Supply chain · also called Authenticated Connections
ads.cert
ads.cert is an IAB Tech Lab standard that uses cryptographic signatures so companies in the programmatic chain can prove that messages such as bid requests really came from who they claim.
ads.txt and sellers.json tell you who is authorised; ads.cert is meant to prove that a message was not forged or altered on the way. It uses public-key cryptography: a company publishes a public key (discoverable through DNS records under its domain), signs messages with its private key, and receivers verify the signature.
The first version of ads.cert was designed around OpenRTB 3.0 and signing bid requests end to end. Because 3.0 saw little adoption, the IAB Tech Lab released ads.cert 2.0 around 2021, focused on "Authenticated Connections" between trading partners and on signing specific fields, such as device and location data, that fraudsters like to spoof, including in CTV SSAI traffic.
In practice, adoption of ads.cert remains limited. It is technically powerful against device spoofing and SSAI spoofing, but needs many parties (SSAI vendors, SSPs, DSPs) to implement it together before buyers can rely on it.
Think of it like this
ads.cert is like a wax seal on a letter: anyone can claim to be the king, but only the king has the seal, and a broken seal shows tampering.
An example
A CTV app's SSAI server signs each request with its private key. The DSP fetches the public key from DNS, verifies the signature and discards requests that fail.
Related terms
ads.txt
ads.txt (Authorized Digital Sellers) is a public text file on a website's domain listing which ad sellers and accounts are authorised to sell that website's ad inventory.
sellers.json
sellers.json is a public file in which SSPs and exchanges list their seller accounts, naming who owns each one and whether it is a publisher or an intermediary.
SSAI spoofing
SSAI spoofing is CTV and video fraud in which fraudsters imitate a server-side ad insertion system, sending fake ad requests that appear to come from real viewers watching real streams.
Device spoofing
Device spoofing is faking the identity or type of device requesting an ad, such as a server posing as a smart TV or iPhone, to earn higher prices or dodge detection.
IAB Tech Lab
IAB Tech Lab is the non-profit standards body for digital advertising technology, founded in 2014, which develops specifications such as OpenRTB, VAST, ads.txt, sellers.json and the Open Measurement SDK.
Sources: IAB Tech Lab: ads.cert