ads.cert
Cryptographic proof for programmatic supply chains. ads.cert is IAB Tech Lab's protocol suite that signs and verifies ad requests, so buyers know a bid request is authentic and untampered.
- Term
- ads.cert
- Is
- IAB Tech Lab cryptographic protocol suite
- Secures
- Programmatic supply-chain transactions
- Fights
- Ad fraud and spoofed inventory
Parts of speech & senses
- ads.cert is a suite of open cryptographic protocols from IAB Tech Lab that authenticate and secure programmatic advertising transactions to raise auction integrity and combat ad fraud. "ads.cert signing let the DSP verify the bid request was genuine."
What ads.cert is
ads.cert is an umbrella name for a suite of open cryptographic protocols developed by IAB Tech Lab, the technical standards body of the Interactive Advertising Bureau, to secure programmatic advertising. Its purpose is auction integrity: to let the parties in a programmatic transaction cryptographically prove who they are and that the request between them has not been tampered with. In practice, a publisher generates a public and private key pair, publishes the public key at its advertising domain, and uses the private key to sign requests as they move through the supply chain. Ad exchanges and demand-side platforms can then verify those signatures, authenticate that inventory genuinely comes from the claimed source, and filter out requests that fail the check — closing a door that ad fraud has long used.
ads.cert matters because programmatic supply chains are long and easy to spoof. A fraudster can misrepresent low-value or fake inventory as premium, or forge requests that look like they came from a reputable publisher, siphoning ad budgets away from real media. Cryptographic authentication attacks that at the root: if a request must be signed by a key tied to the real publisher's domain and verified downstream, a forged or tampered request fails and can be dropped. This raises the trust and transparency of programmatic buying, which is why ads.cert sits alongside other IAB Tech Lab supply-chain measures as part of the industry's broader effort to make automated ad trading harder to defraud.
ads.cert 2.0 and how it works
In September 2021, IAB Tech Lab introduced ads.cert 2.0, a refreshed framework built around cryptographic protocols for transparent transactions. Two of its components are worth naming. The Call Signs protocol establishes, more securely, which domain names are legitimately participating in a given programmatic supply chain, so parties can trust the identities in the path. The Authentic Connections protocol adds origin authentication and tamper resistance to the server-to-server HTTP requests that flow between ad-tech entities, so a receiver can confirm a request truly came from the claimed sender and was not altered in transit. An open-source library implements Authenticated Connections so industry participants can adopt it, and it applies these protections to the OpenRTB bid requests at the heart of programmatic trading.
It helps to see how ads.cert relates to the industry's other anti-fraud tools rather than duplicating them. ads.txt and app-ads.txt let a publisher publicly declare which sellers are authorized to sell its inventory, and sellers.json and the SupplyChain object expose the chain of intermediaries — these are declarative transparency measures. ads.cert goes further by adding cryptographic authentication on top: it does not just declare who should be in the chain, it lets participants prove, request by request, that a message is authentic and untampered. So ads.cert is the cryptographic layer of a layered defense — most powerful when combined with the declarative measures, not as a replacement for them. Together they make it harder to inject fake or spoofed inventory into the auction.
Using ads.cert well
Using ads.cert well means adopting it as one layer of supply-chain hygiene rather than a silver bullet. Publishers implement the key management and signing so their requests can be authenticated downstream; exchanges and DSPs implement verification so they can act on the signatures, dropping requests that fail. It works best deployed alongside ads.txt, app-ads.txt, sellers.json, and the SupplyChain object, because declarative authorization and cryptographic authentication cover different gaps — one says who is allowed to sell, the other proves a specific message is genuine. For buyers, the payoff is fewer spoofed impressions and more trustworthy paths to real inventory; for the ecosystem, it is a harder target for fraud. Adoption across the chain is what gives it teeth, since a signature only helps if the other side verifies it.
The failure modes are treating ads.cert as a complete solution to ad fraud (it authenticates transactions but cannot catch every scheme, such as invalid traffic that comes through legitimate paths), implementing signing without downstream verification (so the signatures are never checked), and neglecting the key management the protocols depend on. Partial adoption blunts the benefit, because unsigned or unverified requests still flow. The discipline is to deploy ads.cert as the cryptographic layer of a broader, layered defense — combined with the declarative supply-chain standards and with fraud detection for the threats it does not cover — and to make sure both signing and verification are actually in place across the parties you trade with.
Synonyms & antonyms
Synonyms
Antonyms
Origin & history
ads.cert — IAB Tech Lab's cryptographic protocol suite for authenticating programmatic ad requests — secures the supply chain as a layer atop declarative standards like ads.txt.
Etymology: source.
Usage trends
Search interest for this term over the last five years:
Common questions
- What is ads.cert?
- An IAB Tech Lab suite of open cryptographic protocols that authenticate programmatic advertising transactions. Publishers sign requests with a private key and downstream parties verify them, raising auction integrity and helping combat ad fraud.
- What is ads.cert 2.0?
- A 2021 refresh of the framework. Its Call Signs protocol securely establishes which domains are in a supply chain, and its Authentic Connections protocol adds origin authentication and tamper resistance to server-to-server requests.
- How is ads.cert different from ads.txt?
- ads.txt declaratively lists which sellers are authorized to sell a publisher's inventory. ads.cert goes further, using cryptography to prove a specific request is authentic and untampered. They are complementary layers, best used together.
Resources & people to follow
- referenceRGM analysis — definitions, senses, and usage verified per term
Curated, non-competitor resources verified per term.
Related training
Disciplines
Areas of marketing where ads.cert is a core concern: