?mref=<handle>, and this page covers the capture half: reading that code off your landing page and parking it where the install can find it.
Referral attribution covers what Meridian does with it afterwards.
Capture on your landing page
CallcaptureReferral in the loader of the page tracked links land on, and put the returned cookies on the response:
?mref= (or ?ref=) off the URL, and when Shopify also put ?shop= there it hands the pairing to Meridian’s server-side stash. Nothing here throws, so it is safe to await on a page whose only job is to render.
utm_source is not an alias: it names a marketing channel rather than an affiliate.
A redirect route is enough
A route that captures and immediately redirects keeps the affiliate’s link pointing at the App Store listing:https://your-app.com/go, and affiliates share …/go?mref=<handle>. The merchant sees one instant hop, and the cookie is set first-party on your own domain, where it survives best.
What the result tells you
Prefer
setCookies. setCookie and headers predate the click timestamp and carry the code alone, so a response built from them loses the click date, and with it the tight commission window.
Consent
The capture stores two first-party cookies on your own domain for 30 days: the affiliate’s handle, and when the link was clicked. They carry no visitor identifier and support no cross-site tracking. They are still cookies a consent banner may have to gate. Pass your banner’s verdict through and nothing is written to the browser:cookieSkipped: true with stashed: false attributed nothing: there was no shop context and no cookie.
Deleting an affiliate’s data is a Meridian-side operation. The SDK holds no state beyond these two cookies.
Wiring the pieces yourself
Every helper is exported and framework-agnostic: they work on the standardURL, Request and Headers, and none of them throws:
MERIDIAN_REFERRAL_COOKIE, MERIDIAN_REFERRAL_CLICKED_AT_COOKIE and REFERRAL_TTL_SECONDS are exported too. The cookies must be SameSite=None; Secure: the embedded app is framed by admin.shopify.com, a cross-site context where a Lax cookie is never sent.