# GHAN > GHAN is an audited cross-promotion and paid-install network for macOS and Windows desktop applications. Member apps promote each other inside templated in-app lifecycle slots and settle through a single append-only credit ledger. Every install is attributed by a single-use, expiring, cryptographically signed token — never by fingerprinting — and money only clears after the referred install is still in use 48 hours later. GHAN is MCP-first: a founder's coding agent can discover the network, register an app, read its own score with machine-readable rejection reasons, run campaigns and pull the raw signed ledger without ever opening the dashboard. The positioning claim the whole product is built to satisfy is "your agent can audit us" — every number GHAN publishes is reproducible from signed data a partner already holds. Last updated: 2026-09-22 ## Key facts - Desktop only: macOS (DMG) and Windows (EXE). No mobile, no web. - Placements are in-app lifecycle slots — install complete, first success, update, idle, uninstall intent. Never inside an installer, which is the mistake that killed the previous generation of desktop bundling networks. - Creatives are templated: partner icon, partner name, one generated line, rendered by GHAN's own SDK. Partners cannot ship custom HTML or images into another app. - Attribution is deterministic only: ed25519-signed, single-use tokens that expire 15 minutes after issue. No device fingerprinting and no probabilistic matching, ever. - Every monetised event carries two independent signatures, one from the serving app and one from the receiving app. A chain cannot advance past install_claim with only one. - Payout clears on behaviour, not on events: a standard install clears after 48 hours of retention, and any pair trading above EUR 500 per day clears on day-7 engagement instead. - Rate card per cleared install is a published FLOOR, not a ceiling: utilities and consumer EUR 12-18, creator tools EUR 20-30, prosumer and B2B EUR 35-50. The floor never rises and any approved advertiser can always buy at it. - Above the floor there is an optional second-price auction for priority in contested inventory. You pay one cent above the next-highest competing bid, never your own maximum, and 30 percent of every category is reserved at floor and never auctioned. You bid per cleared install, not per click. - Nine security layers sit between a member app and a bad install: the gate, the placement constraints, attribution, device signals, economics, behaviour, enforcement, data, and disclosure. - GHAN keeps 30 percent. The serving app earns 70 percent of the CPI, multiplied by 1.2 when taken as network credits instead of cash. - The ledger is append-only at the database level: UPDATE, DELETE and TRUNCATE are blocked by trigger, and every line is retrievable over MCP with its event-chain reference. - Vetting gate before any app can trade: notarisation or Authenticode signature, a clean VirusTotal result, domain age of at least six months, a verified contact email, and a download URL that actually serves the declared bundle id. ## Start here - [Bidding above the floor](https://ghan.io/bidding/): GHAN's rate card is a guaranteed floor, not a ceiling. Above it, advertisers bid for priority in contested inventory — second price, on cleared installs, with a tranche reserved at floor. - [GHAN for advertisers buying desktop installs](https://ghan.io/for-advertisers/): Buy desktop installs at a fixed published price, pay only for installs that survive 48 hours, and audit every charge against a signed chain. - [GHAN for desktop app developers](https://ghan.io/for-developers/): How a macOS or Windows app earns acquisition budget by serving templated partner cards: what you integrate, control, and earn. - [Get started with GHAN](https://ghan.io/get-started/): The path from nothing to a registered, scored, integrated desktop app on GHAN — for a human in about ten minutes, or for a coding agent in one tool sequence. - [Desktop cross-promotion networks — a complete guide](https://ghan.io/guides/desktop-cross-promotion-network/): What a desktop cross-promotion network is, integration for Tauri, Electron, Windows and macOS, eligibility, and the full install flow. - [GHAN guides](https://ghan.io/guides/): Practical guides to desktop application distribution: what a cross-promotion network is, and how to integrate one on every platform. - [How GHAN works](https://ghan.io/how-it-works/): The full path an install takes through GHAN, from a templated slot rendering to a double-signed ledger line clearing 48 hours later. - [The audited cross-promotion network for desktop apps](https://ghan.io/): GHAN lets macOS and Windows desktop apps promote each other and settle in one signed, append-only ledger. Fixed EUR 12-50 per cleared install. - [GHAN pricing and rate card](https://ghan.io/pricing/): GHAN's rate card is a guaranteed floor: EUR 12-18 utilities, EUR 20-30 creator tools, EUR 35-50 B2B per cleared install, with optional bidding above it. ## The referee - [Deterministic attribution, and why GHAN refuses fingerprinting](https://ghan.io/attribution/): How GHAN attributes an install with a single-use ed25519 token that expires in 15 minutes, and why fingerprinting is banned outright. - [How GHAN prevents install fraud](https://ghan.io/fraud-prevention/): The eight fraud rules GHAN runs continuously, from click-to-install-time histograms to pair collusion caps, and the auto-action ladder. - [The five GHAN lifecycle slots](https://ghan.io/lifecycle-slots/): install_complete, first_success, update, idle and uninstall_intent: what each GHAN slot is, and why nothing is placed inside an installer. - [The Eight Commandments](https://ghan.io/manifesto/): The eight rules GHAN plays by and the previous generation of desktop install networks broke — know thy buyer, never be priced out, pay only for the real, and five more. - [Desktop install safety and fraud — GHAN's standard](https://ghan.io/research/desktop-install-network-safety-and-fraud/): Is bundling other apps in your installer safe? A direct answer, plus the definition of a cleared install and every rejection condition. - [The nine security layers](https://ghan.io/security/): Every layer between a partner app and a bad install on GHAN — the gate, the placement constraints, attribution, device signals, economics, behaviour, enforcement, data and disclosure. - [GHAN transparency report](https://ghan.io/transparency/): What GHAN publishes about itself, and the MCP tools that let anyone recompute those numbers from signed data without GHAN’s cooperation. - [How GHAN vets and scores apps](https://ghan.io/vetting/): The three scoring layers every GHAN member passes: an automated gate, a 0-100 reputation score, and a behaviour score after 500 installs. ## For agents - [GHAN REST API](https://ghan.io/docs/api/): The HTTP surface behind the GHAN MCP server — authentication, the x402 machine-payment path on top_up, webhooks, error codes and the published OpenAPI document. - [GHAN documentation](https://ghan.io/docs/): Everything an agent or a human needs to integrate GHAN: the MCP server, the desktop SDK, the REST API, and the machine-readable resources. - [The GHAN MCP server](https://ghan.io/docs/mcp/): Every GHAN MCP tool: register_app, get_score, create_campaign, get_ledger, get_stats, top_up and request_payout, with the auth model. - [GHAN SDK quickstart](https://ghan.io/docs/sdk/): Install @ghan/sdk in an Electron, Tauri or Node app: init, consent, the five lifecycle slots, exclusions, caps and the kill switch. ## Compare - [Onboarding built for the agent, not the buyer](https://ghan.io/blog/agent-first-saas-onboarding/): What MCP-first means in practice: tools before dashboards, rejection reasons as codes, and the two moments that should stay human. - [Desktop distribution is broken, and the auction is why](https://ghan.io/blog/desktop-distribution-is-broken/): Desktop apps cannot buy their own users because auctions price clicks by the highest-lifetime-value bidder. The arithmetic, and what works instead. - [Writing about desktop app distribution](https://ghan.io/blog/): Essays on how desktop software gets distributed: why the install bundling networks died, and why the search auction fails one-time licences. - [Every install network dies the same way](https://ghan.io/blog/why-install-networks-die/): OpenCandy, ironSource installcore and AdDuplex failed through three identifiable mechanisms. What each one was, and why removing them is costly. - [GHAN vs. affiliate networks for desktop software](https://ghan.io/compare/affiliate-networks/): Affiliates are paid on a sale, cross-promotion on a retained install. How commission rates, cookie attribution, discounting and fraud differ, and when each one is right. - [GHAN vs. CrossPromo](https://ghan.io/compare/crosspromo/): CrossPromo is a free barter network for App Store apps. GHAN is a paid network for apps distributed outside the stores. Which one fits, and why both can be right. - [GHAN vs. Google Ads for desktop app installs](https://ghan.io/compare/google-ads/): Why the search auction breaks down for one-time-licence desktop software, and how fixed-rate cross-promotion changes the arithmetic. - [GHAN compared to the alternatives](https://ghan.io/compare/): How GHAN compares to Google Ads, ironSource installcore, AdDuplex, Setapp and affiliate networks for acquiring desktop app users. - [GHAN vs. ironSource installcore and OpenCandy](https://ghan.io/compare/ironsource/): What the 2010s desktop bundling networks did, the mechanisms that got them flagged as malware, and the decisions GHAN made in response. - [Mac app distribution platforms compared](https://ghan.io/compare/mac-app-distribution-platforms/): Setapp alternatives and every realistic way to distribute a Mac app, compared on fees, audience, customer ownership and best fit. - [GHAN vs. Setapp and curated app bundles](https://ghan.io/compare/setapp/): How curated subscription bundles differ from a cross-promotion network: who owns the customer, revenue share versus a fixed CPI. ## Reference - [GHAN frequently asked questions](https://ghan.io/faq/): Direct answers about GHAN: what it is, whether it is bundleware, how attribution works, what it costs, and how a partner verifies the numbers. - [Desktop app distribution glossary](https://ghan.io/glossary/): Definitions for desktop user acquisition: cleared install, CTIT, deterministic attribution, event chain, escrow hold, pair cap and more. - [Desktop software CPI benchmarks and rates](https://ghan.io/reports/desktop-software-cpi-benchmarks/): What cost per install means for desktop software, GHAN’s published per-category rates for macOS and Windows, and a worked calculation. - [GHAN reports](https://ghan.io/reports/): Dated, reproducible reports from GHAN — desktop software CPI benchmarks, network clearing rates, and the monthly public fraud report. - [GHAN research](https://ghan.io/research/): Original research and written standards from GHAN on desktop install safety, install fraud prevention, and the cost of acquiring desktop application users. ## Company - [About GHAN](https://ghan.io/about/): Who builds GHAN, why a desktop install network needs a referee rather than a marketplace, and the seven principles the product is constrained by. - [GHAN changelog](https://ghan.io/changelog/): Dated record of what shipped in the GHAN network, with links to the pages each change affects. Also available as an RSS feed. - [Contact GHAN](https://ghan.io/contact/): How to reach GHAN for founding partnerships, security disclosure and press, and the machine-readable paths an agent should use instead. - [GHAN data processing agreement](https://ghan.io/dpa/): GDPR processing terms between a GHAN member app as controller and GHAN as processor: data categories, subprocessors, transfers, breach duties. - [GHAN privacy policy](https://ghan.io/privacy/): What GHAN processes, why, on what legal basis, how long it is retained, who it is shared with, and the rights available to end users of member applications. - [GHAN network status](https://ghan.io/status/): What is built, what is in progress and what has not started — the honest state of the GHAN network, with no invented install counts or network statistics. - [GHAN terms of service](https://ghan.io/terms/): The terms governing GHAN membership: eligibility, the vetting gate, placement rules, billing, fraud enforcement, payouts and termination. ## Machine interfaces - [OpenAPI document](https://ghan.io/openapi.json): the public GHAN REST API. - [AI catalog](https://ghan.io/.well-known/ai-catalog.json): every machine-readable resource GHAN publishes. - [MCP server card](https://ghan.io/mcp/server-card.json): tools, transport and auth for the GHAN MCP server. - [A2A agent card](https://ghan.io/.well-known/agent-card.json): agent-to-agent description of the network. - [Agent skills index](https://ghan.io/.well-known/agent-skills/index.json): the tasks an agent can complete on GHAN. - [llms-full.txt](https://ghan.io/llms-full.txt): the full text of every page on this site in one file. - [RSS feed](https://ghan.io/feed.xml): changelog and blog entries, dated.