NetBackOpen the app →
Developers

NetBack for developers

Two surfaces: a 1 KB pixel that proves the revenue AI sends you, and a public, read-only API + MCP so any agent can ask whether AI recommends a brand. No key required for the read APIs.

01

The pixel

One line in your site’s <head> on every page. ~1 KB, no dependencies, invisible to visitors. It records first-touch AI referrals and gives you a small JS API. Your data-key is on your workspace’s Connections page.

<script async src="https://app.netback.ai/nb.js" data-key="nb_pub_…"></script>

Fire a conversion (deterministic revenue)

Call this at your purchase / signup success step. NetBack ties it to the AI visit that referred this visitor. value is in your major unit (dollars, not cents); email is SHA-256 hashed in the browser before it ever leaves the page.

nb.convert({ value: 49.00, currency: "USD", email: "buyer@acme.com" });

Recover “dark” AI traffic

Many buyers ask ChatGPT, then type your name into Google — arriving with no referrer. Catch them with a “How did you hear about us?” answer at signup:

nb.survey({ answer: "ChatGPT" });

Get the visitor id

const vid = nb.getVid();  // stable across your subdomains (brand.com ↔ app.brand.com)

Events post to /api/collect as text/plain (no CORS preflight) via sendBeacon with a fetch fallback. The visitor id lives in a first-party cookie on your registrable domain plus localStorage.

02

Connect revenue

Three ways to prove AI-sourced revenue, fastest first — all managed from your workspace’s Connections page:

  • Google Analytics (2 min, no code) — surfaces the AI revenue GA already attributes but hides in “Referral/Direct.” Instant, before the pixel has history.
  • The pixel + nb.convert() — deterministic, per-visitor, ongoing.
  • Stripe (read-only) — a restricted key with read access to Charges, Checkout Sessions and Customers. NetBack can never move money or see card details. Matches AI visits to real purchases.
03

Agent API — read-only, no key

Any agent or script can ask whether AI recommends a brand. Public, CORS-open, cached ~30 min. This is principle #5: humans get a UI, agents get a protocol.

curl "https://app.netback.ai/api/agent/visibility?domain=acme.com&category=CRM%20tools"

Returns the latest scorecard for the domain:

{
  "found": true,
  "source": "netback",
  "domain": "acme.com",
  "brand": "Acme",
  "category": "CRM tools",
  "visibility": 42,
  "grade": { "letter": "C", "label": "Getting seen" },
  "recommendsInstead": ["HubSpot", "Salesforce", "..."],
  "citedSources": [ { "domain": "g2.com", "count": 9 } ],
  "moves": ["Get cited on g2.com", "..."],
  "scannedAt": "2026-09-15T13:33:02.206Z"
}

Not scanned yet returns { "found": false, ... }. A shared scan’s full scorecard JSON is at /api/scorecard/{id}, and an embeddable SVG badge at /api/badge/{id}.

These read endpoints need no key today. Authenticated / higher-limit programmatic access (API keys, in your workspace Settings) is rolling out with pilots.

04

MCP server

NetBack speaks MCP over HTTP (JSON-RPC 2.0), so any MCP client — Claude Code, Claude Desktop, your own agent — can call it as a tool. Add the server:

{
  "mcpServers": {
    "netback": { "type": "http", "url": "https://app.netback.ai/api/mcp" }
  }
}

It exposes one tool, ai_visibility(domain, optional category), returning the same scorecard as the Agent API. GET /api/mcp returns a discovery blurb; POST handles initialize / tools/list / tools/call. Read-only.

05

Crawl beacon (optional)

AI can’t cite what it can’t crawl. Drop one line in your edge middleware to report AI-bot crawls (GPTBot, ClaudeBot, PerplexityBot, Google-Extended…) to your workspace. Uses your public data-key.

// middleware.ts (Next.js / Vercel Edge) — pings only on known AI-bot UAs
export function middleware(req) {
  const ua = req.headers.get("user-agent") || "";
  if (/GPTBot|ClaudeBot|PerplexityBot|Google-Extended|Bytespider/i.test(ua)) {
    fetch("https://app.netback.ai/api/crawl?k=nb_pub_…&ua=" +
      encodeURIComponent(ua) + "&path=" + encodeURIComponent(new URL(req.url).pathname));
  }
}

Or skip the beacon entirely: the free scan’s crawlability check reads your robots.txt / llms.txt and tells you which AI bots are blocked — no code needed.