Self-hosted affiliate software that runs as one file.
AffiliateTracking is self-hosted affiliate software you run on your own server. It's a single file of about 25 MB with SQLite built in, so there's nothing else to install. Pay $99 once and keep every version you download.
Linux, macOS and WindowsSQLite built inPostgres when you want it
# Linux on x86. Other builds below. $ chmod +x affiliate-engine-linux-amd64 $ ./affiliate-engine-linux-amd64 -listen :8080 -db sqlite:affiliate.db # That's the whole server. No Docker, # no Redis, no queue to look after.
Pick your file
What you download, and what it runs on
After you pay, you get a license key by email and a download page with one file per system. Every file is the whole product.
| System | File | Size |
|---|---|---|
| Linux, x86 | affiliate-engine-linux-amd64 | 26.1 MB |
| Linux, ARM | affiliate-engine-linux-arm64 | 24.5 MB |
| Mac, Apple silicon | affiliate-engine-darwin-arm64 | 25.0 MB |
| Mac, Intel | affiliate-engine-darwin-amd64 | 26.4 MB |
| Windows, x86 | affiliate-engine-windows-amd64.exe | 26.5 MB |
- Nothing else to installNo runtime, no database server, no Docker. SQLite is inside the file.
- A domain with HTTPS in frontIt doesn't handle HTTPS itself. Put Caddy, nginx or Cloudflare in front, like you would for any small app.
- Disk for your clicksAbout 2.5 GB at 100 clicks a minute, with 90 days of raw clicks kept. Totals take 13 MB a year.
Running in 5 steps
If you've put a small app behind a domain before, this takes about as long as reading it.
-
Start it
Run the file with a port and a database file. It creates the database and sets it up on first start.
$ ./affiliate-engine -listen :8080 -db sqlite:affiliate.db -
Make your admin key
It's shown once and stored hashed, so copy it somewhere safe right away.
$ ./affiliate-engine -db sqlite:affiliate.db keygen --scope admin --name ops # prints ae_... once
-
Tell it where links may go
Links only send people to domains you list. Set your public address and your proxy too, so visitors' real IPs and countries come through.
AE_ALLOWED_DEST="yourapp.com" \ AE_PUBLIC_URL="https://track.yourapp.com" \ AE_TRUSTED_PROXIES="127.0.0.1/32" \ ./affiliate-engine -listen :8080 -db sqlite:affiliate.db
-
Connect your billing
Add a webhook in Stripe pointing at your install, then give AffiliateTracking its signing secret. Paddle and Lemon Squeezy work the same way. Chargebee and Recurly use a username and password instead.
# Stripe webhook address https://track.yourapp.com/webhooks/stripe # The signing secret, not your API key AE_STRIPE_SECRET="whsec_..."
-
Open the admin screen
Go to your address, paste your admin key in the box at the top right and choose Admin. Then check the books any time with doctor.
$ ./affiliate-engine -db sqlite:affiliate.db doctor doctor: ALL CHECKS PASSED
SQLite now, Postgres if you outgrow it
Both run the same ledger rules and the same database triggers. The difference is how much you want to look after.
SQLite, built in
- No setup. The database is one file next to the app
- Backup, restore, doctor and test sales are one command each
- Measured at 19,613 clicks a second on an Apple M2
- Upgrading is swapping one file
Postgres, when you want it
- Point it at a Postgres URL and it sets up the tables on start
- Optional two-role setup: the app itself can't delete money rows
- Back up with pg_dump, like any Postgres app
- Backup, restore, doctor and test sales are SQLite only for now
# Postgres instead of SQLite
./affiliate-engine -db "postgres://user:pass@host:5432/affiliate?sslmode=verify-full"
Backups that check themselves
Take a backup while it runs. When you restore, AffiliateTracking checks the copy before it swaps it in, and keeps your current database aside in case you change your mind.
- The backup file is complete, with no half-written parts next to it
- SQLite's own integrity check passes
- The ledger still sums to 0
- Every table and every money guard is in place
Upgrading is replacing the file and restarting. Changes to the database run on start and only go forward, so take a backup first. Back up the .secret file next to your database too. It signs every tracking cookie.
# Snapshot while it runs $ ./affiliate-engine -db sqlite:affiliate.db backup # Check it, then swap it in $ ./affiliate-engine -db sqlite:affiliate.db restore -from snapshot.db # Nightly, from cron 0 3 * * * cd /srv/at && ./affiliate-engine -db sqlite:affiliate.db backup 0 4 * * * cd /srv/at && ./affiliate-engine -db sqlite:affiliate.db doctor
Locked down before you touch a setting
The defaults are the safe ones. You'd have to change something to make it less safe.
Owner-only files
The database and its secret file are readable only by the user running the app. It refuses a secret shorter than 32 bytes.
Webhooks checked first
AffiliateTracking checks every billing event's signature or password before it writes anything, and refuses bodies over 1 MB.
Rate limits on
120 clicks a minute per IP on links, 600 requests a minute per API key, and failed logins slowed before they touch the database.
No raw IPs
Visitor IPs become keyed hashes before storage. Turn on IP trimming and even the hash is less precise.
Keys stored hashed
You see each API key once, and AffiliateTracking keeps only a hash. Admin keys and single-affiliate keys are separate scopes.
Money rows guarded
Database triggers refuse edits and deletes on money tables. See what else the database refuses.
What $99 gets you, and what it doesn't
One payment, no renewal. Here's the whole deal in plain words.
You get
- Every feature, with no plan limits
- As many servers as you control
- Every brand your business owns
- 12 months of new versions
After 12 months
- Everything keeps working
- You keep every version you downloaded
- New versions stop coming
- The app never checks your key
Not included
- Hosting it for other companies
- A Docker image to pull. Wrap the file in your own if you like
- HTTPS or a service file. Your server setup does that
- Hosting. That's what cloud is for, from $49 a month
Not happy? Full refund within 14 days. Email us with "Refund request" in the subject. No reason needed.
Self-host FAQ
What is self-hosted affiliate software?
It's affiliate tracking you run on your own server instead of someone else's. Your affiliate and customer data stays in your database, and you pay for the software, not a monthly seat.
What do I need to run it?
A server or VPS running Linux, macOS or Windows, a domain, and HTTPS in front of it. You need to be comfortable running a command on that server.
Does it need Docker?
No. It's one file. You can put it in your own container if that's how you run things, but there's no image to pull yet.
Will it run on ARM, like a Raspberry Pi or Graviton?
Yes. There's a Linux ARM build, and a Mac build for Apple silicon.
How much disk does it use?
About 2.5 GB at 100 clicks a minute, 12.6 GB at 500 a minute, with 90 days of raw clicks kept. After that, it prunes raw clicks and totals take about 13 MB a year.
Does the app check my license key?
No. Your key is for downloading new versions. The app runs the same with or without it.
What happens after my 12 months of updates?
It keeps working. You keep every version you downloaded, you stop getting new ones.
Can I move to Postgres later?
Yes. It runs on Postgres too, with an optional setup where the app can't delete money rows. Backup, restore and doctor are SQLite only for now.
Your server. Your data.
$99 once.
Buy self-host, download your file and be running in 5 steps. Full refund within 14 days. Rather not run a server? Cloud is free for 14 days, see the cloud plans.