# Tapad > Tapad is a cross-device digital identity company founded in 2010 in New York City, acquired by Telenor in 2016 and by Experian in 2020. Its product is the Tapad Graph, a probabilistic device graph used for programmatic targeting, media measurement, attribution and personalization. Tapad does not run a public developer program: there is no developer portal, no OpenAPI, no self-service signup and no published pricing. It does operate two live first-party HTTP endpoints, both requiring a partner id that only Tapad can issue. generated: 2026-08-12 method: generated source: apis.yml plus the artifacts in this repository (packages/, errors/, authentication/, conventions/, lifecycle/, conformance/, plans/, rate-limits/, well-known/, security/). Not published by Tapad — generated by API Evangelist from probed and first-party evidence. ## What an agent needs to know first - There is no OpenAPI, AsyncAPI, GraphQL SDL, Postman collection or JSON Schema for Tapad anywhere. Do not look for one; four hosts were probed at every conventional path on 2026-08-12 and all returned 404. - The API returns **HTTP 200 for errors**. Failure is signaled only by the presence of an `errors` key in the JSON body. Code that keys off status codes will read every Tapad failure as a success. - Access requires a `ta_partner_id` issued by Tapad through a partnership conversation. A syntactically valid but unprovisioned id is rejected identically to no id at all. - Tapad's product pages now redirect into Experian. The company's documentation host, `docs.tapad.com`, 301s to Experian's client-only Marketing Knowledge Base. ## APIs - [Tapestry Web API](https://tapestry.tapad.com/tapestry/1): Cross-device identity and audience API. GET-only, query-string encoded, JSON response. Reads and writes key/value data and audience tags against a resolved device clique. Live, 200, verified 2026-08-12. - [Event tracking beacon](https://analytics.tapad.com/app/event): App install and in-app event tracking. GET beacon, responds with a 1x1 PNG. Live, 200, verified 2026-08-12. ## Authentication - [Authentication profile](authentication/tapad-authentication.yml): `ta_partner_id` as a query parameter over TLS, plus a server-side referrer check. No OAuth, no OIDC, no bearer token, no Authorization header, no mTLS. ## Conventions - [API conventions](conventions/tapad-conventions.yml): all input in the query string under a `ta_` prefix; no request body; no pagination; no idempotency keys; no request-id or trace header; path-segment versioning frozen at `1` since 2013. ## Errors - [Error catalog](errors/tapad-problem-types.yml): nine documented types, encoded as `"|"` strings in an `errors` array. Not RFC 9457. Notable codes: `3|NoPartnerIdError`, `4|OptedOut`, `5|NoPermissions`, `7|CannotIdentifyDevice`, `8|ClientRequestError`. ## SDKs and packages - [Package inventory](packages/tapad-packages.yml): four first-party mobile SDKs — tapestry-ios-sdk, tapestry-android-sdk, tapad-ios-sdk, tapad-android-sdk — **all archived by Tapad as unmaintained**. Newest release is v1.3.1, 2014-03-12, twelve years older than the API it calls. Nine first-party Maven artifacts under `com.tapad*` are Scala build tooling, not API clients. Nothing on npm, PyPI, RubyGems, crates.io, NuGet or pkg.go.dev. ## Lifecycle - [Lifecycle](lifecycle/tapad-lifecycle.yml): no versioning policy, no deprecation policy, no Sunset/Deprecation headers, no SLA, no status page. Retired without announcement: `engineering.tapad.com` (dead), `swappit.tapad.com` (NXDOMAIN), `www.tapad.com/insights` (404), `docs.tapad.com` (absorbed into Experian). ## Commercial - [Plans and pricing](plans/tapad-plans-pricing.yml): zero published plans. Data-partnership sale only; no `/pricing` page exists. - [Rate limits](rate-limits/tapad-rate-limits.yml): zero published limits and no runtime rate-limit headers. ## Security and conformance - [Domain security](security/tapad-domain-security.yml): TLS 1.3, SPF and DMARC (quarantine) present; no HSTS on the marketing host, no DNSSEC, no CAA. - [Conformance](conformance/tapad-conformance.yml): no security.txt, no robots.txt, no vulnerability disclosure program, no trust center, no published certifications. Still emits a P3P header, a protocol W3C retired in 2018. - [Well-known probe](well-known/tapad-well-known.yml): every `/.well-known/` path on every host returned 404. ## Company - [Homepage](https://www.tapad.com) - [Global privacy notice](https://www.tapad.com/global-privacy-notice) - [GitHub organization](https://github.com/Tapad) — 29 public repositories, 28 of them archived as unmaintained - [Experian Consumer Sync](https://www.experian.com/marketing/consumer-sync) — where Tapad's product pages now redirect - [Client portal](https://crportal.tapad.com) — login only