# AppLovin > AppLovin is a marketing platform for mobile advertising, ad mediation, and analytics. Its > public HTTP surface is split across four independent products with four different hosts, > four different key types, and four different authentication styles: MAX Ad Unit Management > (mediation configuration), Axon Campaign Management (advertiser campaigns and creatives), > the Reporting family (revenue, growth, asset, cohort, web, user-level), and the Conversion > API (server-side web event ingestion). AppLovin publishes no OpenAPI, no llms.txt, no MCP > server and no /.well-known/ discovery documents; the specifications linked below were > harvested from the published documentation by API Evangelist. Generated by the API Evangelist enrichment pipeline on 2026-08-13. AppLovin serves no llms.txt of its own — probed https://www.applovin.com/llms.txt, https://axon.ai/llms.txt, https://developers.applovin.com/llms.txt and https://support.applovin.com/llms.txt; all four return HTTP 200 with the site's HTML shell (a Next.js catch-all route), not a document. ## APIs - [MAX Ad Unit Management API](https://support.applovin.com/en/max/advanced-features/ad-unit-management-api): View and manage MAX ad units, waterfalls, A/B experiments, and test devices. Base https://o.applovin.com/mediation/v1. Auth: `Api-Key` header carrying the account Management Key. Rate limit 2,000 requests/hour. - [Axon Campaign Management API](https://support.applovin.com/en/app-discovery/api/axon-campaign-management-api/): Create and update campaigns and creative sets, upload creative assets. Base https://api.ads.axon.ai/manage/v1. Auth: `Authorization` header carrying the Campaign Management API key, plus a required `account_id` query parameter. Rate limit 1,000 requests/60 seconds. - [MAX Revenue Reporting API](https://support.applovin.com/en/max/reporting-apis/revenue-reporting-api): Aggregated MAX mediation revenue. GET https://r.applovin.com/maxReport. Auth: `api_key` query parameter carrying the Report Key. 45-day request window. - [Growth Reporting API](https://support.applovin.com/en/growth/promoting-your-apps/api/reporting-api): Aggregated advertiser or publisher campaign performance. GET https://r.applovin.com/report. 45-day request window. - [Asset Reporting API](https://support.applovin.com/en/growth/promoting-your-apps/api/asset-reporting-api): Asset-level campaign performance. GET https://r.applovin.com/assetReport (fixed ranges) and https://r.applovin.com/assetAnalyticsReport (date ranges). - [Web Reporting API](https://support.applovin.com/en/growth/promoting-your-websites/api/web-reporting-api): Web campaign performance with a selectable attribution mode. GET https://r.applovin.com/webReport. 90-day request window. - [Cohort API](https://support.applovin.com/en/max/reporting-apis/cohort-api): Install-cohorted revenue, impressions, and sessions. GET https://r.applovin.com/maxCohort, /maxCohort/imp, /maxCohort/session. - [User-Level Ad Revenue API](https://support.applovin.com/en/max/reporting-apis/user-level-ad-revenue-api): Per-user or per-impression revenue. GET https://r.applovin.com/max/userAdRevenueReport. Returns a presigned S3 URL, not the rows. - [Conversion API for lead gen](https://support.applovin.com/en/growth/promoting-your-websites/api/conversion-api-for-lead-gen): Submit `page_view` and `generate_lead` web events. POST https://b.applovin.com/v1/event. Auth: `Authorization` header carrying the Conversion API key, plus a `pixel_id` query parameter. Batches of up to 100 events; a `dedupe_id` per event de-duplicates against the browser pixel. - [Ad Review Rules Management API](https://support.applovin.com/en/max/ad-review/rules-management-api): Bulk create and read competitor and risky-content rules. Base https://api-safedk.applovin.com/v1/rules. Auth: `Api-Key` header carrying the Ad Review Key. - [S2S impression revenue API](https://support.applovin.com/en/max/advanced-features/s2s-impression-level-api): Outbound. AppLovin GETs a postback URL you define on every MAX impression. Enabled by the account team, not self-serve. - [S2S rewarded callback](https://support.applovin.com/en/max/faq/how-server-to-server-callback-works): Outbound. AppLovin GETs a callback URL you configure when a user completes a rewarded ad, signed with `sha1(EVENT_ID + EVENT_KEY)`. ## Specs These OpenAPI 3.0.3 documents were written by API Evangelist from AppLovin's published documentation. AppLovin publishes none of its own. - [Ad Units](https://raw.githubusercontent.com/api-evangelist/applovin/main/openapi/applovin-ad-units-api-openapi.yml) - [Waterfalls](https://raw.githubusercontent.com/api-evangelist/applovin/main/openapi/applovin-waterfalls-api-openapi.yml) - [Experiments](https://raw.githubusercontent.com/api-evangelist/applovin/main/openapi/applovin-experiments-api-openapi.yml) - [Test Devices](https://raw.githubusercontent.com/api-evangelist/applovin/main/openapi/applovin-test-devices-api-openapi.yml) - [Campaigns](https://raw.githubusercontent.com/api-evangelist/applovin/main/openapi/applovin-campaigns-api-openapi.yml) - [Creative Sets](https://raw.githubusercontent.com/api-evangelist/applovin/main/openapi/applovin-creative-sets-api-openapi.yml) - [Assets](https://raw.githubusercontent.com/api-evangelist/applovin/main/openapi/applovin-assets-api-openapi.yml) - [Revenue Reporting](https://raw.githubusercontent.com/api-evangelist/applovin/main/openapi/applovin-revenue-reporting-api-openapi.yml) - [Growth Reporting](https://raw.githubusercontent.com/api-evangelist/applovin/main/openapi/applovin-growth-reporting-api-openapi.yml) - [Asset Reporting](https://raw.githubusercontent.com/api-evangelist/applovin/main/openapi/applovin-asset-reporting-api-openapi.yml) - [Conversion Events](https://raw.githubusercontent.com/api-evangelist/applovin/main/openapi/applovin-conversion-events-api-openapi.yml) ## Artifacts - [Authentication profile](https://raw.githubusercontent.com/api-evangelist/applovin/main/authentication/applovin-authentication.yml) - [API conventions](https://raw.githubusercontent.com/api-evangelist/applovin/main/conventions/applovin-conventions.yml) - [Error catalog](https://raw.githubusercontent.com/api-evangelist/applovin/main/errors/applovin-problem-types.yml) - [Rate limits](https://raw.githubusercontent.com/api-evangelist/applovin/main/rate-limits/applovin-rate-limits.yml) - [Webhook / postback catalog](https://raw.githubusercontent.com/api-evangelist/applovin/main/asyncapi/applovin-webhooks.yml) - [Lifecycle](https://raw.githubusercontent.com/api-evangelist/applovin/main/lifecycle/applovin-lifecycle.yml) - [Data model](https://raw.githubusercontent.com/api-evangelist/applovin/main/data-model/applovin-data-model.yml) - [Packages / SDKs](https://raw.githubusercontent.com/api-evangelist/applovin/main/packages/applovin-packages.yml) - [Sandbox / test mode](https://raw.githubusercontent.com/api-evangelist/applovin/main/sandbox/applovin-sandbox.yml) - [Agent skills](https://raw.githubusercontent.com/api-evangelist/applovin/main/skills/_index.yml) ## Docs - [Support Center](https://support.applovin.com) — the canonical documentation host. support.axon.ai 302s here. - [Developer portal](https://developers.applovin.com) - [Blog](https://www.applovin.com/blog/) - [Terms of use](https://www.applovin.com/legal/) - [Privacy](https://www.applovin.com/privacy/) - [GitHub organization](https://github.com/AppLovin) ## Notes for agents - There is no single AppLovin API key. Five distinct credentials exist, all issued in the dashboard under Account > General > Keys: SDK Key, Management Key, Report Key, Campaign Management API key, Conversion API key / Event Key, and Ad Review Key. They are not interchangeable and each is scoped to one product. - There is no OAuth, no scopes, and no token endpoint anywhere in the surface. - All keys are long-lived and account-wide. There is no per-agent credential, no expiry, and no revocation surface exposed over the API. - Reporting is windowed: 45 days for the MAX, growth, asset, cohort and user-level reports; 90 days for web reporting. A request outside the window fails rather than truncating. - The Campaign Management API blocks an account for 24 hours after 100 error responses in a five-minute window (`x-al-error-code: 100007`). Retry loops on 4xx are actively dangerous here — back off on the first error, do not retry a 400.