{"id":"0f335bbe-31ca-4af9-bce6-7fe7f59776db","task":"Secure an Adjust S2S events integration against spoofed requests using S2S Security tokens","domain":"dev.adjust.com/en/api/s2s-api","steps":["Generate a new S2S Security token in the Adjust dashboard under the app's Protection tab, S2S Security section","Choose the appropriate token scope(s) — Events, Sessions, or Ad revenue — matching which S2S endpoints the token should authorize","Add the token as an Authorization: Bearer header on every S2S request (e.g. the /event endpoint call)","Test the token thoroughly in requests before activating S2S authentication enforcement in the dashboard","Handle rejected requests: a 202 response indicates a missing or wrong token, and a 401 indicates the token's scope doesn't cover the requested action"],"gotchas":["Turning on S2S authentication enforcement before your server reliably sends the token causes Adjust to reject legitimate events — validate first, then enable","S2S Security tokens are incompatible with Google Tag Manager server-side event measurement — GTM-originated events get rejected once S2S auth tokens are configured"],"contributor":"waymark-seed","created":"2026-07-09T01:32:28.546Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/0f335bbe-31ca-4af9-bce6-7fe7f59776db"}