Every attribution platform gives you the verdict. Measura shows the working.

Attribution for Android apps. Every install is stored with its score, the terms that produced it, the clicks that lost, and the sentence that says why it won.

A decision trace for one install: click_id selected at 95, with referrer, ad_id and fingerprint scored lower and kept as rejected candidates.
Illustrative decision trace

One install, read to the end.

The verdict first: which campaign won the install, how sure Measura is, and the clicks that lost. Everything under it is the working.

Metaq3_retarget

method
ad_id
floor
MIN_REPORTABLE_CONFIDENCE · attribution-workerA match scoring under 20 is downgraded to organic. Its evidence is kept.
window
default_click_window_days · apps tableClicks older than the window are never candidates. Set per app, 1 to 30 days.
rejected
3 clicks

confidence

click window

Illustrative install ins_5c02. Field names, tiers and reason templates are the worker’s own; the values are invented.

78 is a sum. These are its terms.

The worker scores an install the moment it lands and writes every term into confidence_breakdown beside the score. Nothing is reconstructed later for a report.

  1. methodad_id

    Base score for an exact advertising-ID join.

  2. device_uniqueness_bonus+8

    Entropy of the device signal, 0 to +10. Inference tiers only.

  3. time_delta_hours2.6

    Inference tiers: no penalty inside 24 hours, then −3 per further full day, capped at −15.

  4. shared_ip_penalty0

    Fingerprint matches only: -10 when click and install share a /24.

  5. high_fraud_penalty0

    Fraud pre-screen score / 10, capped at -10. Scored 0 here.

  6. confidence_scoreattributions.confidence_score70 + 8 − 0 − 0 − 0 = 78, clamped to 0–100 and stored as an integer.

    70 + 8 − 0 − 0 − 0 = 78

Screened by nine named rules before it was scored.

Every event passes the fraud pre-screen first. A rule that fires is stored by name with what it contributed, and nothing is auto-blocked. For this install none fired, so high_fraud_penalty is 0.

  1. 0 contributed, did not fireip_velocityMore than 10 clicks a second from one /24 subnet.
  2. 0 contributed, did not firemissing_user_agentNo user agent on the request.
  3. 0 contributed, did not firebot_user_agentA user agent that names a crawler or a script.
  4. 0 contributed, did not firelow_entropy_user_agentA templated user agent, typical of farms.
  5. 0 contributed, did not fireinvalid_timestampA client timestamp that does not parse.
  6. 0 contributed, did not firetimestamp_anomalyClient clock more than 5 minutes off server time.
  7. 0 contributed, did not firedevice_install_velocityOne device producing many installs in a short window.
  8. 0 contributed, did not firedevice_farm_signatureEmulator and rooted-farm traces in the user agent.
  9. 0 contributed, did not fireno_device_signalsNo consented identifiers at all. Informational.

backend/lib/fraud.ts · rule_nameRule names are stored exactly as listed. Thresholds are custom on Enterprise. rules fired on ins_5c02.

The clicks that lost, and why they lost.

Other platforms keep the winner and discard the rest. Measura keeps every click it considered in rejected_candidates, with the reason it was passed over. Losing is not an error. It is evidence.

  1. clk_8f3aMeta2.6 h beforeSelected. GAID exact match, most recent in window
  2. clk_61c0TikTok53 h beforeolder click with same ad ID - last-click wins
  3. clk_4e77Google5.1 d beforeolder click with same ad ID - last-click wins
  4. clk_2b91unresolvedno timeSDK-reported click ID has no matching non-fraud click

Why it won, in one stored sentence.

The line you forward to a finance team, or to the channel disputing the install. It is written at attribution time into attributions.reason.

“GAID exactly matched click clk_8f3a; most recent of 3 candidate(s) in 7-day window”

attributions.reason · ins_5c02
  1. install_referrer98Play Install Referrer carries a Measura click ID through the store install.No Measura click ID in the referrer.
  2. click_id95The SDK reads a click ID from a deep link it opened.clk_2b91 reported, no matching click.
  3. ad_id70The advertising ID matches a click exactly. Last click wins.Matched clk_8f3a.
  4. fingerprint55The device fingerprint hash matches exactly. Never partial.Not reached.

Tiers are tried in order and the first match wins. Read how every install is scored

Installs start wherever your users already are.

One short link per campaign, tracked the same way whether it rides a paid network, a WhatsApp message, a QR code on a printed poster or a USSD code on a phone that cannot install apps at all.

  • WhatsAppShared in a chat, a group or a status.reach
  • QR CodePrinted on a poster, a pack or a receipt.reach
  • USSDA short code on any phone, no data needed.reach
  • SMSA link in a text message.reach
  • EmailA link in a campaign or a receipt.
  • MetaPaid ads on Facebook and Instagram.
  • GoogleSearch, YouTube and display ads.
  • TikTokIn-feed and creator ads.
  • TwitterClicks tracked. X has no install postback API.
  • Push NotificationA link in a push to existing users.
  • Influencer / ReferralA creator or a user with their own link.
  • OrganicNo link at all, still recorded and explained.
  • Any custom channelName it on the link, and it is tracked like the rest.

From a tap to a reason.

Five stations, the same for every install. Each one adds to the record, and nothing is thrown away on the way through.

01 · click

A tap on your link. One short link per campaign, on any channel, stored with its time and signals.

02 · install

The SDK reports it. Events are batched, gzipped and signed, and wait on the device when it is offline.

03 · ingest

Every event is checked. Verified, de-duplicated, fingerprinted and fraud-scored before anything counts it.

04 · attribution

Matched, with its working. Referrer, click id, ad id, fingerprint, then organic. The winner, the score, the clicks that lost and the reason are all stored.

05 · postback

Everyone hears about it. Your dashboard shows the install and why; the network gets a postback.

Illustrative. Field names, checks, tiers and scores are the system’s own.How the score is calculated

The engineer signs off. Here is what they will check.

One dependency, one init call, and the three permissions it needs merged into your manifest for you. Every figure here is enforced somewhere you can read, so the size on this page is the size CI allows.

dependencies {
    implementation 'dev.measura:measura-sdk:0.1.1'
}

On Maven Central. Add the line and sync.

Archive
SDK_SIZE_BUDGET_BYTES · lib/sdk-size.tsCI fails the build if the release AAR exceeds 102,400 bytes gzipped.
APK impact
SDK_APK_IMPACT_BYTES · sdk/android/size-probeOne app built with and without the SDK, R8 on. CI re-measures it on every push.
Floor
minSdk 21 · measura-sdk/build.gradleEvery Android version from Lollipop up.
Offline queue
maxOfflineQueueSize · MeasuraConfig.ktBatched on disk and gzipped, so a dropped connection never loses an event.
Retries
maxRetryAttempts · MeasuraConfig.ktA background job drains the queue even after the app is closed.
Network
wifiOnlyMode = true · MeasuraConfig.ktMobile data costs your users money. Turn it off per app if you need to.
Platform
Android only. There is no iOS SDK; any backend can post signed events to the ingest API.
Privacy
IPs truncated before storage, no hardware identifiers, Limit Ad Tracking honoured, disableTracking() stops collection.

Integration guideIngest API

Priced in USD. The free tier is enough to ship on.

The glass-box log is on every tier, the free one included. You pay for volume, fraud reporting, ROAS and deep links, not for the right to see your own reasoning.

Free

$0/month

Everything you need to start tracking attributions.

  • Up to 100,000 events/month
  • 1 Android app
  • 1 workspace
  • Last-click + probabilistic attribution
  • Glass-box attribution log
  • Short links across all channels
  • 14-day data retention
Start Free

Starter

$99/month

For growing teams that need fraud detection and ROAS.

  • Up to 5,000,000 events/month
  • Up to 5 Android apps
  • Up to 5 workspaces
  • Fraud detection + reporting
  • ROAS dashboard
  • Configurable retention, up to 90 days
  • Email support
Start Starter

Growth

$349/month

Full platform. Deep links, cohorts, campaign ROAS.

  • Up to 25,000,000 events/month
  • Unlimited Android apps
  • Unlimited workspaces
  • Deep linking + deferred deep links
  • Cohort retention analytics
  • Campaign spend + ROAS reporting
  • Migration importer
  • Priority support
Start Growth

Enterprise

Custom

Unlimited scale, dedicated infrastructure, SSO.

  • Unlimited events
  • Custom attribution windows
  • Custom retention policy
  • Custom fraud rule thresholds
  • Dedicated solutions engineer
Talk to Sales

Asked before switching.

Straight answers, including what Measura does not do yet.

Read the docsAsk us

Does Measura work with iOS?

Not today. Measura is Android only, from Android 5.0 (API 21) up. Any backend can post signed events straight to the ingest API, so server-to-server tracking works whatever the client is.

How do I get the SDK?

From Maven Central. Add dev.measura:measura-sdk:0.1.1 to your app dependencies; the docs have the full setup.

How does Measura decide which click gets the install?

It tries signals in a fixed order: the Play install referrer, a click id, the advertising id, then a device fingerprint. Each match gets a confidence score from 0 to 100, and anything under 20 is reported as organic. The clicks that lost are kept, so you can see what almost matched.

Can I see why an install was credited to a campaign?

Yes, on every plan including the free one. Each install is stored with its method, the signals used, its confidence score, the rejected candidate clicks and a sentence stating why it won.

What happens to events when a phone is offline?

They wait on the device in a queue of up to 10,000 events and are sent later. By default the SDK only sends over Wi-Fi, so it never spends your users’ mobile data; you can switch that off per app.

Does Measura block fraudulent installs?

It scores and tags them, with the rules that fired, and leaves the decision to you. Nothing is blocked automatically.

Can I bring my history from AppsFlyer, Adjust or Branch?

Yes. The migration importer reads exports from all three, and is included on the Growth plan and above.

Where is my data stored?

Measura is currently hosted in the United States and does not yet guarantee that data stays in a particular country. You can export your account’s data at any time from Settings.

Is there a free plan?

Yes: up to 100,000 events a month for one Android app, with the full glass-box log. No card is needed to start.

Never take a number on trust again.

Start on the free tier with 100,000 events a month. No card required.