Install attribution for command-line tools

Know where your installs come from.

Advertise on social and search, and let Google Ads, Meta, TikTok and X optimise for the install itself.1

Who runs it
acme.example/install01 Visit

Install acme

Version 2.4.0 for macOS and Linux.

ShellCopycurl -fsSL acme.example/install.sh | sh

A developer copies your command

Terminal02 Install
$ curl -fsSL acme.example/install.sh | sh
==> Downloading acme 2.4.0 (darwin-arm64)
==> Verifying checksum
✓ Installed acme 2.4.0 to /usr/local/bin
clitrail: linking this install to your recent visit to https://acme.example (DO_NOT_TRACK=1 turns this off) — https://clitrail.com/installer
$ 

The hook finds the visit receipt on this computer

Install events03 Attributed

Install completed just now

Channel
Google Ads
Campaign
sept-launch
Page
/install
Journey
3 visits · 9 days
Method
Receipt
  • Google Adssubmitted
  • GA4submitted

01Outcomes

Ads that learn from installs, not clicks.

Install conversions sent
  • Google Adsgclid → click conversion
    submitted
  • Metafbc, fbp → CLIInstall
    submitted
  • TikTokttclid → Download
    submitted
  • X Adstwclid → pixel event
    submitted

Campaigns that optimise for installs

Each matched install goes back as a conversion their bidding can optimise for.

Installs by channel · 30 days
ChannelVisitsInstalls
Google Ads1,240186
Developer communities910164
Organic search2,380143
Meta Ads1,02041

Installs by channel and campaign

Each attributed install carries its channel, campaign, landing page and referrer.

One install, three visits
  1. −9 dSocialFirst touchnews.ycombinator.com → /blog/launch
  2. −4 dOrganic searchgoogle.com → /docs
  3. −12 minGoogle AdsLast touchsept-launch → /install
  4. 0Install completedfirst_run follows on first launch

The whole path to install

Every visit before the install, oldest first, with first and last touch.

02Benefits

Nothing for developers to work around.

  • Clean links

    Install commands, docs and ad URLs stay exactly as they are.

  • Private by default

    Off under DO_NOT_TRACK or in CI. Honours GPC. Stores no raw IPs.

  • No runtime to install

    One POSIX shell script. No binary, no Node, no Python.

  • Every install path

    Shell, npm, npx, Homebrew and Python: report the install or first run.

  • Reconstruction on paid plans

    No receipt? A probable match from network, time and device signals.

  • Organisations and roles

    Google or email-link sign-in. Invite teammates as owner, admin, member or viewer.

Destinations

  • GA4Available
  • Google AdsAvailable
  • MetaAvailable
  • TikTokAvailable
  • X AdsAvailable
  • WebhooksAvailable

03Specs

The spec sheet.

Built for the browsers behind up to about 6 in 10 desktop visits from developers.2

What works where
Website SDK
browser.js · 18.0 KB, 6.6 KB gzipped · no dependencies · no cookiesHow to add the website tag
Installer hook
report.sh · 29.8 KB of POSIX sh · curl or GNU wget · always exits 0How the installer hook works
Install paths
shell · npm · npx · Homebrew · Python · single binariesHow to call the hook on each install path
Events
install_started · install_completed · first_run · each once per installationHow to report first-run events
Opt-outs
DO_NOT_TRACK=1 · CLITRAIL_DISABLE=1 · CI · Global Privacy ControlHow opt-outs work
Supported environments
macOS, Linux: Supported in Chrome, Firefox, Edge, Brave, Vivaldi, Chromium (on Linux also Zen and the Snap and Flatpak builds) · Safari: Via handoff · Windows: Via handoff, from WSL · other devices: Probable (paid plans)How to get attribution in each browser
Destinations
GA4 mp/collect · Data Manager v1/events:ingest · Meta Graph v26.0 · TikTok Events v1.3 · X Ads API 12 · Standard WebhooksHow to set up each destination
Delivery
stable event IDs · backoff from 1 min to 24 h · Meta, TikTok and X retried only within 48 hHow retries and time limits work
Security
AES-256-GCM · separate vault store · write-only credentials, only over https · key rotation without downtime · sessions and receipts hashedHow secrets are stored
Privacy
no raw IPs · receipts expire after 30 days · data kept 395 days by defaultHow retention and deletion work
Accounts
Google or email-link sign-in · owner, admin, member, viewer · single-use invites, valid 7 daysHow organisations and roles work
Logs
exact bodies, credentials redacted · 7, 30 or 90 days by plan · S3 or webhook streams on EnterpriseHow logs and telemetry work
Limits
16 KB request bodies · 1,200 events a minute per website · 30 a minute and 500 a day per clientHow limits apply
Hosting
Cloudflare Workers · SQLite Durable Object · secrets in a second, separate Durable ObjectHow the secret store is kept apart

04Pricing

Count installs free. Pay to attribute them.

Free

$0forever

Visits and installs, side by side.

Start free
  • Install-page visits against reported installs
  • Browser, OS and device distributions
  • Logs of every request CLItrail receives
  • No attribution and no destinations: installs are counted, never matched
Install paths
1
Websites
1
Domains per website
5
Members
1
Destinations per website
Not included
Log streams
Not included
Log retention
7 days
Tracked events a month
10,000

Standard Attribution starts here

$99per month

Attribution and ad conversions for one install path.

Choose Standard
  • Everything in Free
  • Installs by channel, campaign, page and referrer
  • Journeys with first and last touch
  • Reconstruction, and Safari or External reasons
  • GA4, Google Ads, Meta, TikTok, X Ads and webhooks
  • CSV export with attribution
Install paths
1
Websites
3
Domains per website
10
Members
3
Destinations per website
10
Log streams
Not included
Log retention
Up to 30 days
Tracked events a month
1,000,000

Enterprise

$499per month

Standard, for up to 10 install paths.

Choose Enterprise
  • Everything in Standard
  • Up to 10 install paths, each with its own hook
  • Log streams to Amazon S3, S3-compatible storage or a webhook
  • More websites, members and destinations
Install paths
10
Websites
25
Domains per website
25
Members
20
Destinations per website
20
Log streams
10
Log retention
Up to 90 days
Tracked events a month
10,000,000

Billed monthly through Stripe. Cancel anytime. Attribution starts with installs reported after an upgrade.

Plans and limits

Start with one website

Find out which clicks become installs.