Use the generated URL
Open the campaign after creation and copy its generated advertiser postback URL. It contains the campaign ID and campaign-specific secret plus placeholders for transaction, click and status values.
Required attribution
The CLICK_ID must be the click token received when the user was sent to the advertiser. The transaction ID must uniquely identify the conversion on the advertiser side.
Protect the secret
Treat the campaign postback secret like a credential. If it becomes exposed, replace/rotate it before trusting additional callbacks.