Settings

Settings (/settings) covers system parameters, access, tracker options, integrations, and operations. Tabs open as /settings?tab=<id>. This is a how-to by group and task.

Settings
Settings group navigation.
General
General tab: currency, timezone, limits.
Track Paths
Public tracking path aliases.
IP Lists
IP/CIDR blacklist and whitelist.

How to open

  1. Header user menu → Settings or /settings.
  2. Pick a tab in settings navigation or use a direct tab= link.

Tab groups

GroupTabs (tab=)
Generalgeneral
Accessaccounts, users, api-tokens, security, audit, action-secrets, ip-lists
Trackertrack-paths, webhook, postback-mapping, conversion-catalog, markers, geo2ip, geo-profiles, fraud-score
Integrationsgoogle-sheets, cloudflare, ai-api, proxy, notifications, scheduled-reports, virustotal
Opsbackup, archive, tracker-import, licensing, updates, self-healing

Typical tasks

  1. Change currency/timezone: General → save → re-check Reports/Logs periods.
  2. Invite a teammate: Access → Users → create user (password ≥ 12 chars), role (admin, account_owner, manager, analyst, viewer), page permissions.
  3. API for scripts: Access → API Tokens → create token with minimal RBAC → see API section.
  4. IP blacklist: Access → IP Lists → Blacklist CIDR; Whitelist for test IPs.
  5. Tracking script paths: Tracker → Track Paths — change public aliases carefully and update site embeds.
  6. Fraud: Tracker → Fraud Score (threshold, weights, datacenter, auto-blacklist, DDoS).
  7. Postback mapping / conversion catalog: when a network sends non-standard names.
  8. Notifications and scheduled reports: Integrations → Notifications / Scheduled Reports.
  9. AI Insights chat: Integrations → AI API.
  10. Keitaro/Binom migration: Ops → Tracker Import (not a sidebar item).
  11. OTA: header badge → Ops → Updates. A container restart while the license gateway is unreachable is downtime (the decryption key is not cached). Details: self-hosted vs cloud.

Tab purposes (short)

general — currency, timezone, click/track rate limit UI. accounts/users — multi-tenant RBAC. security/audit/action-secrets — security, audit log, HMAC secrets. webhook — outbound event webhooks. geo2ip / geo-profiles — GeoIP bundle and geo presets. markers — markers on Reports charts. google-sheets / cloudflare / proxy / virustotal — integrations. backup / archive / licensing / self-healing — S3 backup, ClickHouse archive, license, diagnostics.

Practice by group

Before changing timezone/currency in General, warn the team: Reports/Logs periods and Daily Costs day boundaries shift. Create API Tokens per job (BI / CRM), not one shared admin token. Change Track Paths only together with snippet updates on every landing. Ops → Tracker Import and Updates are admin operations: dry-run and backup awareness matter more than click speed.

Common mistakes

  • Changing track-paths without updating snippets on landings.
  • Looking for Tracker Import in the sidebar — it lives under Settings → Ops only.
  • Granting admin for speed instead of analyst/viewer with needed pages.
  • Changing Fraud Score in production without checking Suspicious in Logs on small traffic first.
  • Changing timezone then comparing yesterday in Insights/Reports without revisiting the period.