SubIDs, and why attribution transparency decides everything

ComplianceAttribution

Any layer that sits between a network and the publisher who actually sends the traffic has to answer one question before anything else: can the network still see who that publisher is?

What a SubID actually is

A SubID is a parameter a publisher attaches to a tracking link that comes back untouched on the conversion postback. It exists so that one account can distinguish its own sources — a publisher running several sites uses it to tell which site produced a sale.

Different providers call it different things and grant different numbers of slots. The names vary — subId, sub1, u1, aff_sub — and so do the length limits and the permitted character sets. What they share is the guarantee that matters: the value round-trips.

Why it becomes load-bearing for an intermediary

When a single account fronts many downstream publishers, the SubID stops being a convenience and becomes the network's only window into where traffic originates. Without it, the network sees one account sending volume from everywhere, with no way to tell a careful content site from a source breaching the program's terms.

That is precisely the situation networks have learned to distrust, and the reason sub-network arrangements are scrutinised. The concern is not hypothetical: an intermediary that cannot identify its downstream sources cannot enforce anything, cannot respond meaningfully to a complaint, and cannot be held accountable in the way the advertiser's contract assumes.

Enforcement follows visibility

Every enforcement action a network might take depends on knowing which source did what. Consider what an advertiser typically asks for when something goes wrong:

  • Which publisher bid on our brand terms?
  • Where did this coupon code leak from?
  • Which source produced this cluster of leads that all failed validation?
  • Who is running this creative we never approved?

Each of these is answerable only if the identifier survived the round trip. If it did not, the only available remedy is blunt: suspend the whole account. That punishes every compliant downstream publisher for the behaviour of one, which is bad for the network, the intermediary and the publishers alike.

What preserving attribution requires in practice

Passing a SubID sounds trivial and mostly is not. The implementation has to survive the parts of the ecosystem that are inconsistent:

  • Stable identifiers. The value for a given downstream publisher must not change between sessions, or the network cannot aggregate by source.
  • Length and character limits. Some providers truncate silently. An identifier scheme has to fit the shortest slot it will ever pass through, which usually means a short opaque key rather than a descriptive string.
  • Slot contention. If a publisher also wants a campaign identifier and the provider offers one slot, something has to give. Deciding that the downstream-publisher identity wins is a policy choice, and it is the right one.
  • Redirect chains. Every hop is an opportunity to drop a parameter. Fewer hops is better, and each one that remains has to be tested against every provider.
  • Graceful degradation. Where a provider offers no SubID equivalent at all, the honest response is to say so — and to treat that program differently — rather than to pass traffic the provider cannot attribute.

Declaration is the other half

An identifier tells a network which source sent traffic. It does not tell them how that source acquired it. That requires the publisher to declare their channels — website, application, social, email, paid search, organic, AI integration — and the intermediary to match those declarations against each program's permissions before exposing the offer.

Declarations are only as good as their verification, which is why publisher onboarding matters. A declaration nobody checks is a formality. Checking it before granting access, and re-checking when a publisher's model changes, is what turns it into a control.

The trade being made

There is a version of this business that maximises short-term volume by obscuring where traffic comes from. It works until it does not, and when it stops working it takes the advertiser relationships with it.

The alternative is slower and duller: identify downstream publishers, pass the identifier faithfully, enforce program rules per program rather than globally, and accept that some traffic will be refused. That is the version networks can actually approve, and it is the only one worth building on.

CommissionAPI is building one API for performance monetization, connecting developers, publishers and AI products to approved commerce, SaaS, lead and performance opportunities.