Anatomy of a Coupon Code: How Codes Get Generated, Tested, and Killed
Trust & Transparency11 min read

Anatomy of a Coupon Code: How Codes Get Generated, Tested, and Killed

A working coupon code has a backstory. It came from somewhere — affiliate network, retention queue, influencer drop — and it'll die when its purpose is served.

M. Castellanos·March 25, 2026

The 15%-off code SARAH15 that an Instagram skincare influencer hands her audience is functionally a different object than the 20%-off code BLOOM20 that lands in your inbox an hour after you abandoned a Bloomingdale's cart, even though both look like a string of characters typed into the same checkout box. They were generated by different systems, tracked through different attribution channels, paid out through different settlement mechanisms, and intended for different audiences. Knowing which kind of code you're holding tells you whether it'll work, why it might fail, and whether the "expired" notice is real.

There's a small genre of coupon-site claims — "we have 47 codes for this store!" — that depends on readers not knowing the difference. Most of those codes are dead. A few of them are alive but restricted in ways the listing doesn't disclose. Knowing the anatomy of a code is how you sort the working ten percent from the noise.

Where codes actually come from

Almost every code in circulation falls into one of six origin categories. The category determines almost everything about how the code behaves.

Affiliate-network codes. The largest single category. Affiliate networks (CJ, Rakuten Advertising, Impact, Awin, ShareASale, Pepperjam) distribute promotional codes to publishers — coupon sites, content sites, deal forums — that earn a commission when a user clicks through and buys. The retailer creates a code in their commerce platform (Shopify, Salesforce Commerce Cloud, custom), tags it with an affiliate-network tracking parameter, and pushes it to the network's publisher feed. Publishers list it. Customers use it. Commission flows.

These codes are typically 10–25% off, valid for weeks or months, and apply to most non-excluded categories. They are the "background hum" of coupon-site listings and the most reliably working class of code. The trade-off: retailers know publishers are listing them, and they're never the deepest discount available.

Influencer / partnership codes. A code given to a single content creator (typically with their first name or handle in the code: SARAH15, JESSCOSMETICS, etc). Tied to a specific affiliate link, tracked through a specific commission rate (often higher than the network rate — 15–25% is common for partnership deals), and intended only for that influencer's audience.

The interesting feature: most influencer codes work for anyone who types them in. The retailer doesn't enforce the "only your audience" expectation at the code level — they trust the code distribution to be the gating factor. So a code that surfaces on a deal forum from an influencer drop will often work even though it was never intended for general-public use. It will also typically be killed faster than a network code if the retailer notices it leaking widely.

Retention codes. Generated by the retention or CRM team for a specific lifecycle moment — a first-purchase code in a welcome email, a winback code to a lapsed customer, a birthday code, a "we noticed you haven't bought in 90 days" code. These are usually one-time-use per account, often single-use period, and frequently keyed to the email address that received them.

The interesting feature: many retention codes are not technically locked to the email — the lock is on the code, used once, period. So a code shared from one account's welcome email to another user's account often works exactly once for whoever uses it first. After that the code is dead for everyone.

Cart-abandonment codes. A subspecies of retention. Triggered when a logged-in user (or a user with a tracked email) leaves items in cart for some threshold (commonly 24, 48, or 72 hours). The code lands by email or sometimes via on-site notification on the next visit. Almost always single-use per account, almost always with a value floor (the cart had to have been above $X), and almost always expires within 7 days.

Loyalty-program codes. Generated for members, distributed inside the loyalty app or member emails, tied to member status. These usually validate against the logged-in account, not just the code, so sharing them does nothing — the checkout system checks "is this user a Diamond-tier member" before accepting the code, and a non-member's checkout will reject it even with the right string.

Customer-service / make-good codes. Generated by an agent in response to a complaint or a return-related issue. Frequently have "CS" or "AGENT" prefixes. Almost always single-use, usually with a 30-day expiration. These leak into coupon listings occasionally; they almost never work for anyone but the original recipient because the customer-service backend ties them to a specific order or account.

Why some codes work for some people and not others

The number-one reason a code "doesn't work" when a coupon listing said it would is not that the listing is lying. It's that the code has eligibility constraints that aren't visible at the listing level. The major ones:

Geographic restriction. Many promotional codes are valid only for shipping addresses in a specific country, region, or state. Cross-border shoppers are most affected, but it's not uncommon for a U.S. retailer to run a state-targeted code (Texas-residents-only for a regional grand-opening, etc).

Customer-segment targeting. Codes can be tagged "first-purchase only" (rejects accounts with prior order history), "lapsed customer only" (rejects accounts with orders in the last X months), "member-tier-specific," or "category-buyer-only" (you've bought from category Y in the past). The checkout error message rarely tells you which one fired; it usually says "Code not eligible for your cart" or similar.

Single-use codes that have already been redeemed. A retention code tagged as single-use will validate the first time and reject every subsequent attempt. If a code surfaces on a deal forum at 11 a.m. and you try it at 3 p.m., it may have already been used by someone earlier in the day.

Cart-content restrictions. Excluded brands, excluded categories, sale-item exclusions, MAP-pricing exclusions, gift-card exclusions. Most codes have at least one of these, and the exclusion list is sometimes longer than the code description on the listing.

Minimum purchase requirements. Standard, well-disclosed at the listing level usually, but the most common mundane cause of a "code doesn't work" message.

Stacking conflicts. A loyalty-applied member discount on the cart can lock out a public code, or vice versa. The system is enforcing "one promotion per cart" and silently ignoring the second one.

How retailers detect coupon abuse

Three categories of abuse are common enough that retailers have built specific detections for them:

Code-stuffing browser extensions. Honey, Capital One Shopping, and similar tools rapid-fire test every code in their database against a cart. Retailers see this as a high-rate sequence of failed code applications from the same session. Some platforms now rate-limit code attempts (3–5 per cart, then a cooldown) to disrupt this. The user-visible effect is occasional checkout slowdowns and a few "please wait before trying another code" messages.

Account churn for first-purchase codes. Creating a fresh account with a new email to use a "new customer" code repeatedly. Retailers detect this through device fingerprinting, shipping-address matching, and payment-method matching (the same credit card on a "new" account is a strong signal). Most major retailers will accept the first or second instance and then start blocking the code on accounts that share signals with prior users.

Reseller code-pooling. Larger-scale abuse, mostly tied to gray-market reselling rather than personal shopping. Retailers detect these through cart-pattern analysis (high-quantity, high-frequency, single-SKU buying) and shut down both the codes and the accounts.

The honest read: most ordinary shoppers don't trigger any of these. The detections exist for the edge cases. The casual user typing one code into one cart is not on anyone's enforcement radar.

The lifecycle of a typical code

A representative timeline for a 20%-off site-wide code in a mid-size apparel retailer:

  • T-0 (creation). Marketing team generates the code in the commerce platform, sets a 30-day validity window, sets exclusions, sets a single-use-per-customer flag.
  • T+0. Code distributed to the affiliate network feed and to the retailer's own email list. Coupon sites pick it up within hours.
  • T+1 to T+7. Peak usage. Most legitimate redemptions happen here. The code's commission rate to publishers is at the standard tier.
  • T+8 to T+21. Long tail. Decay in usage as the email-list recipients have either redeemed or not. Coupon sites continue listing it. Some retailers de-index the code from the affiliate feed at this stage to discourage continued listing, but the code itself remains live.
  • T+22 to T+30. Quiet period. Code still works, traffic is mostly from coupon-site stragglers, attribution is fuzzier. Retailer may extend the code, may let it expire, may swap it for a successor (often the same percent-off with a new code string, which is a soft way to say "the old one was getting too widespread").
  • T+31. Code expires per the original schedule. Or it doesn't — many retailers leave a successful code live longer than its stated expiration, especially if it's still driving incremental sales.

The "expired" status on a coupon listing is, in practice, a guess. The listing site doesn't know whether the code's still live unless they test it, and many sites test on a delay. A code marked "expired" yesterday may still work today; a code marked "active" this morning may have been killed an hour ago.

When "expired" codes still work, and why

A code marked expired by a coupon listing is dead from the listing's standpoint. From the retailer's standpoint, it might be:

  • Genuinely expired. Code's validity window has passed, system rejects it. Most common case.
  • Replaced, but not deleted. Marketing team rolled the code (changed the string, kept the same offer). Old string still validates because the code object in the database is still active. Common for major retailers that update codes monthly without changing the underlying offer.
  • Conditionally expired. The public-facing code is dead, but the same percentage off is being delivered through a member-segment code or a cart-abandonment code with the same value. Try abandoning the cart and waiting 24 hours; the same offer often surfaces in the recovery email under a different string.
  • Expired in the affiliate feed but live on-site. Some retailers pull codes from the affiliate network when they want to limit publisher commissions but continue honoring the code via direct customer emails. Coupon listing site sees "feed says expired," marks it dead. The code still works because the back-end object is still active.

The "try the expired code anyway" trick has a hit rate of maybe 10–20% on dead listings — high enough to be worth thirty seconds, low enough that you should never count on it.

How to read a coupon listing without getting fooled

A short triage procedure that has reliably saved me time over the past few years:

  1. Check the date the listing was last verified. If it's more than a week old, the freshness is unreliable; if it's same-day, the code is probably alive in some form.
  2. Look at the eligibility text below the code, not just the headline percent-off. "First order only," "minimum $75," "excludes sale items" — these are where most code failures come from.
  3. Try the most-recent code first, and if it fails, try the second-most-recent. Don't burn time testing every code in a long list. The listings are typically ordered most-recent-first, and the working rate drops off sharply by the third or fourth code down.
  4. If a code fails with a generic error, copy the exact error text. Specific eligibility errors (geographic, segment-based) tell you whether the code is broken for everyone or just for you. A "this code has been redeemed" error means single-use and already used; move on.
  5. For a high-value cart, abandon and wait. Cart-abandonment codes are real, are higher-value than most public codes (often 25–30% versus a 15–20% public code), and arrive in 24–48 hours.

CouponHive's verification timestamps are part of why the listing is structured the way it is — knowing when a code was last tested matters more than knowing how many codes are in the list. A short list of recent, verified codes is functionally better than a long list of mostly-dead ones, and the math of the genre is that the long lists are mostly dead.

A coupon code is not a magic word. It's the visible end of a pipeline that runs from a marketing team's calendar through an affiliate network's feed through a checkout's validation logic through your cart. Once you can see the pipeline, the codes that work and the ones that don't stop being mysterious. They're just at different stages of a process that was never designed for you to see.

This article is published by CouponHive's editorial team. We may earn a commission when readers click through to retailer sites and complete a qualifying purchase. This does not influence our editorial content. See our disclaimer.

More in Trust & Transparency