How TopWapi works
The complete mechanic: from account creation to a leaderboard position, including exactly how visitors are counted and how rank is calculated.
Six steps from account to leaderboard
Create your account
A username, a valid email address and a password. We validate the email structurally and reject disposable inboxes, because a platform where accounts cannot be contacted is a platform that fills with abuse. Passwords are hashed with PBKDF2-SHA256 at 120,000 iterations.
List one website
Title, URL, a 40–200 character short description and a category. Your listing goes live on the leaderboard immediately — there is no review queue. The domain must be unique across the platform, so nobody can list a site they do not control in a way that splits its click history.
Receive your promotional link
A unique, shareable URL is generated automatically at /p/your-code. Anyone who opens it sees a short recommendation panel for your website and a button through to your site. Each unique human who arrives earns you one credit.
Earn credits from unique visitors
We fingerprint the visitor with a hash of network and client signals plus a salt that rotates at UTC midnight. Only the hash is stored. A database uniqueness constraint rejects duplicates, so the same person cannot be counted twice in a day — whether they refresh, reopen or return from the same network.
Climb the leaderboard
Your score blends clicks in the last seven days (55%), thirty-day volume (15%), lifetime unique clicks (10%), promotional impressions (10%) and trust signals (10%). Recent activity dominates deliberately: a listing readers are clicking today should outrank a dormant one.
Measure everything
Your dashboard shows unique clicks, total clicks, seven and thirty-day volume, promotional impressions, bounce rate, top region, leaderboard rank, percentile and a day-by-day traffic report. No sampling, no estimation — these are the same rows the leaderboard is built from.
The counting rules, in full
Every other platform in this category is vague about counting, because being specific makes the limits visible. Here are ours in full.
What counts as a unique visitor
One request from one human to one destination, deduplicated within a UTC calendar day. Repeated requests from the same human to the same destination that day are counted once. The same human visiting tomorrow counts again, which is correct — a person who returns is a new visit.
How the fingerprint is produced
visitor_hash = sha256(
connecting_ip
+ user_agent
+ accept_language
+ utc_day // rotates at 00:00 UTC
+ platform_secret
).slice(0, 32)
The hash is truncated to 32 hex characters and stored. The raw IP is discarded inside the request handler. Because the day is part of the input, yesterday's hashes cannot be joined to today's, so the identifier is effectively single-use.
Why the constraint matters more than the code
The naive implementation is "look up whether this visitor exists, then insert if not". Between the lookup and the insert there is a window, and thirty parallel requests become thirty credits. Instead we rely on the database:
INSERT OR IGNORE INTO promo_visits
(promo_link_id, user_id, website_id,
visitor_hash, day, credited)
VALUES (?, ?, ?, ?, ?, 1)
-- meta.changes === 1 → this request earned the credit
-- meta.changes === 0 → duplicate, no credit awarded
Exactly one caller ever sees changes === 1, regardless of concurrency. No
transaction, no lock, no race.
Where the counting is imperfect, and why we accept that
| Case | Effect | Why we accept it |
|---|---|---|
| Shared corporate or campus network | Undercounts on busy days | The daily rotation bounds the error to a single day, and overcounting is worse |
| Mobile carrier address rotation | Occasional double count | The effort to trigger this exceeds the value of a credit |
| Privacy browser with no referrer | Counted normally | We never relied on cookies or referrers for identity |
| Distributed automation on residential proxies | Can defeat counting | Cannot be solved by counting; solved economically by keeping credit value low |
What a credit is worth
A credit represents one delivered human. It is not a currency you can cash out, and it is deliberately not worth enough to farm profitably: the cost of a residential proxy request is roughly an order of magnitude above the attention value of a credit. That ratio is the actual anti-abuse mechanism.
What we do not do
- We do not store IP addresses or set tracking cookies.
- We do not run third-party advertising or analytics scripts.
- We do not count page refreshes, prefetches, or bot traffic as visitors.
- We do not sell placement, and no amount of money changes a rank.