NetBack for developers
Two surfaces: a 1 KB pixel that proves the revenue AI sends you, and a public, read-only API + MCP so any agent can ask whether AI recommends a brand. No key required for the read APIs.
The pixel
One line in your site’s <head> on every page. ~1 KB, no dependencies, invisible to visitors. It records first-touch AI referrals and gives you a small JS API. Your data-key is on your workspace’s Connections page.
<script async src="https://app.netback.ai/nb.js" data-key="nb_pub_…"></script>Fire a conversion (deterministic revenue)
Call this at your purchase / signup success step. NetBack ties it to the AI visit that referred this visitor. value is in your major unit (dollars, not cents); email is SHA-256 hashed in the browser before it ever leaves the page.
nb.convert({ value: 49.00, currency: "USD", email: "buyer@acme.com" });Recover “dark” AI traffic
Many buyers ask ChatGPT, then type your name into Google — arriving with no referrer. Catch them with a “How did you hear about us?” answer at signup:
nb.survey({ answer: "ChatGPT" });Get the visitor id
const vid = nb.getVid(); // stable across your subdomains (brand.com ↔ app.brand.com)Events post to /api/collect as text/plain (no CORS preflight) via sendBeacon with a fetch fallback. The visitor id lives in a first-party cookie on your registrable domain plus localStorage.
Connect revenue
Three ways to prove AI-sourced revenue, fastest first — all managed from your workspace’s Connections page:
- Google Analytics (2 min, no code) — surfaces the AI revenue GA already attributes but hides in “Referral/Direct.” Instant, before the pixel has history.
- The pixel +
nb.convert()— deterministic, per-visitor, ongoing. - Stripe (read-only) — a restricted key with read access to Charges, Checkout Sessions and Customers. NetBack can never move money or see card details. Matches AI visits to real purchases.
Agent API — read-only, no key
Any agent or script can ask whether AI recommends a brand. Public, CORS-open, cached ~30 min. This is principle #5: humans get a UI, agents get a protocol.
curl "https://app.netback.ai/api/agent/visibility?domain=acme.com&category=CRM%20tools"Returns the latest scorecard for the domain:
{
"found": true,
"source": "netback",
"domain": "acme.com",
"brand": "Acme",
"category": "CRM tools",
"visibility": 42,
"grade": { "letter": "C", "label": "Getting seen" },
"recommendsInstead": ["HubSpot", "Salesforce", "..."],
"citedSources": [ { "domain": "g2.com", "count": 9 } ],
"moves": ["Get cited on g2.com", "..."],
"scannedAt": "2026-09-15T13:33:02.206Z"
}Not scanned yet returns { "found": false, ... }. A shared scan’s full scorecard JSON is at /api/scorecard/{id}, and an embeddable SVG badge at /api/badge/{id}.
These read endpoints need no key today. Authenticated / higher-limit programmatic access (API keys, in your workspace Settings) is rolling out with pilots.
MCP server
NetBack speaks MCP over HTTP (JSON-RPC 2.0), so any MCP client — Claude Code, Claude Desktop, your own agent — can call it as a tool. Add the server:
{
"mcpServers": {
"netback": { "type": "http", "url": "https://app.netback.ai/api/mcp" }
}
}It exposes one tool, ai_visibility(domain, optional category), returning the same scorecard as the Agent API. GET /api/mcp returns a discovery blurb; POST handles initialize / tools/list / tools/call. Read-only.
Crawl beacon (optional)
AI can’t cite what it can’t crawl. Drop one line in your edge middleware to report AI-bot crawls (GPTBot, ClaudeBot, PerplexityBot, Google-Extended…) to your workspace. Uses your public data-key.
// middleware.ts (Next.js / Vercel Edge) — pings only on known AI-bot UAs
export function middleware(req) {
const ua = req.headers.get("user-agent") || "";
if (/GPTBot|ClaudeBot|PerplexityBot|Google-Extended|Bytespider/i.test(ua)) {
fetch("https://app.netback.ai/api/crawl?k=nb_pub_…&ua=" +
encodeURIComponent(ua) + "&path=" + encodeURIComponent(new URL(req.url).pathname));
}
}Or skip the beacon entirely: the free scan’s crawlability check reads your robots.txt / llms.txt and tells you which AI bots are blocked — no code needed.