Blog
OpenRTB news and analysis
What changed in the spec, what IAB Tech Lab is shipping, and what each development means for the people who maintain bid streams. Reference material lives in the docs; this is the timely layer on top. RSS feed.
European programmatic CTV can grow 44 percent while open auction samples stay STB-heavy, because most programmatic views clear as guaranteed deals.
FreeWheel's 1H 2026 report puts 71% of European programmatic ad views on guaranteed programmatic direct against 27% in the US, with CTV at 39% of European programmatic impressions versus 92% in the US. Headline growth rates describe ad-server delivery, not the bid request shape US filters were built on.
Authorized Buyers vs OpenRTB is a spec request plus at 3 and imp.ext.billing_id.
OpenRTB at is 1, 2, or 500 and above. Authorized Buyers documents request at 3 as fixed price and requires imp.ext.billing_id. Deal.at 3 is a different field. A spec-only check does not apply the profile.
AdCP vs OpenRTB is an agent task against a bid request, and the mapping is where the fields die.
get_products and create_media_buy are not auctions. video_placement_types maps to video.plcmt, not placement. A media buy carries no consent string. The deal id has to land on imp.pmp.deals or the open auction runs.
source.tid vs imp.ext.tid is the transaction and one impression inside it, not a single tid column.
source.tid is the transaction on that request. imp.ext.tid is one impression inside it. imp.id is often 1, 2, 3 and does not join paths. A second auction will not reuse the values unless you set them.
UID2 vs ID5 vs RampID is one OpenRTB array, and the source domain is what tells them apart.
They are not OpenRTB fields. They travel in user.eids, each with its own source. user.id is the exchange id. user.buyeruid is the cookie sync. An ID with no source is unmatchable. On 2.6 the array is not under ext.
GPP vs TCF vs the US Privacy string live on different OpenRTB fields, and one does not fill the others.
TCF is regs.gdpr plus user.consent. The US Privacy string is regs.us_privacy and is legacy next to GPP. GPP is regs.gpp plus regs.gpp_sid. A flag of 1 with no consent string is unresolved.
PMP vs preferred deal vs programmatic guaranteed is private_auction, at, and guar.
A private auction is private_auction 1, Deal.at 1 or 2, guar 0. A preferred deal is at 3 and guar 0. Programmatic guaranteed is at 3 and guar 1. Deal.bidfloorcur does not inherit the impression currency.
ads.txt vs app-ads.txt is the domain file or the bundle file, and the request picks which.
Web inventory reads ads.txt for site.domain. App inventory reads app-ads.txt for app.bundle. The first payment hop, hp not 0, has to match a DIRECT or RESELLER line in that file. The CLI does not fetch either file.
placement vs plcmt is not a rename: the same integer 2 is a different placement.
video.placement was deprecated in OpenRTB 2.6-202303. video.plcmt uses a new list. Copying the old integer claims the wrong subtype. Muted in-article autoplay that said placement 1 is plcmt 2, not sound-on instream.
ads.txt vs sellers.json vs schain is three files, and a complete chain can still fail the join.
ads.txt is the publisher allowlist. sellers.json is the seller account directory. source.schain is the path on this request. complete 1 with a missing hop is the dishonest case. The CLI does not fetch the files.
OpenRTB 2.5 vs 2.6 is a version string that says 2.6 and objects that still live under ext.
A request can announce 2.6 and still carry regs.ext.gdpr, user.ext.consent, source.ext.schain, and video.placement. plcmt and GPP are dated updates. Pin the snapshot on the builder output.
A DSP partner sample bid request is not the request production will send.
A solutions engineer at a DSP can validate the sample and still be looking at fields production leaves on the 2.5 paths. The sample has plcmt, regs.gdpr, and one inventory object. The live request has placement, regs.ext.gdpr, site and app together, and a floor with no currency.
An exchange bid-request fixture should fail in CI on the builder, not on a cleaned sample.
An engineer at an SSP or an exchange can pin the rtblint action on the JSON the request builder emits. A hand-cleaned golden file stays green while production still writes regs.ext.gdpr, a boolean imp.secure, and both site and app.
A publisher captured bid request is not the request the DSP bid on.
An engineer at a publisher can paste the OpenRTB the page or Prebid Server built into the tester. A spec pass on that paste does not describe the body Amazon TAM or Google Open Bidding sent.
nurl vs burl vs lurl lines up a win notice, a billing notice, and a loss notice.
test=1 is a non-billable auction, so a burl on that request is not spend. Deal.at of 3 means the floor is the price. Loss 209 is bcat on the request that ran, not a weak CPM.
Prebid vs Amazon TAM vs Google Open Bidding lines up three assemblies of one impression.
bcat and badv are per request, so a block in Prebid is not a block in TAM or Open Bidding. If at is omitted, the default is 2, second price, not first price.
Two-thirds of tested publisher homepages let every synthetic bot through. OpenRTB still treats device.ua as identity telemetry.
A June 2026 benchmark of 21,491 high-traffic domains found 65.3 percent stopped none of ten automated visitors and only 2.4 percent stopped all of them. More than seven in ten let a spoofed AI crawler string through. Buyers who classify invalid traffic from the bid request cannot see that gap on the landing page where forms and pixels fire.
Comscore uniques at a flagship publisher fell seventy-eight percent since 2021. OpenRTB site.domain did not shrink with them.
Status reporting on a September all-hands slide shows Business Insider averaging twenty-one million Comscore uniques in 2026 year-to-date, down from ninety-five million in 2021. Buyers who still buy open-web news on site.domain are pricing the same string while the measured audience behind it collapsed.
CTV pre-bid show targeting can splice a Content object from app.bundle alone while the exchange still forwards an empty content block.
OpenEPG DB 1.0 maps 375,000+ bundle variations to 580,000+ shows across 13,900+ FAST channels and returns OpenRTB 2.6 Content fields from app.bundle and device.ua with zero publisher opt-in. Buyers who QA only raw SSP logs still see title-blind requests after enrichment already ran upstream.
Jounce puts ninety-eight percent of the bidstream in reach of directness validation. Blunt supply filters act like ads.txt was never crawlable.
IAB Tech Lab's September 2026 supply-chain essay cites Jounce research that ninety-eight percent of bidstream traffic enables independent validation of directness. Buyers who skip ads.txt and sellers.json crawls in favor of hop-count caps alone are refusing inventory the existing stack already authorizes.
Half a billion AI slop impressions in H1 2026 can still arrive as clean OpenRTB requests, because nothing on the bid labels generated junk.
Verification data counted more than 500 million low-quality AI-generated impressions in the first half of 2026, blocked and post-bid combined. Travel and violence topped EMEA category lists. Bid requests that pass ads.txt and field validation still monetize the same pages until a buyer filters outside the payload.
Console-native FAST sells authenticated gaming identity. The OpenRTB request still reads like generic CTV unless the path declares it.
Live TV on PS5 routes SSAI through Publica and programmatic supply through PubMatic against 125 million PlayStation Network accounts. Third-party FAST apps on the same console only expose device-level IDs. Buyers who segment CTV on devicetype and IP alone cannot tell which identity layer they priced.
57 ad SDKs ship precise location into ad requests without manifest disclosure. OpenRTB device.geo inherits that gap.
A Q2 2026 source-code audit of 698 mobile ad SDKs found 57 transmitting precise geolocation without declaring it in bundled privacy manifests, affecting up to 88,787 apps, and 60+ SDKs built to broadcast location directly into the advertising bidstream. A bid request that passes field validation can still carry coordinates an integrating app never disclosed to the store or the user.
A 25 percent lead rate at half the CPA is not a supply win. It is an optimization signal fraudsters can manufacture.
An Offernet pet-insurance investigation found 70 percent of leads from cheap app placements with 15 to 25 percent form completion rates, while call-centre callbacks contradicted the data. When buyers optimize on in-platform conversion events without downstream reconciliation, fabricated success looks identical to real demand in the training loop, even though the bid request still passes as a real Android device.
Open programmatic CTV spends 57 percent on TV sets and 43 percent on phone apps. The auction still sells it as one class.
MediaPost coverage of a June 2026 U.S. open exchange study maps 57% of open programmatic CTV spend to large-screen TV OS players and 43% to mobile apps. Buyers who filter on devicetype=3 alone are aligning to half the money or misclassifying the other half, because OpenRTB never segregates the two surfaces in the deal label.
UK consumers block fewer ads than the global average, but two-thirds opt out of cookie tracking. That split is a bidstream problem.
A survey of 22,000 consumers finds 40% of UK users run ad blockers versus 47% globally, while 68% have opted out of cookie tracking. Inventory that still ships with third-party identity but thin privacy metadata is priced as addressable when the user population has already rejected cross-site profiling.
MRC invalid traffic rules require a decision rate. Unknown impressions are not clean.
Accredited measurement must report how many impressions had enough telemetry to classify invalid traffic. The MRC worked example leaves 15 of 100 rendered impressions unknown, and explicitly forbids treating unknown as valid. OpenRTB fields for IP, user agent, and app identity are the same signals.
A spec-valid video bid can still fill with empty VAST.
OpenRTB can accept imp.video and a well-formed bid.adm while the VAST inside is a wrapper that returns no ads, a SIMID file with no MediaFile, or a companion with no width. Bid-stream QA is not tag QA.
Half a million streaming shows get ranked from app.bundle alone. Your content object is optional to everyone but you.
Pixalate's July 2026 OpenEPG Index maps 532,000+ U.S. streaming TV shows from open-exchange bundle IDs without publisher opt-in. News drew 52% of mobile programmatic spend at 6.1% IVT while CTV news over-monetized at 37% spend versus 28% reach. Buyers who hard-require content.title are filtering on a field sellers rarely send.
adagents.json does not audit schain. Those two trust files do not talk.
AgenticAdvertising.org put publisher authorization in /.well-known/adagents.json. IAB Tech Lab already had ads.txt, sellers.json, and source.schain. A hop can be a valid seller and an unauthorized agent at the same time, because nothing in OpenRTB cross-checks the two files.
imp.native.request is a JSON string, not a nested object.
OpenRTB 2.x sends the Native request as a string inside imp.native.request, not as a nested JSON object. A bidder that json.Unmarshal into a struct without a second parse accepts the impression and never reads the assets.
Car head units now join the residential proxy pool. OpenRTB still has no field for that device class.
Kaspersky documented the first in-the-wild malware on Android automotive infotainment systems: click fraud and a BADBOX-linked residential proxy botnet delivered through a legitimate firmware updater. Pre-bid datacenter lists miss those IPs; the bid request does not say the device is a car.
A spec-valid SupplyChain hop can still be pooled inventory. ads.txt certifies the seller ID, not the site.
Dark pooling shares one authorized seller ID across unrelated domains. Buyers who only check that schain nodes appear in ads.txt and sellers.json will pass inventory they never meant to fund. Two academic crawls put a size on those pools.
OpenRTB carries device.ipv6 beside device.ip. IPv4-only datacenter blocks miss the parallel path.
During the dual-stack transition, a bid request can expose a residential device.ip and a datacenter device.ipv6 on the same impression. IPv4-only pre-bid datacenter lists miss that path; blunt IPv4 blocks can also reject an entire household when only a fraction of traffic behind the address is invalid.
Fraudulent CTV bundle IDs mimic each platform's ID grammar. OpenRTB validates shape, not spoof.
Analysis of the 50 highest-traffic fraudulent CTV bundle IDs finds brand spoofing on Roku, ASIN-style mimicry on Fire TV, numeric ID mimicry on Samsung, and mobile bundles in CTV streams. A well-formed app.bundle passes schema checks while the identity claim is false.
A CTV app delisted from the store can still bid. The auction keys on bundle ID, not shelf status.
Pixalate's August 2026 CTV pre-bid blocklist flags apps removed from stores that continue generating programmatic traffic. Impression-level IVT does not catch that gap; app-level exclusion does, because OpenRTB never carries whether the store still lists the bundle.
OpenRTB has two JSON encodings, and ARTF's own sample corpus uses both
The OpenRTB specification types 28 flag fields as integers. The IAB OpenRTB protobuf schema declares those same fields bool. Both encodings are in the wild, a payload valid in one is invalid in the other, and two of the five ARTF reference samples cannot be parsed by the protobuf JSON parser the framework runs on.
SupplyChain v1.1 adds nodes that never touch the money. Most schain checks assume those cannot exist.
The proposed upgrade puts technical custody entities into the main chain with hp=0, bumps ver, and reworks what complete means. Public comment closes August 21. What that does to hop counting, sellers.json cross-checks, and every validator that treats hp=1 as an invariant.
The agentic protocols shipped a version handshake. A bid request still has nowhere to say which OpenRTB it is.
AdCP 3.1 puts a version on every request and response, advertises supported releases, and returns a typed error when a buyer pins one the seller does not serve. AAMP 2.3 added trust verification on price-moving paths. OpenRTB, ten dated snapshots into 2.6, still agrees its version in an onboarding document.
CTV runs at 65 percent of commercial capacity. Part of that gap is demand that could not read the request.
Omdia's July 29 benchmark puts ad-supported CTV at 65 percent of commercial capacity and prescribes a bigger advertiser base. A seller's fill rate cannot tell a buyer who passed from a buyer who filtered the request before pricing it, and the CTV fields most likely to be wrong are the pod fields carrying the unsold slots.
AdCOM 1.0-202607: new enums, five redefined playback methods, and two releases carrying the wrong field names
The July 16 AdCOM release adds the CTV Ad Portfolio enumerations, quietly rewords five existing playback methods, and ships a Content object whose field names were renamed by accident in March and reverted on main a week after the tag. What that does to anything generated from a tagged release.
ARTF lets agents rewrite the bid request in flight. Nothing in it checks the result.
The Agentic RTB Framework specifies mutations against a live OpenRTB payload: eight intents, three operations, a path, and a typed payload. Every one of them can produce a request that is no longer valid for the version the exchange is running. What each intent touches, and where to put the check.
Live event ad insertion: a burst, not a stream, and the OpenRTB fields that carry it
A live break is thousands of impression opportunities released on one cue, with a hard deadline set by the transport stream. Which OpenRTB fields describe that, which one changed meaning in June 2026, and what a bid request for a live pod should actually look like.
Redefining Media Types: eight new claims, and the bidstream fields they land on
The IAB RMT Standard is in public comment until August 8, 2026 and is designed to be encoded directly into OpenRTB bid requests. Its eight impression-level attributes map onto fields that already exist and are already populated inconsistently. What to audit before the classification lands on top.
Bid request quality is a revenue line: the auction economics of broken fields
Every malformed or missing field in a bid request removes bidders, and every removed bidder lowers the clearing price. How field-level breakage turns into CPM decay, QPS deprioritization, and unauditable revenue.
What happens when your stack doesn't support an OpenRTB version? Nothing. That's the problem.
VAST has error 102 for version mismatches. OpenRTB has silence: unknown fields are ignored by design, and the version travels in an optional HTTP header. Where the signal actually drops, and how to catch it.
What is bidstream data? Everything a bid request broadcasts, field by field
Regulators now use the word bidstream in enforcement orders. What it means at the protocol level: which OpenRTB fields carry location, identifiers, and context, who receives them, and what the spec can and cannot do about it.
Will AI agents replace OpenRTB? Why the bid stream is the stable layer
Agentic advertising is reframing how media gets bought, but OpenRTB is not going away. Why both agent stacks build on the bid stream, what actually changes, and why validation matters more, not less.
OpenRTB 2.6-202606, field by field: live content and discount macros
The June 2026 dated snapshot added content.realtime and content.firstbroadcast, redefined content.livestream, and added two discount macros. What changed and the migration it forces.
AAMP, AdCP, and the bid stream: where agentic advertising actually touches OpenRTB
IAB Tech Lab's AAMP and AAO's AdCP both claim the agentic future. Where each one touches the bid stream, and the OpenRTB 2.6-202606 fields that shipped meanwhile.
CTV pod bidding grows up: duration floors, guaranteed deals, and live sports
The 2.6 pod bidding toolkit (podid, rqddurs, durfloors, mincpmpersec) was built for the live-sports CTV surge now underway. What sellers actually ship in 2026.
OpenRTB 2.6-202505: what changed and what to do about it
A field-by-field look at the May 2025 OpenRTB update and the integration work it creates for exchanges and bidders, centered on the new data.cids field.
The User-Agent string is going away: sua, client hints, and what to send now
Chrome UA reduction froze device.ua years ago. How the structured device.sua object (UserAgent, BrandVersion) works, and why bidders should parse it first.
DSA transparency in OpenRTB: where enforcement stands in 2026
The regs.ext.dsa and bid.ext.dsa extension two years into EU Digital Services Act enforcement: who requires it, what dsarequired values mean in practice.
Three years of plcmt: the state of the placement migration
OpenRTB 2.6-202303 deprecated video.placement for plcmt in April 2023. Three years on, why dual-sending both fields is still the norm, not the exception.
OpenRTB 3.0 and ads.cert in 2026: still waiting, still worth watching
Eight years after 3.0 went final, the layered protocol and its signed supply chain remain mostly unadopted. What would have to change, and what to do now.
GPP in OpenRTB: regs.gpp, gpp_sid, and the 2026 state sections
Every GPP section id bid requests carry in 2026, what regs.gpp and regs.gpp_sid must contain per OpenRTB 2.6-202211, and the half-pair mistakes validators keep flagging.
No more 2.7: how OpenRTB ships now, and why your parser should care
Since 2.6-202211, OpenRTB version numbers only move on breaking changes; everything else lands as dated snapshots. What that means for validation.
OpenRTB 2.6-202501 in review: the January update, field by field
OpenRTB 2.6-202501 added content.gtax and content.genres for CTV genre signaling. What changed, who is affected, and how to check your fixtures against it.
What the IAB Tech Lab 2026 roadmap means for OpenRTB
IAB Tech Lab's 2026 roadmap is mostly agentic advertising. Its one OpenRTB post covers gtax, genres, and a Curation object excluded from OpenRTB itself.