mistakes

I have seen the same five mistakes wreck MaxBounty tracking setups over and over. Avoid these.

1. Forgetting to URL-encode the s2 value. If your tracker's click ID contains hyphens, slashes, or special characters, the value can get truncated when it hits MaxBounty's URL parser. Always URL-encode the s2 value before sending it. Most trackers do this automatically; verify with a test click before scaling.

2. Hard-coding s2 instead of using the token. I have audited setups where the affiliate pasted a literal string into s2 (like s2=campaign1) instead of the tracker click ID token. Every conversion comes back with the same s2, the tracker cannot match them, all conversions report as the same click. Use the token, not a static value.

3. Setting the postback at the offer level instead of globally. MaxBounty has per-offer postback overrides. If you set the postback per-offer and then accept a new MaxBounty offer, the new offer has no postback configured and silently drops every conversion. Use Global Postback Settings unless you have a specific reason to override per offer.

4. Not handling reversals at all. This is the same compounding problem as ClickBank without refund correction. MaxBounty reverses 5 to 20 percent of leads on most offers. If your tracker ignores reversals, your gross conversion count is inflated, your ad platforms are optimizing toward customers who got scrubbed, and your CPA on month two is worse than month one.

5. Trusting the s2 in MaxBounty's dashboard column but not verifying the postback fired. MaxBounty stores s2 against the conversion regardless of whether the postback succeeded. You can have an s2 visible in MaxBounty's dashboard and still have zero conversions in your tracker because the postback URL was wrong. Always cross-check both sides.


What Good Looks Like

A correctly configured MaxBounty postback setup produces:

  • Every MaxBounty conversion attributed to its original ad click in your tracker, with the click ID, traffic source, campaign, and ad creative all populated.
  • Reversal postbacks rolling back the original conversion in the tracker within seconds of MaxBounty firing them.
  • Downstream CAPI events firing to Meta, Google, and TikTok with the full first-party identity payload (hashed email, phone, click ID, IP, user agent, browser ID).
  • A clean reconciliation between MaxBounty's monthly report and your tracker's conversion count, with reversal-adjusted net leads matching to within 1 to 2 percent.

The work above takes 15 to 30 minutes the first time if you have a tracker that handles MaxBounty postback formats natively. It takes an hour if you are configuring the postback URL manually with a tracker that has limited MaxBounty documentation.


Why This Matters

CPA networks like MaxBounty are the channel where postback configuration sloppiness costs the most, because the offer payout and reversal logic depends entirely on the network's server-side notification. There is no browser pixel fallback. There is no second chance. If the postback is wrong, the conversion is invisible to your tracker, and every downstream signal you feed your ad platform is computed on incomplete data.

The buyers who get this pipeline right pull ahead, because their tracker becomes the source of truth and their ad platforms train on accurate, reversal-adjusted conversion signals. The buyers who get it wrong spend the next quarter wondering why their CPA does not improve.

See how ClickerVolt's native MaxBounty postback parsing works


Frequently Asked Questions

Can I use the MaxBounty postback without a tracker?

Yes, but you will write the wiring yourself. The postback URL can point at a serverless function (Cloudflare Workers, AWS Lambda) that receives the GET request, parses the cid, payout, and ctype parameters, and fires whatever downstream events you want. The tracker is what saves you from building that integration.

What is the difference between MaxBounty's s1 through s5 sub IDs?

They are five generic pass-through slots MaxBounty preserves through the click and returns in the postback. By convention, affiliates use s2 for the tracker click ID, s1 or s3 for the campaign name, and the others for ad creative or placement. There is no functional difference between them. Pick a slot per data type and stay consistent.

How fast does the MaxBounty postback fire?

Typically within 5 to 60 seconds of MaxBounty registering the conversion. The exact latency depends on offer-specific delays (some advertisers send delayed callbacks) and on MaxBounty's queue depth. For most affiliate offers, the postback hits your tracker fast enough that the conversion shows up in dashboards within the same minute.

Does MaxBounty support reversal postbacks for every offer?

Yes, MaxBounty fires reversal postbacks across the account through the same global postback URL. The reversal is identified by the #CTYPE# value (Reversal or Adjustment typically). Your tracker has to read that field to differentiate a forward conversion from a reversal.

What if my tracker click ID has special characters?

URL-encode the s2 value before it hits MaxBounty's link. Most trackers handle this automatically. If you are building the URL manually, run the click ID through encodeURIComponent (JavaScript) or urllib.parse.quote (Python) before substitution.

Can I send the postback to multiple trackers?

MaxBounty Global Postback supports one URL. To send to multiple destinations, point the postback at a webhook fanout service (Zapier, Make, custom Lambda) that receives the original and re-fires to each destination tracker. Adds 200ms to 500ms of latency per hop. Usually not worth it; pick one tracker and run reconciliation reports against MaxBounty's API for the second source of truth.

What is the minimum payout MaxBounty fires postbacks on?

Every conversion, regardless of payout amount. Even $0.10 incentive offers fire the postback. The #RATE# token contains the affiliate payout in USD. You can filter low-value conversions inside your tracker if you do not want them counted in your ad platform CAPI events.

Ready to Track Smarter?
Start for free — every feature, no credit card, no trial countdown.
Try ClickerVolt Free →
500 events/month free · All features included · No credit card