Blog · Privacy

Safari 27 can shrink user.eids on web bid requests while impression counts stay flat.

Apple began rolling out iOS 27 on September 14, 2026. Within a week, The Trade Desk engineer Ian Meyers filed WebKit bug 324771 because Safari refused requests to adsrvr.org, the company's core ad request and delivery domain. AdExchanger reported on September 29 that The Trade Desk could not serve ads in Safari on updated iPhones and iPads. On October 9, AdExchanger's "The Apple Bites Back" noted Apple may remove adsrvr.org from the block list in an iOS 27.2 beta while identity vendors remain blocked, and that WebKit may enforce a larger private list than the nine domains named in public code review.

Request volume is the wrong health check

Publisher and SSP dashboards still show Safari browser sessions after an OS upgrade. Prebid and other wrappers still fire auction calls. OpenRTB request counts on device.os iOS and device.browser Safari can look unchanged week over week. That stability hides a different drop: the identity extensions that user-id modules populate after sync calls succeed.

In OpenRTB 2.6, extended identifiers live in user.eids, an array of objects each tagged with a source registrable domain and one or more uids. Buyers map those entries to UID2, ID5, RampID, and house graphs. When the browser never completes a sync because WebKit blocked the sync host at the network layer, the module exits quietly and the array is empty or missing the sources that still appear on Chrome traffic for the same site.

Sellers experience that as stable supply with softer CPMs or wider no-bid bands. Buyers experience it as Safari-looking inventory that fails addressability checks inside the bidder. Neither side sees a parse error: the request is valid JSON with fewer identity objects than last month's baseline.

What WebKit actually blocks

Meyers' September 21, 2026 bug description ties Safari 27 behavior to a WebKit change merged for bug 307853 that introduced unconditional blocking via IS_REQUEST_UNCONDITIONALLY_BLOCKABLE. The public ticket lists domains bundled into that behavior, including uidapi.com, adsrvr.org, id5-sync.com, eu-1-id5-sync.com, rlcdn.com, pippio.com, permutive.com, and ad.gt. Meyers wrote that the intent appears to be blocking domains that power post-cookie identity, but that adsrvr.org is The Trade Desk's core ad request and delivery domain, not an identity graph, and that the match subdomain relies on legacy third-party cookies.

PPC Land and other coverage of the same bug note the check runs on registrable domains before WebKit's tracker exemption logic, so subdomains such as js.adsrvr.org and match.adsrvr.org inherit the same answer. That mechanism is why a pixel-focused failure and an auction-focused failure show up together on some stacks even though OpenRTB never names those hosts. For the browser pixel and universal tag consequences, see pixellint.org on Safari 27 and adsrvr.org.

On October 5, 2026, Apple WebKit privacy manager John Wilander asked Meyers to test iOS 27.2 beta build 24B5099f. Meyers replied that he saw changes in that build. AdExchanger on October 9 reported Apple may have removed adsrvr.org from the list in beta while leaving the identity vendors blocked, and that Apple keeps a separate private list vendors must decompile WebKit to discover. The ticket remains open; production iOS 27 devices may still block delivery domains until a public 27.2 ships.

Where the bid request loses signal

Header bidding and identity modules run in the page context. A UID2 or ID5 module typically loads a sync URL, reads a token or cookie, then writes into user.eids on the outbound OpenRTB object. WebKit's block happens before that URL returns bytes. The module does not throw into the publisher console in a way sellers monitor; it simply omits the entry.

// Same page, two browsers — seller sees both as "Safari web"
{
  "device": { "ua": "... Safari/27 ...", "os": "iOS" },
  "user": {
    "eids": [
      { "source": "uidapi.com", "uids": [{ "id": "A4AAA..." }] },
      { "source": "id5-sync.com", "uids": [{ "id": "ID5*..." }] }
    ]
  }
}

// iOS 27 with sync hosts blocked — still a valid request
{
  "device": { "ua": "... Safari/27 ...", "os": "iOS" },
  "user": {}
}

Downstream systems that keyed frequency, deal eligibility, or model features on user.eids[].source now see anonymous web. If the bidder falls back to IP or coarse geo, buyers may still bid, but not with the same confidence the line item name implies. If the bidder hard-requires UID2, the same impression becomes a no-bid with reason codes that never reach the seller.

Google's ad tech remedies ruling, which we covered in Prebid Server as compliance record, already forces arguments about whether identity and consent signals pass on equal terms across routes. Safari shrinking user.eids on one browser slice is a parallel pressure: the signal never existed to pass, regardless of ad server fairness.

Why ATT comparisons mislead ops

AdExchanger's October 9 piece quotes editors comparing the block list to App Tracking Transparency. ATT constrained identifier use after consent prompts. The WebKit list blocks network access to named registrable domains during ordinary browsing, which stops parts of the ad stack from operating at all on affected builds, not only from reading IDFA.

Conversion APIs and server-side identity were the industry's answer to ATT on mobile apps. Mobile web and in-browser programmatic still depend on modules that call third party hosts before the bid request leaves the page. When those hosts are on the list, server-side CAPI does not backfill OpenRTB: the auction already went out thin.

Ops teams that split reporting by OS version but not by Safari minor release will blend iOS 26 sync-rich traffic with iOS 27 sync-blocked traffic. Addressability metrics look like model drift when the population changed at the network layer.

What to do this week

  • Capture paired bid requests from the same placement on iOS 26 and iOS 27 Safari, then diff user.eids, user.ext, and any Prebid userId keys.
  • Break out Safari traffic by OS build in SSP exports; do not rely on aggregate Safari CPM as a single series.
  • Map each eids.source you bid on to the sync host it requires; cross-check that host against the public WebKit ticket list and your own network logs on iOS 27.
  • Treat empty user.eids on regulated traffic as a consent and policy question, not only a supply quality question, before forwarding IDs from other contexts.
  • If you depend on adsrvr.org for delivery, track iOS 27.2 beta release notes separately from identity domains; delivery recovery does not restore UID2 entries.
  • Validate OpenRTB shape in CI so missing arrays are caught as schema issues, not mistaken for intentional anonymization.

Paste captured requests into the bid request tester and read user.eids and source domains for field-level detail. RTBlint is independent and not affiliated with Apple, WebKit, The Trade Desk, or Prebid.org. It checks whether payloads match OpenRTB and AdCOM; it does not detect browser block lists or restore blocked sync calls.

Sources