Key takeaways
- All three keys are in the Integration tab of your app, under 2. Keys and security, with Replace your keys at the bottom.
- The old key stops working right away, so have the new one ready to deploy on your server before you click.
- Keep the hash check on. Without it, anyone who knows or guesses a user ID can open that user's offerwall and History.
How do I rotate my keys and link hash salt?
Go to Apps, click Manage, and open the Integration tab. Under 2. Keys and security, use Replace your keys and click New link hash salt, New postback secret key, or New API key. The old one stops working right away, so update your server at once.
Publisher applications open soon. The Integration tab appears once our team approves your app.
Which key does what
- Link hash salt: makes the
{HASH}in every offerwall link, so nobody can open the wall as another user. Not shown for Offers API apps. - Postback secret key: verifies the postbacks we send to your server. It is different from the link hash salt.
- API key: your server sends it as
Authorization: Bearerwhen it calls the Offers API or the Reporting API.
These keys belong on your server only. Never put them in a browser or an app. Click Show to see a key and Copy to copy it.
Step by step: replace a key
- In the sidebar under Publish, click Apps, then Manage next to the app.
- Open the Integration tab. A live app opens on this tab.
- Scroll to 2. Keys and security and find the box Replace your keys: “Use this if a key may have leaked. The old one stops working right away.”
- Click the button for the key you want to replace:
- New link hash salt: “Offerwall links made with the current salt stop working until you update your site.”
- New postback secret key: “Your postback checks fail until you update the key on your server.”
- New API key: “Offers API and Reporting API calls with the current key fail until you update it on your server.”
- Read the question in the window that opens, and confirm with the button of the same name.
- The page reloads with a message such as “New link hash salt created. Update it where your server builds offerwall links.” Click Show and Copy next to the new key, and put it on your server.
Every change also creates a security notification under the bell, such as Link hash salt changed, Postback secret key changed, or API key changed. If you did not make the change, secure your account at once. See Secure your Sharklio account.
What to update on your server
- After a new link hash salt: update the code that builds offerwall links. Until then, users get the Link not valid page. Links built with the old salt, for example in emails you already sent, stop working too. Use Test a link in the same tab to check your new links.
- After a new postback secret key: update the key in your postback handler. Until then, the hash check on your server fails. Postbacks that failed in the meantime can be sent again with Resend in Reports > Postbacks, and a resent postback is signed with the new key. See How to resend a failed postback.
- After a new API key: update it everywhere your server calls the Offers API or the Reporting API.
Tip: rotate in a quiet hour
Have your deploy ready before you click, then replace one key at a time and send a test with Send test in the Postback tab. See How to test your app.
The Link security setting
Above the link hash salt, Link security controls the hash check:
- On (recommended): every offerwall link must carry a valid
{HASH}, so nobody can open the offerwall of another user by changing the user ID. The button reads Turn off the hash check. - Off: a Hash check is off badge appears, and links work without a
{HASH}. Anyone who knows or guesses a user ID can open that user’s offerwall and History. The link hash salt is marked Not in use, and New link hash salt is grayed out. Click Require the hash to turn the check back on.
Turning the check off asks you to confirm first. While it is off, the link and code shown in the Integration tab have no hash. Turn the check on before you go live. When you turn it on, every link needs a valid hash again, so make sure your server adds it first. More on why it matters: Postback security.
On a phone
Tap Apps in the bottom tab bar, then Manage. The app opens on Integration. If you are on another tab, swipe the row of tabs sideways to find it.
Need help?
Think a key leaked? Replace it, then email support@sharklio.com with your App ID.
Frequently asked questions
Does rotating a key change my App ID?
No. The App ID stays the same. Only the key you replaced changes.
Can I undo a rotation?
No. The old key stops working right away and cannot be brought back. Put the new key on your server.
Is the postback secret key the same as the link hash salt?
No. The salt signs offerwall links, and the secret key signs postbacks. A common mistake is to use one in place of the other.
Why can I not click New link hash salt?
The hash check is off, so the salt is not in use. Turn on Require the hash first.