Keitaro + Cloaker: Two Setups That Work

If your traffic already lives in Keitaro, you do not need to replace the tracker with a cloaker: you can plug the cloaker in as a filter inside a Keitaro flow, or put it on the landing page and send conversions back to the tracker with a postback.

Tracking and Analytics11 min read
Keitaro + Cloaker: Two Setups That Work
Contents
  1. Why connect Keitaro and a cloaker
  2. Setup 1: Keitaro cloaking with ArtisanClo as a flow filter
  3. Setup 2: cloaker on the landing page, Keitaro as an external tracker
  4. Which setup to choose
  5. How to test the setup before launching traffic
  6. Common mistakes when connecting Keitaro and a cloaker
  7. What you get in the end
  8. The bottom line

Keitaro is one of the most widely used trackers among affiliate teams: campaigns, flows, offers and reports are all set up there, and nobody wants to move away from it. The good news is that you do not have to. ArtisanClo sits next to Keitaro and handles a single job: deciding whether the visitor is a real person or a bot, and recording the reason for that decision. Everything else stays in your tracker. Keitaro is installed on your own server; how that differs from a cloud option is covered in cloud vs self-hosted tracker.

Why connect Keitaro and a cloaker

A tracker and a cloaker solve different problems. A tracker counts: where a click came from, where it went, what it cost and what it earned. A cloaker decides: who sees the offer and who sees a neutral White Page. The difference is explained in detail in cloaker vs tracker: what is the difference.

When you already work in Keitaro, what you need is not a second accounting system but a reliable “let in or not” answer right inside your existing setup. That gives you two ways to connect them.

Setup 1: filter inside Keitaro Setup 2: cloaker on the landing page + Keitaro
Who sees the visit first Keitaro Your landing page with the tag or PHP file
Where the check runs A flow filter in the Keitaro campaign On the landing page
Who routes the visit Keitaro flows The ArtisanClo flow; the offer is a Keitaro link
Browser check (JavaScript, time on page) No Yes
What you need to do Put the filter file on the Keitaro server Install the JS tag or PHP file and set up a postback
When to choose it Traffic already runs through Keitaro links You need full checks plus conversions in the cloaker's stats

Setup 1: Keitaro cloaking with ArtisanClo as a flow filter

Here the ad link points to a Keitaro campaign, as before. Before serving the offer, Keitaro asks ArtisanClo whether to let this visit through. If the answer is yes, the offer flow handles it. If no, the visit falls through to the flow below, the one with the White Page.

Step-by-step setup

  1. Create a flow in ArtisanClo. A flow is one campaign: the source, filtering rules, geo and protection.
  2. Open the flow menu → Connect → Keitaro filter and download this flow's filter file.
  3. Put the file on the Keitaro server in /var/www/keitaro/var/filters (in older versions, application/filters) and reload the Keitaro page.
  4. In the Keitaro campaign, open the offer flow and add the filter with the file name in Yes mode.
  5. Below it, place the flow with your White Page: everyone the filter did not let through ends up there.

Note that the offer and White Page URLs set in the ArtisanClo flow are not used in this setup. Your Keitaro flows decide where to send a person and where to send a bot; ArtisanClo only answers “let through?”. In effect, Keitaro acts as a TDS here, distributing traffic, while the filter just gives it the answer.

Filter limitations

Keitaro calls the filter before it responds to the visitor. There is no way to show the browser a check page at that moment, so:

  • the JavaScript check, minimum time on page and live interaction check do not apply;
  • the decision is based on the network and request traits: IP address, ISP, data center, VPN and proxy, headers, the click ID, plus geo, device and schedule rules;
  • if the service does not respond within 3 seconds, the visit goes to the White Page.

For many sources that is enough: server traffic, data centers and proxy networks give themselves away at the network level. Bots that run a real browser and pretend to be human are not always visible from the network; the browser check in setup 2 catches those.

Shadow mode and Tracker mode

The Keitaro filter supports shadow mode: it blocks nobody and only marks in the log who it would have blocked. This is handy when you suspect you are losing real people, or want to see what tighter rules would do without risking traffic. Do not leave shadow mode on for long: while it is active, the offer is open to everyone.

The flow's Tracker mode also works with the Keitaro filter: everyone goes to the offer and bots are only flagged in reports. It is useful when you want to know the bot share in the traffic you paid for but are not ready to filter yet.

Tip. Right after connecting, open the click log in ArtisanClo and look at the decision reasons for the first visits. If they are all blocked for the same reason, an audience rule (geo, for example) is probably not set up for your traffic.

Setup 2: cloaker on the landing page, Keitaro as an external tracker

In the second setup, your site meets the visit first. It carries the ArtisanClo JS tag or PHP file, and the site stays with you, on your hosting and your domain. The cloaker runs the full check, including the browser, and decides: White Page or offer. The “offer” here is a link to your Keitaro campaign, and from there everything works as usual.

How to connect the cloaker to a site is described in detail in connecting a cloaker: JS tag or PHP file.

How to send conversions from Keitaro back to the cloaker

In Cloaking mode the cloaker does not see conversions on its own: it knows who it let through but not who bought. To get CR and revenue into its statistics, you need to close the loop:

  1. In the ArtisanClo flow, open step 3. Tracker → the External tracker block and pick Keitaro from the list. The “?” button next to it shows a note and a link to the tracker's documentation.
  2. Copy the parameter for the ad link, which looks like external_id={click_id}. The Add to the link button appends it to every offer in the flow. The field turns green if the parameter is already in the offer link and red if it is not.
  3. In Keitaro, capture this parameter into one of the campaign's sub parameters so the tracker stores the ArtisanClo click number.
  4. In ArtisanClo, open the window with the postback URL and paste it into the Keitaro campaign postback settings, substituting the stored parameter and the conversion status.
  5. Send a test conversion and check the status line.

The offer link in the flow will look roughly like this:

https://trk.your-domain.com/AbCdEf?external_id={click_id}

ArtisanClo replaces {click_id} with the number of the specific click. Keitaro stores it, and when the affiliate network sends the tracker a conversion, Keitaro forwards it on, so the conversion attaches to the original click in the cloaker. The How click_id makes the round trip diagram in the dashboard shows this path visually. If click IDs are new to you, see Click ID and Sub ID.

What the status line means

Message What to do
“Conversions are already coming in” Nothing, the loop is closed
“Postbacks are reaching us, but none has matched a click yet” Keitaro is sending the wrong parameter: make sure the postback carries the value from external_id, not the tracker's own click ID
“One step left: point your tracker's postback to our address” No postback from Keitaro has arrived yet

Also look at Conversions setup → Log: it lists the latest incoming messages with their outcome, such as “lead recorded”, “click not found”, “no click_id”. The outcome tells you right away at which step the chain breaks.

Which setup to choose

  • Campaigns are already built in Keitaro and you do not want to rework landing pages: setup 1. It slots into the existing flow and does not touch the pages.
  • You need a browser check, plus CR and revenue right in the cloaker's statistics: setup 2, the tag or PHP file on the landing page plus a postback from Keitaro.
  • A source with a large share of server traffic (native, push, pop): setup 1 is often enough, because that traffic is visible at the network level. More about platforms in the traffic sources section.
  • You only want to measure bots without filtering: setup 1 with Tracker mode or shadow mode.

You can mix both setups across campaigns: one campaign, one flow, each with its own connection method.

How to test the setup before launching traffic

Before you turn on the budget, run through the setup by hand. It takes ten minutes and saves a day of troubleshooting.

  1. Your own click. Open the ad link on your phone over mobile data. A visit with a decision reason should appear in the ArtisanClo click log, and a click in the right flow should appear in Keitaro. If you do not want your test clicks to be checked, add your address to the flow's IP whitelist with the Add my IP button.
  2. A click from a data center. Open the same link through a VPN or from a server. The visit should go to the White Page flow and get a reason in the log such as “VPN or proxy” or “High-risk network”.
  3. Parameters. Make sure campaign parameters (utm_campaign, sub1 and others) reach Keitaro intact: open the click card in the ArtisanClo log and compare it with what the tracker recorded.
  4. A conversion. For setup 2, send a test conversion from Keitaro and check that the status line has changed to “Conversions are already coming in”.

Only then switch the flow to Active and start the ads.

Common mistakes when connecting Keitaro and a cloaker

  • The White Page flow sits above the offer flow. Then the visit never reaches the filter. The order is: offer flow with the filter in Yes mode first, White Page below.
  • The filter is in No mode. The logic flips: the visitors the cloaker filtered out go to the offer.
  • A filter file from a different ArtisanClo flow. The file is tied to a specific flow; each campaign has its own.
  • A postback with the Keitaro click ID instead of external_id. Conversions arrive, but “no click matched”.
  • Comparing numbers across different dates. The conversion log filters by arrival date by default, while reports assign revenue to the click date. Switch the log to Click date and the cloaker's numbers will match Keitaro. How to reconcile revenue by status is covered in conversion statuses.

What you get in the end

Once connected, ArtisanClo shows a decision reason for every visit: “Allowed”, “VPN or proxy”, “Ad verification or spy service”, “Outside campaign hours” and dozens more. Keitaro keeps the money, the offers and the reports you are used to. If something goes wrong (fewer conversions than usual, a drop in pass rate), the investigation starts with the click log and the flow's diagnostics, described in why a click went to the White Page.

Integration details are collected on the ArtisanClo and Keitaro page.

The bottom line

Keitaro and a cloaker do not compete, they complement each other. The flow filter setup slots into existing campaigns in a few minutes and decides based on the network and request traits. The tag or PHP file setup on the landing page gives you a full browser check, and a postback from Keitaro brings conversions and revenue back into the cloaker. Choose based on where your campaigns already live and how deep a check your traffic needs.

Frequently asked questions

01

Can I connect a cloaker to Keitaro without changing the landing page?

Yes, with a flow filter. The filter file goes on the Keitaro server, and in the campaign you add the filter to the flow with the offer. Neither the landing page nor Keitaro itself is rebuilt; only the order of flows in the campaign changes.

02

Why does the JavaScript check not work with the Keitaro filter?

Keitaro queries the filter before it responds to the visitor, so there is nowhere to show a browser check page. The decision is made from the network, the IP address and request traits. If a browser check matters for your platform, use the setup with a JS tag or PHP file on the landing page.

03

What happens if the cloaker does not respond to Keitaro?

If the service does not respond within three seconds, the visit goes to the White Page, which means the lower flow in the campaign. A connection failure does not let an unchecked visit through, and the click log shows what happened.

04

Where do I get the postback URL for the cloaker in Keitaro?

The postback URL is issued by ArtisanClo, not by Keitaro: the Tracker step of the flow has a link to a window with the ready URL. Paste it into the postback settings of the Keitaro campaign so the tracker forwards conversions back.

05

Do I need a separate ArtisanClo flow for each Keitaro campaign?

Ideally, yes. One campaign, one flow: that way decision reasons, statistics and diagnostics relate to a single ad, and you can see exactly where the filter is cutting traffic.

Read next

See your traffic for real

Connect ArtisanClo to your site, see who actually arrives from your ads, and why every click got its decision.