Key takeaways
- ATT is the iOS permission prompt: without a yes, an app may not track the user across other companies and the advertising ID is all zeros.
- SKAdNetwork and its successor AdAttributionKit measure ad results without ATT, through delayed, aggregated postbacks from Apple.
- Postbacks arrive in up to three conversion windows, carry a conversion value instead of user data, and show more detail only for larger crowds.
What are SKAdNetwork and ATT?
ATT (App Tracking Transparency) is the iOS permission prompt that an app must show before it can track a user or read the device’s advertising ID, and SKAdNetwork is Apple’s privacy-preserving way to measure ad installs without that permission. Together they define what iOS advertisers can measure. Since 2024, Apple has also offered AdAttributionKit, the successor to SKAdNetwork, which works with both the App Store and alternative app marketplaces.
| App Tracking Transparency | SKAdNetwork | AdAttributionKit | |
|---|---|---|---|
| What it is | A permission prompt and framework | An install attribution API | An attribution API, successor to SKAdNetwork |
| Available since | Required from iOS 14.5 | iOS 11.3, with version 4 features from iOS 16.1 | iOS 17.4 |
| Needs user permission | It is the permission | No | No |
| User-level data | Yes, if the user agrees | No | No |
How App Tracking Transparency works
Apple’s user privacy guidance says that on iOS 14.5 and later, an app needs the user’s permission through ATT to track them or to access the advertising identifier (IDFA). Apple defines tracking as linking user or device data from your app with data collected from other companies’ apps, websites, or offline properties for targeted advertising or ad measurement, or sharing it with data brokers. Without permission, the IDFA is all zeros, and Apple’s rules forbid fingerprinting the device as a workaround.
In the European Union, apps can add an optional Additional Information button to the prompt with more detail for the user. ATT has also drawn regulators’ attention: France’s competition authority fined Apple €150 million over it in March 2025, and Italy’s fined Apple about €98 million in December 2025, a decision Apple said it would appeal. For the identifier itself, see GAID and IDFA.
How SKAdNetwork and AdAttributionKit measure installs
- A registered ad network signs its ad, and a publisher app shows it.
- The user taps or views the ad and installs the app, by default within 30 days of a click or 24 hours of a view.
- On first launch, the advertised app registers a conversion value and updates it as the user progresses, for example after the tutorial or a first purchase.
- After each conversion window closes, the device sends a cryptographically signed postback to the winning ad network after a random delay, and a copy to the developer if they opt in. Up to five other networks whose ads qualified receive a single non-winning postback.
When several ads qualify, Apple ranks clicks above views and the most recent above older ones, and only one ad wins. The two frameworks are interoperable: Apple compares their impressions together, and SKAdNetwork’s documentation now points advertisers to AdAttributionKit for app campaigns.
What a postback contains
According to Apple’s AdAttributionKit documentation, a winning install can produce up to three postbacks:
| Window | Covers | Conversion value | Sent after |
|---|---|---|---|
| First | Days 0 to 2 after first launch | Fine (0 to 63) or coarse, depending on crowd size | A random 24 to 48 hours |
| Second | Days 3 to 7 | Coarse only: low, medium, or high | A random 24 to 144 hours |
| Third | Days 8 to 35 | Coarse only | A random 24 to 144 hours |
An app can lock a conversion value early to receive that postback sooner. How much detail arrives depends on crowd anonymity: Apple assigns each conversion a data tier from 0 to 3 based on how many users share the same publisher app, advertised app, country, and campaign identifier. Small crowds get a two-digit source identifier and little else; large crowds get up to four digits, the fine value, the publisher app, and, in AdAttributionKit, a country code.
Illustrative schema: using 64 fine values
A game could map its 64 fine values to what happens in the first two days: 0 for an install only, 1 to 20 for tutorial and level progress, and 21 to 63 for revenue bands. The second and third windows then use coarse values, for example low for still playing, medium for level 10, and high for any purchase. The mapping is only an example; design yours before launch, because for users who did not opt in, postbacks are all you get.
What changed in 2025
At WWDC25 in June 2025, Apple presented AdAttributionKit updates, several of them tied to iOS 18.4:
- Configurable attribution windows. Apps can set the view window anywhere from 1 to 7 days and the click window from 1 to 30 days, globally or per ad network, instead of the defaults of 1 and 30 days.
- Cooldowns. Apps can block new conversions for up to 720 hours after an install or re-engagement.
- Overlapping re-engagement conversions. Several re-engagement campaigns can be measured at once. Re-engagement itself arrived in iOS 18 and counts only clicks, not views.
- Country code. Postbacks can include the App Store storefront country when the crowd for that country is large enough.
What iOS advertisers can still see
- For users who allow tracking: device-level attribution through an MMP, as before 2021.
- For everyone else: install counts per network and campaign, conversion values in up to three windows, and more detail where volume is high. No user IDs, and results only after a delay.
- Your own first-party data: how users behave inside your app, which you can analyze yourself as long as you do not link it with other companies’ data for advertising without permission.
Because of the delays, judge iOS campaigns on cohorts at least a week old. What is an MMP? explains how measurement partners merge both kinds of data, and What is a conversion window? covers related time limits.
Pricing that does not depend on attribution on Sharklio
Sharklio campaigns are priced per approved result. A task campaign is checked from the proof the user sends, and an offer campaign pays for steps your own server confirms by postback, so your cost does not depend on how many installs an attribution framework reports. How your app collects the events behind a postback on iOS remains your privacy decision under Apple’s rules. You can target iOS separately by OS and country with its own price. See device and OS targeting or Sharklio for advertisers.
Related terms: attribution in mobile marketing and the GAID deprecation outlook.
Frequently asked questions
Do I need ATT permission to use SKAdNetwork?
No. Apple says apps can call SKAdNetwork and AdAttributionKit regardless of the user’s tracking authorization, because the postbacks contain no user-level data.
Is SKAdNetwork being replaced by AdAttributionKit?
AdAttributionKit is the successor and works alongside it. The two are interoperable, and Apple’s SKAdNetwork documentation points to AdAttributionKit for app campaigns.
How long do SKAdNetwork postbacks take?
The first arrives 24 to 48 hours after its conversion window ends or is locked; the second and third arrive 24 to 144 hours after theirs.
What happens to the IDFA if a user declines ATT?
The app receives all zeros instead of the identifier, and it may not track that user across other companies’ apps and websites.