Integrations Connect the tools you already have. The visitors stay the same.
Paste the script on the site you already run. Ad click IDs are read from the landing-page URL. Alerts and webhooks go out when you need them.
- 8 site builders
- 14 ad click IDs
- Signed webhooks
Site builders · 8
Ad platforms · 14
Notification channels · 5
Webhooks · 7
The script goes where your site already lives
WordPress, Shopify and Webflow can use a plugin. Everywhere else, the same script goes into custom code. Analytics and Chat still share it.
WordPress
Drop the script into the theme, or install the plugin.
WooCommerce
The storefront uses the same script. Orders can also be sent from the server API.
Shopify
Drop the script into the theme, or install the plugin.
Webflow
Drop the script into custom code, or install the plugin.
Squarespace
Paste the script into header code injection.
Wix
Paste the script into the site's custom code.
Ghost
Paste the script into code injection.
Framer
Paste the script into the site's custom code.
14 click IDs, read from the landing-page URL
No extra snippet per platform. The script reads the click ID already on the URL. Ten platforms below are global, four are in China.
Google Ads
gclid, wbraid and gbraid on the landing page.
Meta
fbclid on the landing page.
TikTok
ttclid on the landing page.
Microsoft Ads
msclkid on the landing page.
X Ads
twclid on the landing page.
li_fat_id on the landing page.
Snapchat
ScCid on the landing page.
epik on the landing page.
Reddit Ads
rdt_cid on the landing page.
Yandex Direct
yclid on the landing page.
Ocean Engine
clickid on the landing page, from Douyin and Toutiao.
Baidu Marketing
bd_vid on the landing page.
Tencent Ads
gdt_vid for WeChat traffic, qz_gdt for everything else.
Kuaishou Magnetic Engine
callback on the landing page.
Click-ID parameters recognised automatically
Any one of these on the landing-page URL assigns the visit to its platform. Import costs and channel ROI appears in marketing analytics.
Alerts arrive where the team already is
Which channels your plan includes is on the pricing page. Anything not listed can go out through a webhook.
A chart or an alert in the inbox you already read.
Slack
Post to a channel through an incoming webhook.
WeCom
Markdown alerts into a WeCom group.
DingTalk
Alerts into a DingTalk group.
Lark
Alerts into a Lark group.
- Sign-ups · mobile −38%Tue 09:40 · submit errors 2% → 41% · open →WeCom
- Checkout exit rate above 45%Mon 08:00 · second day in a rowSlack
- Weekly report: Newsletter ROI 6.2×Mon 09:00 · subscribed report · PDF attachedEmail
When something you care about happens, a signed POST goes out
Each endpoint has a shared secret. Requests carry an HMAC-SHA256 signature and a timestamp — verify the signature before trusting the body. Failed deliveries retry automatically, up to 5 times.
- Signature: X-TapCub-Signature, HMAC-SHA256
- Replay protection: timestamps older than 5 minutes are rejected
- Retries: exponential backoff, up to 5 attempts
- Alertsalert.fired and alert.recovered.
- Privacy requestsdsar.status as an export or deletion progresses.
- Exportsexport.done when a file is ready to download.
- Product signalsinbox.new_candidates, segment.membership_change, identity.merge_conflict.
# Sent to your endpoint when a monitor fires
POST /hooks/tapcub HTTP/1.1
Content-Type: application/json
X-TapCub-Signature: sha256=7f1c…d9a0
X-TapCub-Timestamp: 1727841600
{
"event": "alert.fired",
"project": "acme-web",
"monitor": "signup_mobile",
"metric": "signups",
"value": 112,
"baseline": 181,
"change": "-38%",
"url": "https://app.tapcub.com/p/acme-web/monitors/signup_mobile"
}
# A 2xx response counts as delivered; otherwise retried with exponential backoff// Verify the signature before trusting the body
const sig = crypto.createHmac('sha256', SECRET)
.update(ts + '.' + body).digest('hex');
if ('sha256=' + sig !== req.headers['x-tapcub-signature'])
return res.status(401).end();
// Reject timestamps older than 5 minutes
if (Math.abs(Date.now() / 1000 - Number(ts)) > 300)
return res.status(401).end();An integration is not another snippet
The website keeps one async script. Everything else is either already on the URL or a message you send out.
- Analytics and Chat share the script
- Ad click IDs are read from the landing-page URL, with no per-platform tag
- Anything that never happens in a browser goes through the server API
- Webhooks carry alerts and exports into your own systems
About integrations
Still have a question?
Chat with the team behind TapCub — we usually reply within a few hours on business days.
Do I need a snippet per ad platform?
No. 14 click IDs are read from the landing-page URL: ten global platforms and four in China (Ocean Engine, Baidu Marketing, Tencent Ads, Kuaishou Magnetic Engine).
Which site builders are listed?
WordPress, WooCommerce, Shopify, Webflow, Squarespace, Wix, Ghost and Framer. WordPress, Shopify and Webflow can use a plugin; the others take the script in custom code.
Which are the four Chinese platforms?
Ocean Engine (clickid), Baidu Marketing (bd_vid), Tencent Ads (gdt_vid and qz_gdt), Kuaishou Magnetic Engine (callback).
How are webhooks signed?
Each endpoint has a shared secret. The X-TapCub-Signature header carries an HMAC-SHA256 signature and X-TapCub-Timestamp the timestamp. Verify the signature before trusting the body.
Can I skip the plugin and just paste the script?
Yes. The script is enough. Plugins are only a shorter route on WordPress, Shopify and Webflow.
How do attribution platforms (AppsFlyer, Adjust) connect?
App install attribution arrives through a postback, so each install carries its channel and campaign and sits next to retention and payment. See app analytics.