iOS Install Referrer: Alternatives Without Fingerprinting

Also in: German · Spanish

On Android, attributing a referral after an install is a solved problem: you put the code into the Play Store link, and your app reads it back on first launch. Then you build the iOS version, look for the same API — and there isn't one.

This guide covers what Android gives you, why iOS has no equivalent, and every option that does exist on iOS — checked against Apple's documentation. It ends with a deterministic design and a decision table.

Sources: Apple Developer documentation, App Store Connect Help and Android Developers documentation, as of October 2026. APIs and policies change — check the linked pages before you build.

The short answer

Option Works before the app is installed? User-level? Deterministic?
Play Install Referrer (Android only) Yes Yes Yes
Universal links No — the link opens your website Yes Yes
Fingerprinting / probabilistic matching Sometimes Guessed No — and Apple doesn't allow it
Clipboard Yes, if the clipboard survives Yes Yes, when it works
App Clip Yes, if the user opens the clip first Yes Yes
AdAttributionKit / SKAdNetwork Yes, for registered ad networks No — aggregate Not for people
Apple offer codes (custom codes) Yes Per offer, not per code Partly
Manual code entry in onboarding Yes Yes Yes
Web signup first, then app login Yes Yes Yes

No iOS API hands you a referral code on first launch. A reliable setup combines several deterministic options.

What Android gives you: the Play Install Referrer

Google's Play Install Referrer API lets an app "securely retrieve referral content from Google Play". You add a referrer parameter to the store link — Google's example is https://play.google.com/store/apps/details?id=com.example.package&referrer=example_referrer_source (documented here) — and after the install the client library returns a ReferrerDetails object:

  • getInstallReferrer() — the referrer string from the link
  • getReferrerClickTimestampSeconds() — when the link was clicked
  • getInstallBeginTimestampSeconds() — when the install started
  • getGooglePlayInstantParam() — whether the user used your instant experience in the past 7 days

The service documentation adds server-side timestamps and the app version at first install. Google says the data stays available for 90 days. For a referral program, that's everything: the code travels with the install.

Why iOS has no equivalent

The App Store does accept parameters on a link — just not for your app. App Store campaign links carry a provider token (pt=) and a campaign token (ct=), and the results appear in App Store Connect Analytics: aggregated, with each metric shown only once it reaches a threshold of 5 in the selected date range. Apple doesn't document a way for the installed app to read the ct value.

Apple's attribution tools measure campaigns, not who invited whom. The code has to reach the app through a path the user takes.

The options, one by one

Universal links are normal HTTPS links that iOS opens in your app instead of the browser. A link like https://example.com/r/ABC123 can carry the code straight into onboarding.

The catch is in Apple's own description: "If the person hasn't installed your app, the system opens the URL in their default web browser". The person you're referring usually doesn't have the app yet — universal links only help if they install first and tap the link afterwards.

Before you rely on them:

  • You need the Associated Domains entitlement and an apple-app-site-association file. Per Apple's associated domains documentation, its CDN requests the file within 24 hours, and devices check for updates about once a week after install.
  • If the user is browsing your site in Safari and taps a universal link on the same domain, iOS keeps it in Safari. Test referral links from Messages and other apps, not only from your own site.

A related helper is the Smart App Banner: with an app-argument, it opens the installed app with that URL. Per Apple, after a download from the banner the button changes to Open when the user returns to the page — so if they come back, the code still arrives.

2. Deferred deep linking via fingerprinting — what Apple says

To bridge "link clicked, app not installed", some deep-linking setups use probabilistic matching: on the click, a server records signals such as IP address, user agent, OS version and time; on first launch, the app sends the same signals, and the server guesses which click belongs to which install.

Apple addresses this in its User Privacy and Data Use FAQ. Asked whether you can fingerprint or use device signals to identify a device or user, the answer is no — "you may not derive data from a device for the purpose of uniquely identifying it" — and apps doing this, or using SDKs that do, may be rejected. The required reason API documentation adds that fingerprinting is not allowed regardless of whether the user grants tracking permission. App Tracking Transparency consent doesn't fix it.

It's also a weak basis for paying money. Matches are guesses: an office or a mobile carrier can put many people behind one IP address, and the wrong person gets the commission. The signals are getting worse — with iCloud Private Relay, websites visited in Safari see a temporary IP address (Apple Support). And "the match score was too low" is not an answer a referrer accepts.

3. The clipboard — and the paste prompt since iOS 16

The landing page copies the code (or the whole referral link), and the app reads it on first launch. Either the code is on the clipboard or it isn't — deterministic.

iOS has tightened this. Since iOS 14 the system notifies the user when an app reads another app's pasteboard content without user intent. And per the UIPasteControl documentation, "In iOS 16 and later, programmatic pasting raises a user alert that prompts the user for approval". A permission prompt on first launch, before the user knows why, is a poor start.

The fix is to let the user paste:

  • UIPasteControl / SwiftUI PasteButton (iOS 16+) — a system button the user taps; Apple's docs say to use it "to paste without a user prompt".
  • Pattern detection — detectPatterns(for:completionHandler:) (iOS 14+, async variants since iOS 15) tells you whether the pasteboard holds a probable web URL, a number or a web search term. It doesn't reveal the contents, so the system doesn't notify the user. The detectValues methods do return contents — and do notify.

So: copy the full referral link (a URL), check for it silently, and only then show a paste button:

let found = try? await UIPasteboard.general.detectedPatterns(for: [\.probableWebURL])
showPasteInvite = found?.contains(\.probableWebURL) == true
// In onboarding: PasteButton(payloadType: String.self) { items in parseCode(items.first) }

The user may copy something else before the first launch, so treat paste as a shortcut next to a code field.

4. App Clips — the closest thing to an install referrer

An App Clip is a small part of your app that launches without a full install — from a link, QR code, NFC tag or App Clip Code. It receives its invocation URL on launch (responding to invocations), so https://example.com/r/ABC123 hands the clip the code.

The clip can write to a shared App Group container or shared UserDefaults. When the user installs the full app, which replaces the clip, the full app can read that data (sharing data between App Clip and full app). Store the code there and the full app finds it on first launch.

Trade-offs: it's real native work (an extra Xcode target, App Clip experiences in App Store Connect, Apple's size limits), and it only covers users who open the clip before installing. Clips also can't request tracking permission — irrelevant here, since the user brings the code with them.

5. AdAttributionKit and SKAdNetwork — aggregate, not user-level

Apple's install attribution is AdAttributionKit (iOS 17.4+) and the older SKAdNetwork, whose page now directs App Store ad campaigns to AdAttributionKit. Both serve ad networks that register with Apple and sign their ads. Postbacks arrive with a documented minimum delay of 24 to 48 hours, their detail depends on crowd anonymity tiers, and the signed postback "doesn't include user- or device-specific data".

Right tool for ad campaigns, wrong one for referrals: your referrers aren't ad networks.

6. Apple offer codes with custom codes

Subscription offer codes give a discounted or free period. Custom codes are named codes such as SPRINGPROMO, up to 64 characters, redeemable via a redemption URL or in your app (iOS 14+). As of October 2026, App Store Connect Help lists up to 1 million redemptions per app per quarter and up to 10 active offers per subscription SKU.

Good for rewarding the invitee, limited for attribution:

  • In StoreKit, the transaction's offer ID holds the reference name of the offer; the documentation doesn't describe a field for the individual custom code. Telling referrers apart would take one offer each — and 10 per SKU don't go far.
  • In-app redemption happens in Apple's system sheet, and Apple says not to use a custom UI, so your app doesn't see what was typed.

Use them for a few large partners, or as the discount on top of your own code — not as the code itself.

7. Manual code entry in onboarding

The least clever option is the most reliable: an "Invite code?" field in onboarding or on the paywall. It works for every route — App Store search, a code said out loud, a screenshot. Keep it low-friction: short codes without look-alike characters (0/O, 1/I), case-insensitive matching, instant validation, and prefill it whenever a code arrives another way.

8. Web signup first, then account linking

If your product has accounts, this skips the install problem: the user signs up on your website, the code is stored with the account, and when they log in to the app, your backend already knows who referred them.

For in-app purchases, connect the transaction to that account: StoreKit's appAccountToken (iOS 15+) takes a UUID for your user, and the App Store returns it in the resulting transaction.

A deterministic design that works

Every route ends in the same place — a code attached to a user:

  1. Each referrer gets a code and a link on a domain your app handles, e.g. https://example.com/r/ABC123.
  2. App installed: the universal link opens the app, onboarding shows the code prefilled, the user confirms.
  3. App not installed: the link opens a landing page with the code in large type, a "Copy code" button (copy the full link so pattern detection finds it), an App Store button and — if you have accounts — "Sign up on the web".
  4. First launch: onboarding shows the code field, plus a paste button if a probable URL is on the pasteboard. Never read the clipboard silently.
  5. Web signup: the code is already on the account; app login links it, and appAccountToken ties the purchase to it.
  6. Server side: validate the code, block self-referrals, attach it to the subscription.

Users who skip all of this aren't attributed. That's the honest cost of not guessing.

Decision table

Your situation Use
Subscription app, installs come from the App Store Code entry + universal link prefill + paste button
Users usually sign up on the web first Web signup linkage + appAccountToken; code entry as fallback
QR codes, posters, events App Clip passing the code via an App Group, if you can invest in native work
You want to give the invitee a discount Apple offer code for the discount, your own code for attribution
You're measuring paid ad campaigns AdAttributionKit / SKAdNetwork via your ad network
You're tempted by "magic" install matching Don't — Apple doesn't allow fingerprinting, consent or not

Checklist before you ship

  • Code field in onboarding and on the paywall, validated instantly
  • Universal links set up and tested from Messages, not only from your own site
  • Clipboard only via PasteButton/UIPasteControl; silent checks only with pattern detection
  • Web signups store the code server-side; in-app purchases carry appAccountToken
  • No SDK in the app that does fingerprint or probabilistic matching
  • Program terms visible in the app (see the App Store rules for referral programs)

Where AppThunder fits

AppThunder Referrals is built on this deterministic model: a referral counts only when a code actually arrives — no device fingerprinting, no probabilistic matching. Codes come in three ways: the subscription webhook (your app stores the code as the subscriber attribute at_ref, and in-app subscription events carry it), the Stripe webhook for web checkouts, and a REST API for your backend (POST /codes, /referrals, /events with the secret key; GET /codes/:code with the public key to validate a code typed into your onboarding field). Copy-paste templates exist for Swift, Kotlin, React Native, Flutter and the web; the web snippet keeps a code first-touch for 90 days on the same device, which covers "visit now, sign up on the web later".

Commissions stay pending for a 30-day hold by default, refunds void them, self-referrals are blocked, and you pay out yourself from exports (PayPal Mass Pay, Wise batch, CSV) — AppThunder never holds or moves money. As of October 2026 it costs €19 per month flat, net, with no revenue share.

What it doesn't do: attribute a user who never enters, pastes or brings a code — that's the trade-off of not guessing. It doesn't set up your universal links, Smart App Banner or App Clip, and it can't give you an install referrer on iOS, because none exists.

FAQ

Is there an iOS equivalent of the Play Install Referrer? No. Apple's install attribution (AdAttributionKit, SKAdNetwork, campaign links) is aggregate. A per-user code has to arrive through a path the user takes — a link, a paste, an App Clip, a typed code or an account.

Can I fingerprint if the user allows tracking? No. Apple's documentation says fingerprinting is not allowed regardless of tracking permission.

Can I read the clipboard on first launch? Since iOS 16, a programmatic read triggers a permission alert. Use PasteButton or UIPasteControl so the user pastes deliberately, without the prompt.

Can Apple offer codes replace my referral codes? Not fully. StoreKit identifies the offer by its reference name, not the individual custom code, and there are at most 10 active offers per subscription SKU.