Install the tracking script
One tag. It turns the referral code on an incoming tracked link into a first-party cookie, and hands that code to your checkout. The tag alone credits nothing: a sale is credited when the code reaches Klibon, on a signup or on the payment, and the Setup page will not let a program go live until one has.
The snippet
Copy it from your program's Setup page — the one below is the shape, with your program id in place of <program_id>.
<script async src="https://go.klibon.com/klibon.js?p=<program_id>"></script> Paste it in <head> on every page a tracked link can land on, plus every page that starts a checkout. Site-wide is the simple answer. It is async and does no network work for ordinary visitors.
Working with a coding agent? The Setup page also has Copy prompt for your AI agent: your tag plus the checkout steps for the processors you connected, ready to paste into Cursor, Claude Code or Codex.
The script is generated per program, so your cookie window is compiled into it. Changing your terms later never asks you to paste the snippet again.
What it does
- Reads
viafrom the URL — andkc, the affiliate's coupon code, when the link carries one. Each must match/^[A-Za-z0-9_-]{1,64}$/; anything else is ignored. - Writes the cookie
_klb, value<code>.<timestamp>[.<coupon>], withmax-age= your cookie window in days × 86400,path=/,SameSite=Lax, andSecurewhen the page is served over HTTPS. - Removes
viaandkcfrom the address bar withhistory.replaceState. Every other query parameter and the fragment are preserved, so your own UTM tags and anchors survive. - Decorates Stripe Payment Link anchors with the code, and prefills the coupon where the checkout accepts one (Coupon codes).
Last click wins. A later via overwrites the cookie. A visit with no via changes nothing.
Sharing the cookie across subdomains
By default the cookie belongs to the exact host that set it, so a code captured on www.example.com is invisible to app.example.com, and so is window.Klibon.referral() on pages there. If your landing page and the page that starts your checkout live on different subdomains, add data-cookie-domain:
<script async
src="https://go.klibon.com/klibon.js?p=<program_id>"
data-cookie-domain=".example.com"></script>The leading dot covers the apex and every subdomain. Use it only for domains you control.
Stripe Payment Links
The script rewrites every a[href*="buy.stripe.com"] link to carry ?client_reference_id=<code>. That is the field Stripe sends back on the checkout session, and the one Klibon reads to attribute the sale.
It runs twice: once at DOMContentLoaded, and again on click, from a capturing listener — so a link your framework renders after load is covered too. A client_reference_id you set yourself is never overwritten. The same goes for prefilled_promo_code, which is added when the visitor has a coupon to use and left alone when you set one.
Report signups
If your product has accounts, this is the simplest way to get sales credited. Call Klibon.signup() once an account is created, with its email:
// Right after an account is created, with the email it was created with.
// Safe to call on every signup: nothing is sent for a visitor nobody referred.
window.Klibon?.signup(user.email)
// An object works too; only the email is sent.
window.Klibon?.signup({ email: user.email })Klibon ties that email (stored hashed, never in the clear) to the affiliate in the visitor's cookie. Every later payment made under the same email is credited to them, even when the checkout carries no code and even when the customer pays from another device. Prefill your checkout with the account's email so the payment is recorded under it.
- It sends nothing for a visitor nobody referred, so there is nothing to check first. It never throws and there is nothing to wait for.
- A signup credits payments for as long as your cookie window, counted from the signup. An email that is already a customer keeps its affiliate.
- Last click still wins. If the payment itself carries another affiliate's code or coupon, that affiliate is credited instead.
- The tag has to be on the page that calls it. If signup happens on another subdomain, share the cookie with
data-cookie-domain(above).
Checkouts you create yourself
Any other checkout — a Checkout Session you create server-side, a different processor — needs the code passed on explicitly. Read it in the browser when the visitor starts the checkout, and send it with your checkout request:
// In the browser, when the visitor starts a checkout. null for a visitor who was
// not referred, which is most of them.
const referral = window.Klibon ? window.Klibon.referral() : null
await fetch('https://api.example.com/checkout', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ priceId, referral })
})On the server, treat it like any other input from the browser: check its shape, then hand it to your processor.
// On your server. The code came from the browser, so keep it only if it has the
// shape of a Klibon code: 1 to 64 letters, digits, dashes or underscores.
const referral = req.body.referral
const code = typeof referral === 'string' && /^[A-Za-z0-9_-]{1,64}$/.test(referral)
? referral
: undefined This works wherever your checkout API lives: on your site, on a subdomain such as api.example.com, or on another host entirely. Where the code goes on the processor's side is in its guide, for example Connect Stripe.
Reading the cookie on the server instead
When the checkout request goes to the same origin as the page (a form post, or a fetch to /api/checkout on the same host), the browser sends the _klb cookie with it, and the server can read the code there:
// Only when the checkout request goes to the same origin as the page: the browser
// sends the _klb cookie with it. The code is the part before the first dot.
// (req.cookies: Express with cookie-parser. Next.js: (await cookies()).get('_klb')?.value)
const code = req.cookies._klb?.split('.')[0] || undefined An API on another origin does not get the cookie, and that includes api.example.com called from example.com. The browser leaves cookies off a cross-origin fetch unless it is made with credentials: 'include' and the API answers with Access-Control-Allow-Credentials, and a subdomain only sees the cookie once data-cookie-domain shares it. Sending the code in the request body avoids all of that.
The browser API
// The code attributed to this visitor, or null if there is none.
window.Klibon.referral() // "ada"
// The coupon to prefill at checkout for this visitor, or null: the affiliate's
// own code, else your program-wide coupon, and only for a referred visitor.
window.Klibon.coupon() // "LAUNCH20"
// After a visitor creates an account: ties their email to the affiliate who sent
// them. Returns false, and sends nothing, for a visitor who was not referred.
window.Klibon.signup('[email protected]') // true
// The program this snippet belongs to.
window.Klibon.program // "7c1f0f6e-…"Klibon.referral() and Klibon.coupon() read the cookie on every call, so they are always current. Both return null when the visitor was not referred, which is most of them — guard for it.
The code belongs to the visitor, not to your program: each one carries the code of the affiliate who sent them. Read it at the moment of checkout, every time. A code copied from your own console into your server would credit every sale to that one link.
Checking it works
- Open one of your own tracked links, then run
window.Klibon.referral()in the console. It should return that link's code; the test link on your Setup page gives one starting withtest. That is your browser's code, not a value to configure. - Look for
_klbin devtools → Application → Cookies. The value is the code, a dot, the timestamp of the click — and, when the affiliate has one, a dot and their coupon. - The address bar should no longer show
via, and should still show everything else it had. - Your program's Setup page reports that the script has been seen. That ping only fires when a referred visitor lands — ordinary page views are never reported to Klibon.
- Then prove the code travels on: through your test link, sign up, or buy something (a 100%-off code or a free trial is enough). The Setup page shows when the code reached Klibon and on what. Until it has, a draft program cannot be activated: a script that sets a cookie nobody reads credits no one.
If the script 404s, the response says why in a comment on the first line: a missing or unknown program id. An archived program still serves a valid file that simply does nothing, so an old snippet left on a site never throws in your visitors' consoles.
Cookies and consent
_klb is a first-party cookie set on your domain, by code running in your page. You are its controller. Declare it in your cookie notice — one entry, purpose "affiliate attribution", lifetime your cookie window — and gate the script behind consent if that is what your jurisdiction requires. It stores a referral code, a timestamp and at most a coupon code: no profile, no cross-site identifier, nothing an ad network could use.
What Klibon itself stores about a click is listed in our privacy policy. IP addresses and user agents are only ever kept as salted hashes.