generated: '2026-08-13' method: searched source: >- https://docs.firstpromoter.com/script-docs/fpr-js-docs, https://docs.firstpromoter.com/advanced/embed-dashboard-login, https://docs.firstpromoter.com/advanced/embed-dashboard-logout, https://docs.firstpromoter.com/guides/tracking-with-fprjs name: FirstPromoter client-side and embeddable components description: >- FirstPromoter's client-side surface is a single browser tracking library plus a fully hosted, embeddable promoter dashboard. There is no component library, no web components and no element primitives - the embed is an iframe of FirstPromoter's own UI, signed in with a short-lived token your backend mints. families: - name: Tracking script kind: browser library components: - name: fpr.js loader: '' bootstrap: 'fpr("init", {cid: ""}); fpr("click");' docs: https://docs.firstpromoter.com/script-docs/fpr-js-docs placement: HEAD of every marketing/public page, loaded async methods: - name: fpr("init", options, callback?) description: >- Initializes tracking. Options - cid (required company id), ref_id, tid, url, domain, referrer. Unknown keys are ignored. - name: fpr("click", payload?, callback?) description: Records the referred click; payload overrides stored values first. cookies: - name: _fprom_tid purpose: Visitor tracking id, the attribution key passed to the Tracking API as tid. - name: _fprom_ref purpose: Referral id of the promoter. - name: _fprom_track purpose: Legacy tracking cookie for accounts created before April 2021. note: >- Distribution is unpinned - the CDN URL carries no version. See packages/firstpromoter-packages.yml. - name: Embedded promoter dashboard kind: hosted iframe components: - name: Embedded dashboard with auto-login docs: https://docs.firstpromoter.com/advanced/embed-dashboard-login mechanism: >- Your backend POSTs the promoter's promoter_id or cust_id to the iframe login endpoint and receives a short-lived bearer token scoped to that promoter and account. The token is passed as the tk query parameter on the iframe src, and the dashboard loads signed in. endpoint: POST https://v2.firstpromoter.com/api/v2/promoters/iframe_login auth: Server-side only - Authorization Bearer API key plus ACCOUNT-ID. Never call from the browser. requirements: - A custom domain configured on the FirstPromoter account - Business plan or higher - Server-side API access - name: Embedded dashboard logout docs: https://docs.firstpromoter.com/advanced/embed-dashboard-logout mechanism: End a promoter's embedded session from your backend, or from inside the iframe. - name: Hosted promoter portal kind: hosted surface components: - name: Affiliate portal / promoter dashboard description: >- Brandable hosted dashboard with custom domains, custom CSS and JavaScript, custom signup fields and removable FirstPromoter branding (plan-dependent). docs: https://firstpromoter.com/pricing findings: - >- The iframe login endpoint is served from https://v2.firstpromoter.com - a fourth API host that appears in NO published OpenAPI document and is not the api.firstpromoter.com base every spec declares. An integrator following only the specs will never find it. - >- There is no npm-distributed component package. Everything client-side is a script tag or an iframe. component_count: 6