From nothing to a first attributed event.
Measura matches an Android install back to the click that caused it, and stores the reasoning: which signal matched, how strong it was, and which candidates it rejected. Other tools return the verdict alone. Here you can audit a number you do not believe.
| Signal | How it matches | Base confidence |
|---|---|---|
install_referrer | Click id carried through the Play Store install | 98 |
click_id | Click id read from a deep link the SDK opened | 95 |
ad_id | Advertising id matched exactly | 70 |
fingerprint | Device fingerprint hash matched exactly | up to 55 |
organic | No signal matched | n/a |
Tried in that order, first match wins. A deterministic answer is never replaced by an inferred one.
dependencies {
implementation 'dev.measura:measura-sdk:0.1.1'
}Archive under 100 KB gzipped, held there by a build gate. Budget about 312 KB of APK growth in a minified release build, mostly WorkManager and Room. Permissions come through manifest merging.
<uses-permission
android:name="com.google.android.gms.permission.AD_ID"
tools:node="remove" />Create an account to get an API key: msr_ followed by 64 characters, shown once.
import android.app.Application
import dev.measura.sdk.Measura
import dev.measura.sdk.core.EventType
class MyApplication : Application() {
override fun onCreate() {
super.onCreate()
Measura.init(this, "msr_your_key_here")
}
}
// Then anywhere in your app:
Measura.trackEvent(
EventType.PURCHASE,
mapOf("revenue" to 49.99, "currency" to "USD")
)The install event and first session fire automatically.
For consent, initialise normally and call Measura.disableTracking() until the user agrees. The decision is written to disk immediately and survives a process kill, so events are dropped rather than queued.
Any backend can post signed events directly. Each carries an HMAC-SHA256 signature over a canonical payload, so ingest needs no session. Rules: event ingestion.
Within seconds of an install, a worker searches the app’s attribution window for a click that could have caused it, walking the signals above in order until one matches.
Every attribution scores 0 to 100. It starts at the base for the signal that matched, then moves on device entropy, click-to-install delta, shared IP, and the fraud pre-screen.
Below 20 it is downgraded to organic. The evidence is kept either way.
Every attribution stores its method, signals, written reason, confidence breakdown, and the candidate clicks it rejected with a reason for each. When an install lands somewhere you did not expect, you see the click that won, the ones that lost, and why. Read it at resource=attribution_log.
| Platform | Status |
|---|---|
| Android | Supported. Play Install Referrer, deep links, offline queue. |
| Server to server | Supported. Post signed events from any backend. |
| iOS | Not supported. |
Android is most of the market we serve, and it carries the strongest signal there is: the Play Install Referrer passes a click id through the store install, so the match is deterministic. One platform keeps the SDK small and its offline path properly tested. For anything else, the ingest API accepts signed events from any backend.