Growth Marketing Glossary

ads.cert

ads-certnoun

Cryptographic proof for programmatic supply chains. ads.cert is IAB Tech Lab's protocol suite that signs and verifies ad requests, so buyers know a bid request is authentic and untampered.

unverified requestscryptographic signingauthenticated requests
Schematic — an ad request cryptographically signed and verified
Term
ads.cert
Is
IAB Tech Lab cryptographic protocol suite
Secures
Programmatic supply-chain transactions
Fights
Ad fraud and spoofed inventory

Parts of speech & senses

ads.cert · noun
  1. ads.cert is a suite of open cryptographic protocols from IAB Tech Lab that authenticate and secure programmatic advertising transactions to raise auction integrity and combat ad fraud. "ads.cert signing let the DSP verify the bid request was genuine."

What ads.cert is

ads.cert is an umbrella name for a suite of open cryptographic protocols developed by IAB Tech Lab, the technical standards body of the Interactive Advertising Bureau, to secure programmatic advertising. Its purpose is auction integrity: to let the parties in a programmatic transaction cryptographically prove who they are and that the request between them has not been tampered with. In practice, a publisher generates a public and private key pair, publishes the public key at its advertising domain, and uses the private key to sign requests as they move through the supply chain. Ad exchanges and demand-side platforms can then verify those signatures, authenticate that inventory genuinely comes from the claimed source, and filter out requests that fail the check — closing a door that ad fraud has long used.

ads.cert matters because programmatic supply chains are long and easy to spoof. A fraudster can misrepresent low-value or fake inventory as premium, or forge requests that look like they came from a reputable publisher, siphoning ad budgets away from real media. Cryptographic authentication attacks that at the root: if a request must be signed by a key tied to the real publisher's domain and verified downstream, a forged or tampered request fails and can be dropped. This raises the trust and transparency of programmatic buying, which is why ads.cert sits alongside other IAB Tech Lab supply-chain measures as part of the industry's broader effort to make automated ad trading harder to defraud.

ads.cert 2.0 and how it works

In September 2021, IAB Tech Lab introduced ads.cert 2.0, a refreshed framework built around cryptographic protocols for transparent transactions. Two of its components are worth naming. The Call Signs protocol establishes, more securely, which domain names are legitimately participating in a given programmatic supply chain, so parties can trust the identities in the path. The Authentic Connections protocol adds origin authentication and tamper resistance to the server-to-server HTTP requests that flow between ad-tech entities, so a receiver can confirm a request truly came from the claimed sender and was not altered in transit. An open-source library implements Authenticated Connections so industry participants can adopt it, and it applies these protections to the OpenRTB bid requests at the heart of programmatic trading.

It helps to see how ads.cert relates to the industry's other anti-fraud tools rather than duplicating them. ads.txt and app-ads.txt let a publisher publicly declare which sellers are authorized to sell its inventory, and sellers.json and the SupplyChain object expose the chain of intermediaries — these are declarative transparency measures. ads.cert goes further by adding cryptographic authentication on top: it does not just declare who should be in the chain, it lets participants prove, request by request, that a message is authentic and untampered. So ads.cert is the cryptographic layer of a layered defense — most powerful when combined with the declarative measures, not as a replacement for them. Together they make it harder to inject fake or spoofed inventory into the auction.

Using ads.cert well

Using ads.cert well means adopting it as one layer of supply-chain hygiene rather than a silver bullet. Publishers implement the key management and signing so their requests can be authenticated downstream; exchanges and DSPs implement verification so they can act on the signatures, dropping requests that fail. It works best deployed alongside ads.txt, app-ads.txt, sellers.json, and the SupplyChain object, because declarative authorization and cryptographic authentication cover different gaps — one says who is allowed to sell, the other proves a specific message is genuine. For buyers, the payoff is fewer spoofed impressions and more trustworthy paths to real inventory; for the ecosystem, it is a harder target for fraud. Adoption across the chain is what gives it teeth, since a signature only helps if the other side verifies it.

The failure modes are treating ads.cert as a complete solution to ad fraud (it authenticates transactions but cannot catch every scheme, such as invalid traffic that comes through legitimate paths), implementing signing without downstream verification (so the signatures are never checked), and neglecting the key management the protocols depend on. Partial adoption blunts the benefit, because unsigned or unverified requests still flow. The discipline is to deploy ads.cert as the cryptographic layer of a broader, layered defense — combined with the declarative supply-chain standards and with fraud detection for the threats it does not cover — and to make sure both signing and verification are actually in place across the parties you trade with.

Worked example. A premium publisher keeps finding its brand attached to bid requests it never generated — spoofed inventory that fraudsters pass off as its own to command higher prices. It adopts ads.cert, publishing a public key at its ad domain and signing its real requests with the private key. Downstream, a DSP verifies the signatures and drops requests that fail the check, so forged requests claiming to be the publisher no longer clear. Combined with the publisher's ads.txt declarations, the spoofing largely dries up. The lesson: ads.cert adds cryptographic proof of authenticity to programmatic requests, and paired with declarative supply-chain standards it makes forged and tampered inventory far harder to sell. (Illustrative; RGM analysis.)
Failure modes to watch. Treating ads.cert as a complete fix for all ad fraud rather than one layer; implementing signing without downstream verification so signatures are never checked; neglecting key management; and relying on it alone instead of pairing it with ads.txt, sellers.json, and fraud detection.

Synonyms & antonyms

Synonyms

ads.cert 2.0ad request authenticationsupply-chain signing

Antonyms

unauthenticated requestsspoofed inventory

Origin & history

ads.cert — IAB Tech Lab's cryptographic protocol suite for authenticating programmatic ad requests — secures the supply chain as a layer atop declarative standards like ads.txt.

Etymology: source.

Usage trends

Search interest for this term over the last five years:

View interest-over-time on Google Trends →

Common questions

What is ads.cert?
An IAB Tech Lab suite of open cryptographic protocols that authenticate programmatic advertising transactions. Publishers sign requests with a private key and downstream parties verify them, raising auction integrity and helping combat ad fraud.
What is ads.cert 2.0?
A 2021 refresh of the framework. Its Call Signs protocol securely establishes which domains are in a supply chain, and its Authentic Connections protocol adds origin authentication and tamper resistance to server-to-server requests.
How is ads.cert different from ads.txt?
ads.txt declaratively lists which sellers are authorized to sell a publisher's inventory. ads.cert goes further, using cryptography to prove a specific request is authentic and untampered. They are complementary layers, best used together.

Resources & people to follow

Curated, non-competitor resources verified per term.

Related training

Disciplines

Areas of marketing where ads.cert is a core concern:

Sources

  1. trendsGoogle Trends — "ads.cert"