Ad tech stocks
TEAD0.59▲ +16.13%CDLX2.69▼ -8.33%PSKY9.54▼ -7.70%186013.51▲ +7.48%U43.30▲ +5.78%APPS11.60▲ +4.50%APP278.01▼ -4.28%STGW8.45▲ +3.81%RDDT147.51▲ +3.56%ZETA32.45▲ +2.79%OMC75.62▲ +2.70%MNTN10.43▲ +2.56%TRU62.66▲ +2.51%SFOR44.85▼ -2.50%CCO2.41▲ +2.50%LFTO15.42▼ -2.41%CART43.95▲ +1.92%PUBM19.09▲ +1.92%WPP382.90▲ +1.81%INUV0.57▲ +1.79%NFLX68.36▼ -1.76%DSP12.52▲ +1.71%ILLM0.66▲ +1.54%GOOGL338.81▼ -1.53%SAX35.96▲ +1.41%SCOR4.75▲ +1.39%SIRI25.54▼ -1.31%035420191200.00▼ -1.29%4755681.70▼ -1.26%SPOT493.33▲ +1.22%AZRN0.82▼ -1.20%AAPL329.05▼ -1.19%IHRT2.13▲ +1.19%MGNI25.54▲ +1.09%ROKU150.66▼ -1.06%BIDU85.99▼ -1.01%PUB95.34▲ +0.87%SNAP5.45▲ +0.83%IBTA39.73▲ +0.82%SST2.64▲ +0.76%SNOW341.49▲ +0.57%47511238.50▲ +0.57%HAVAS17.55▼ -0.57%TBLA3.35▼ -0.45%RAMP37.69▲ +0.44%META728.04▲ +0.39%24331308.00▲ +0.38%TTD12.21▲ +0.29%OUT27.68▼ -0.25%0700431.00▼ -0.23%PINS18.93▲ +0.19%NEXN9.02▲ +0.17%DEC24.68▲ +0.16%PERI8.68▼ -0.12%CRTO15.21▲ +0.07%CPNG13.88▲ +0.04%DV13.48▼ -0.04%43243564.00▲ +0.03%WBD30.94▼ -0.02%BABA107.54▲ 0.00%VER12.08▲ 0.00%
Ticker byClearTrust

Supply chain · also called Authenticated Connections

ads.cert

ads.cert is an IAB Tech Lab standard that uses cryptographic signatures so companies in the programmatic chain can prove that messages such as bid requests really came from who they claim.

The short answer, from the AdTech Sumo glossary

ads.txt and sellers.json tell you who is authorised; ads.cert is meant to prove that a message was not forged or altered on the way. It uses public-key cryptography: a company publishes a public key (discoverable through DNS records under its domain), signs messages with its private key, and receivers verify the signature.

The first version of ads.cert was designed around OpenRTB 3.0 and signing bid requests end to end. Because 3.0 saw little adoption, the IAB Tech Lab released ads.cert 2.0 around 2021, focused on "Authenticated Connections" between trading partners and on signing specific fields, such as device and location data, that fraudsters like to spoof, including in CTV SSAI traffic.

In practice, adoption of ads.cert remains limited. It is technically powerful against device spoofing and SSAI spoofing, but needs many parties (SSAI vendors, SSPs, DSPs) to implement it together before buyers can rely on it.

Think of it like this

ads.cert is like a wax seal on a letter: anyone can claim to be the king, but only the king has the seal, and a broken seal shows tampering.

An example

A CTV app's SSAI server signs each request with its private key. The DSP fetches the public key from DNS, verifies the signature and discards requests that fail.

Related terms

Sources: IAB Tech Lab: ads.cert