IAB Tech Lab chief executive Anthony Katsur has spent the ten days since Safari's block on The Trade Desk's ad domain became public telling the industry to move its ad stack off the browser and onto publisher-controlled servers. In three posts on X dated September 30, October 8 and October 9, 2026, Katsur pointed to Trusted Server, an open-source edge runtime the Tech Lab maintains, and on October 8 declared it "production ready TODAY!" The project's public GitHub repository, captured on October 10, shows 343 commits, 130 branches, an Apache 2.0 licence and no published releases.
In Short
Apple's Safari browser on new iPhones and iPads stopped letting certain advertising companies' web addresses load, which cut The Trade Desk's ads out of Safari pages. The industry body that writes many ad tech standards says publishers can get around part of this by running the ad machinery on their own servers instead of inside the reader's browser, using free software it built called Trusted Server. Whether that works at scale is still unproven, because the software has no formal release yet and the Tech Lab itself says publishers have been slow to test it.
What Katsur posted, and when
The sequence starts on September 29, 2026, when Ari Paparo, the ad tech author and commentator, posted on X: "TTD ads blocked entirely in Safari. @adexchanger with the scoop and detailed breakdown." Katsur quoted that post the next morning, at 10:42 AM on September 30.
"If there was ever a better use case for the @IABTechLab Trusted Server, I can't think of any. We've predicted this at the Tech Lab for the last three years. Go server side," Katsur wrote, linking to iabtechlab.github.io/trusted-server/. By the time of the capture the post had 3,810 views, 4 replies, 2 reposts and 31 likes.
The second post followed on October 8 at 2:12 PM. It linked a Digiday story headlined "Apple's Safari ad tech blocklist sends publishers back to IAB Tech Lab's Trusted Server" and set out what Katsur said the software does. According to Katsur, Trusted Server enables publishers to "Regain control of their advertising technology and infrastructure," to "Restore addressability and measurement signals in restricted environments," to "Improve performance and efficiency through secure, server-side execution" and to "Protect consumer privacy while unlocking new monetization opportunities." He added: "And most importantly, Trusted Server is production ready TODAY!" and closed with "The technology is ready. Let's put it to work!" That post had 373 views, 2 reposts and 8 likes at capture.
The third, on October 9, quoted a Digiday post from October 8 that read: "What publishers once filed under someday now has a deadline, and Apple set it." Katsur's reply went further than the earlier two. "And that someday is the @IABTechLab Trusted Server. As an industry, we can no longer operate in the browser. It is time to move the entire open web ad stack server side. Trusted Server does that in a turnkey solution. Open-source and free to all." It recorded 650 views.
Katsur's account lists him as CEO of IAB Tech Lab and a former executive at Nexstar, MediaMath, DoubleClick and Magnite. The profile shows 5,465 posts, 3,646 followers and a join date of March 2009. The view counts on all three posts are modest, a few thousand at most, which says something about where this argument is actually being made: in trade press and at industry events rather than on the open platform.
Advocacy, not a forecast record
Two of Katsur's statements need to be read for what they are. The first is the claim that the Tech Lab "predicted this" for three years. None of the six documents examined for this article contains a dated prediction, from the Tech Lab or anyone else, that Apple would block specific ad tech domains at the browser level. Trusted Server itself was introduced in March 2025, according to AdTechRadar, roughly 18 months before Katsur's post. The three-year claim is the chief executive of a standards body promoting his own organisation's product, and it is presented here as that.
The second is "turnkey." The project's own README, discussed below, describes installation through the Rust toolchain, a command-line tool, a configuration file whose placeholders must be edited, and deployment to one of several commercial edge platforms or a container. It also says Trusted Server "needs little or no change to the publisher's CMS or monetization stack," which is a narrower and more testable claim than "turnkey." "Free to all" is accurate as far as the software licence goes, since the code is published under Apache 2.0. The edge platforms it runs on are separate services.
What Apple actually changed
None of the six source documents describes the Safari change in technical terms. AdTechRadar, in a staff-written piece dated October 9, 2026, refers only to "Apple's new Safari restrictions" and frames them as having "created an unexpected headache" as the industry gathered in New York for Advertising Week. Paparo's post, quoted inside Katsur's, is the only description among the attached materials, and it is one line long. The mechanism comes from reporting elsewhere.
Apple began rolling out iOS 27 on September 14, 2026. PPC Land's technical analysis of the WebKit code traced the block to a change merged on February 13, 2026: WebKit bug 307853, titled "Unconditionally block requests going to certain domains," and commit 307525@main, which added 11 lines and no deletions to a single file, WebPrivacyHelpers.mm. The public code contains only the hook. The list of domains it blocks is compiled into Apple's internal builds. The check receives a registrable domain, or eTLD+1, so every subdomain of a listed domain is covered.
Ian Meyers, senior director of engineering at The Trade Desk, filed WebKit bug 324771 on September 21, 2026, with priority P1 and severity Major. He reproduced nine entries: tainted.example, which appears to be a test fixture, plus uidapi.com, adsrvr.org, id5-sync.com, eu-1-id5-sync.com, rlcdn.com, pippio.com, permutive.com and ad.gt. Those map to Unified ID 2.0, The Trade Desk, ID5, LiveRamp, Permutive and Audigent. Meyers argued that adsrvr.org is The Trade Desk's core ad request and delivery domain rather than an identity domain, which is why the block stopped its ads entirely rather than degrading targeting. PPC Land's first report on the block noted that Google's ad.doubleclick.net continued to deliver on the same page.
Apple has not explained the list publicly. On October 5, John Wilander of Apple asked Meyers to test an iOS 27.2 beta, build 24B5099f, and Meyers replied 15 minutes and 22 seconds later that he could see changes. As of PPC Land's October 8 report, the bug remained in NEW status. AdExchanger reported on October 2 that the short list had been replaced by a remotely updated library covering hundreds of companies, a claim Apple has not confirmed, according to PPC Land's coverage of ID5's response.
A gap in the record
The framing in AdTechRadar and in Katsur's October 8 post treats "Apple's latest Safari restrictions" as a settled, describable event. The attached documents do not support that level of certainty. They contain no Apple statement, no list of affected domains, no indication of whether macOS is affected, and no mention of the iOS 27.2 beta that Apple asked The Trade Desk to test on October 5. AdTechRadar's own caveat is the more careful line: "Trusted Server isn't necessarily a workaround for all of Apple's restrictions."
What Trusted Server is
The repository README describes Trusted Server as "an open-source edge runtime from IAB Tech Lab that acts as a hyper-intelligent reverse proxy for publishers." It can sit at the CDN perimeter or behind a publisher's existing CDN, as a backend in front of the origin server. "Every page and ad request passes through it, so Trusted Server sees the content and the ad stack in the same request path and can act on both at once," according to the README.
That placement is the whole argument. In a conventional setup, the reader's browser loads the publisher's page and then runs JavaScript from a set of third parties: header bidding wrappers, identity modules, measurement tags, a demand-side platform's own domain. Each of those is a separate request from the browser to a separate domain, and each is something the browser can refuse. AdTechRadar summarised the alternative: "instead of relying on third-party JavaScript running in browsers to request ads, manage identity signals and communicate with adtech partners, publishers can handle more of those functions server-side."
According to the README, the result is three things: "a durable first-party identifier and stronger signal in restrictive browser environments (like Safari), auctions that run server-side at the edge instead of in the browser, and fewer third-party scripts on the page." Safari is the only browser named.
Language, runtime and hosting
Trusted Server is written in Rust and compiled to WebAssembly. The repository's language breakdown shows Rust at 77.7 percent of the code, TypeScript at 14.6 percent, HTML at 4.8 percent, JavaScript at 1.6 percent, shell scripts at 0.9 percent and HCL, the configuration language used by Terraform, at 0.3 percent.
Portability across hosts is handled by a layer called EdgeZero. "Through EdgeZero, one codebase runs on Fastly Compute, Cloudflare Workers and Akamai's Spin, or as a native Axum server for container-based deployments," the README states. The build commands reflect that split: a Fastly adapter compiled to the wasm32-wasip1 target, a Cloudflare Workers build compiled to wasm32-unknown-unknown, a native Axum development server, and separate test suites for Fastly, Axum, Cloudflare and Spin. Fastly tests require Viceroy, Fastly's local runtime emulator. A local Axum server can run without the Fastly command-line tools.
The project's documentation site tells a narrower story. Its homepage lists six features, one of which reads "Edge Computing: Runs on Fastly Compute for low-latency, high-performance ad serving at the edge," with no mention of Cloudflare, Akamai or Axum. The same page carries the label "Rolling main documentation," states that it was built from commit da31a215, and warns: "Content may describe unreleased behavior." The repository's most recent commit at the time of capture was 2a0cb04, so the documentation and the code head were not built from the same commit.
Configuration and the command-line tool
Deployment is driven by a TOML configuration file, trusted-server.toml. The README's quick start runs "ts config init" to create a local file, then asks the operator to edit placeholders before running "ts config validate." Server-side auctions are configured through map-shaped [auction.providers.] and [auction.bidders.] tables. A recent commit message in the repository reads "Add configuration-driven OpenRTB auction providers," which places OpenRTB, the protocol most programmatic exchanges use to pass bid requests, at the centre of the server-side auction design.
One command stands out for publishers trying to estimate the work involved. "ts audit generate https://publisher.example" uses Chrome or Chromium to audit a live public page and "bootstrap a draft config," according to the README. In practice that means the tool inspects what a page currently loads and proposes a starting configuration, rather than requiring ad operations teams to inventory every script by hand.
The README lists Getting Started, Architecture, Configuration, CLI and Integrations guides, and names Prebid and Lockr as partner integrations. AdTechRadar wrote that Trusted Server "integrates with existing systems like Prebid, allowing publishers to run auctions while potentially preserving ad revenue in environments where browser tracking is restricted."
Identity and consent
The documentation homepage describes the identity component as "Edge Cookie (EC) Generation," defined as "HMAC-based edge cookies minted by the publisher; downstream use determined by deployer configuration." HMAC is a keyed hashing method. The cookie is set by the publisher's own domain at the edge, which makes it first-party from the browser's point of view.
Consent is handled in two places. Under "Consent Signal Handling," the site lists "Extraction, decoding (TCF v2 format, GPP, GPC), and enforcement logic applied to ad serving decisions." Under "Configurable Consent Handling," it says "Trusted Server forwards available consent signals (TCF v2 format, GPP, GPC), and the deployer configures jurisdiction lists, signal interpretation, and conflict resolution." TCF v2 is IAB Europe's Transparency and Consent Framework, GPP is IAB Tech Lab's Global Privacy Platform, and GPC is the Global Privacy Control browser signal.
The wording matters. The consent logic is configured by the publisher, including which jurisdictions apply and how conflicting signals are resolved. Trusted Server provides the mechanism; the legal interpretation remains with whoever deploys it. A commit two weeks before the capture, titled "Complete removal of the legacy consent KV path (#903)," indicates the consent storage design was still changing in late September.
How active is the project?
The repository snapshot, captured on October 10, 2026, gives a reasonably detailed picture. It shows 343 commits on the main branch, 130 branches, 0 tags, 196 open issues and 71 open pull requests. It has 43 stars, 15 forks, 9 watchers and 13 contributors. The licence is Apache 2.0, and the LICENSE file was last changed "last year" with the commit message "Update LICENSE with Tech Lab copyright." The panel on the right reads "No releases published."
Activity in the week before the capture was heavy. The most recent commit, by contributor ChristianPavilonis and dated "yesterday," was titled "Fix missing Permutive segments and ignored integration log s..." (the message is truncated in the capture). Two days earlier came "Fold a build-time core source digest into the template fing...," touching the docs, the .github folder, AGENTS.md, Cargo.lock and the README. Five days before capture, someone added "an AWS deployment planning skill for Prebid Server G...," alongside a new deploy/pbs-example folder. Four days before, a commit adopted "EdgeZero reusable-sandbox lifecycle for Fastly." A week before, a folder named tinybird changed with the message "Split origin shareability from template eligibility."
The Permutive fix is worth noting. permutive.com is one of the nine domains on the list Meyers reproduced, and PPC Land's October 8 report described how Paradium, which owns Men's Journal and Parade, rerouted its Permutive code through Trusted Server to test whether audience data would flow again in Safari. Nothing in the repository links that commit to Paradium, and the timing alone does not establish a connection.
The repository also includes files aimed at AI coding assistants. A .claude folder, an AGENTS.md file and a CLAUDE.md file sit at the root, with the latter carrying the commit message "Make AGENTS.md the source of truth with CLAUDE.md as...". A pre-commit "URL-host linter" hook, installed through "ts dev install-hooks," is described in the README as required for contributors. Other root files include FAQ_POC.md, ProjectGovernance.md, TESTING.md and a CHANGELOG.md.
Production ready, without a release
Katsur's October 8 statement that Trusted Server "is production ready TODAY!" and AdTechRadar's line that "according to Katsur, Trusted Server is now production-ready" sit uneasily next to the repository. There are no tags and no published releases. The documentation is built from a rolling main branch and warns it may describe unreleased behaviour. The repository root also includes a file named FAQ_POC.md, with "POC" conventionally meaning proof of concept.
None of that proves the software cannot run in production. Many open-source infrastructure projects deploy from a main branch without formal versioned releases. But a publisher's engineering team evaluating "production ready" would typically look for a version number to pin, release notes, and a deployment reference, and the capture shows none of the first two. PPC Land's October 8 report, drawing on Digiday, said the Tech Lab was still preparing to go live with its first publisher. That is a different status from production use.
Who has to move first
Katsur conceded the adoption problem himself. Replying on September 30 to a user who asked whether technical sales houses were "incentivized in some way to implement this at scale, or does it impede their own operational control and margins?", he wrote: "Great question. We've educated many of the technical sales houses on Trusted Server, but it has been a slow mover. This may be the event that gets them to finally move forward with testing the framework."
"Testing the framework" is the operative phrase. Eighteen months after the project was introduced, the chief executive of the organisation behind it describes the next step for intermediaries as testing, not deployment.
Other replies on the thread captured the range of reactions. Gareth Glaser wrote: "This incident is certainly enough to convince me that this migration should be a priority, and every cdn should be seeing dollar signs." Dustin Cha called Trusted Server "a fantastic initiative" and added: "Adblocking creep is coming in from angles, this Safari incident is the tip of the iceberg." Paparo raised a practical question: "When you render the whole page server side do tracking pixels still fire on render?" The captured thread does not show an answer.
Glaser's comment points at a cost that the "free to all" framing leaves out. Trusted Server runs on Fastly Compute, Cloudflare Workers, Akamai's Spin or a self-managed container. Every page and ad request passing through an edge runtime is billable traffic on those platforms. The README does not discuss hosting costs, and none of the documents gives a figure.
The limits of going server side
Moving ad requests to the server changes which party the browser talks to. Under Trusted Server, a Safari user's device requests the publisher's own domain, and the edge runtime makes the calls to bidders and identity vendors server to server. Safari's domain check, which acts on requests leaving the browser, does not see those onward calls. That is the logic behind Katsur's "Go server side."
It is not a complete answer, and the record shows why. PPC Land reported in July that the Safari 27 beta also blocked LinkedIn and Bing tracking endpoints by IP address, terminating connections to known ad infrastructure ranges regardless of which domain loaded the script. The review that article drew on treated server-side tagging as unaffected but said first-party proxies remained exposed when they forward to the blocked destination. Trusted Server describes itself as a reverse proxy. Where exactly an edge runtime on a publisher's own domain falls in that distinction is not addressed in any of the attached documents.
There is also a plainer limit, noted in PPC Land's October 8 coverage: once all ad activity runs through the publisher's own domain, the remaining option for a browser maker that wants to stop it is to block or restrict the publisher's site itself. That is a far more visible step than adding an ad tech domain to an unpublished list. Whether Apple would take it is unknown.
And Trusted Server addresses only the web. In-app inventory on iOS is governed by App Tracking Transparency and the operating system's own rules, which an edge proxy in front of a website does not touch.
Why this matters for advertisers and publishers
Safari accounted for 15.1 percent of global browser traffic in the third quarter of 2025, against 66.3 percent for Chrome, according to Cloudflare data cited in PPC Land's coverage. On iPhone, where Safari is the default, the share of a typical publisher's mobile audience is considerably higher. A browser-level block on a buyer's delivery domain removes that buyer's demand from that traffic entirely.
The Trade Desk entered the episode already under pressure. Its shares fell 24 percent after hours on August 6 after third-quarter guidance pointed to a 12 percent revenue decline, and on September 4 it cut about 575 jobs, roughly 15 percent of staff. Identity vendors on the list face a similar exposure. Permutive's own August data, cited in PPC Land's reporting on ID5, put the CPM penalty for impressions lacking an identity signal at 41 percent, a vendor figure rather than an independent measurement.
For publishers, the attraction of Trusted Server is control over first-party data and over which partners touch a page. The open questions are cost, engineering capacity, and whether buyers bid as much on server-side impressions. PPC Land's October 8 report noted that earlier server-side auctions earned less because buyers who lost cookie access bid lower, and that the Tech Lab's project struggled for traction because its benefits were hard to price while its costs were visible.
Apple's restrictions have been tightening since Safari began blocking all third-party cookies by default on March 24, 2020. The difference this time is that the restriction landed on a buyer's delivery domain, not a cookie, and arrived without notice. AdTechRadar's "Our Take" put it bluntly: the industry wants to focus on AI and agentic advertising, "But those old battles never really get resolved, do they? They just keep coming back!" It closed with a question rather than an answer: "When will someone do something about Apple's monopolistic behavior? (If that's even possible.)"
What the Tech Lab can point to is a codebase under active development, a licence that allows anyone to deploy it, and a chief executive who says it is ready. What it cannot yet point to, on the evidence available, is a versioned release, a named production publisher, or data showing that server-side impressions in Safari recover the revenue the block removed.
Timeline
- March 24, 2020: Safari begins blocking all third-party cookies by default
- March 2025: IAB Tech Lab unveils Trusted Server, according to AdTechRadar
- February 13, 2026: WebKit commit 307525@main adds 11 lines enabling unconditional domain blocking
- July 2026: Safari 27 beta found blocking LinkedIn and Bing trackers by IP address
- August 6, 2026: The Trade Desk shares fall 24% after hours on weak Q3 guidance
- September 4, 2026: The Trade Desk cuts about 575 jobs
- September 14, 2026: Apple begins rolling out iOS 27
- September 21, 2026: Ian Meyers files WebKit bug 324771 listing nine blocked domains
- September 29, 2026: Ari Paparo posts "TTD ads blocked entirely in Safari," citing AdExchanger
- September 30, 2026: Katsur quotes Paparo: "We've predicted this at the Tech Lab for the last three years. Go server side"; replies that Trusted Server "has been a slow mover" with technical sales houses
- October 2, 2026: AdExchanger reports the list now covers hundreds of companies, unconfirmed by Apple
- October 5, 2026: Apple asks The Trade Desk to test iOS 27.2 beta build 24B5099f
- October 8, 2026: Katsur posts that Trusted Server "is production ready TODAY!", linking Digiday's report on publishers returning to the project
- October 8, 2026: PPC Land reports Paradium testing Permutive through Trusted Server
- October 9, 2026: Katsur posts that Trusted Server moves "the entire open web ad stack server side" in "a turnkey solution"; AdTechRadar publishes "Apple's AdTech Crackdown Gives Trusted Server Its Moment"; Trusted Server repository receives a commit fixing missing Permutive segments
- October 10, 2026: Trusted Server GitHub repository shows 343 commits, 130 branches, 0 tags and no published releases
Related PPC Land coverage
- Safari 27 blocks The Trade Desk's ads via 11 lines WebKit merged in February - the technical breakdown of the WebKit hook, the nine-domain list and Meyers' bug report.
- Apple's iOS 27 blocks The Trade Desk from serving ads on Safari - the first report on the block, including the note that Google's ad.doubleclick.net kept delivering.
- Apple asks The Trade Desk to test an iOS 27.2 build that may unblock ads - covers the iOS 27.2 beta and Digiday's reporting on publishers turning to Trusted Server, including Paradium's Permutive test.
- Trade Desk to test iOS 27.2 beta as Safari ad-domain ticket stays open - the October 5 exchange between Apple's John Wilander and The Trade Desk's Ian Meyers.
- ID5 faces Apple's iOS 27 Safari block as CEO says regulators should look - ID5's response and the regulatory history of Apple's ad and privacy decisions in Europe.
- Raptive's Bannister links Apple's 30% App Store fee to its Safari block - a publisher executive and IAB Tech Lab board member on what the block could mean commercially.
- Safari 27 blocks LinkedIn and Bing ad trackers by IP address - the July beta review that separated server-side tagging from first-party proxies.
- Ad tech veteran slams IAB's 2026 agenda for abandoning publishers - criticism from January 2026 that the IAB's agenda lacked publisher revenue sessions.
Summary
Who: Anthony Katsur, chief executive of IAB Tech Lab, promoting the organisation's open-source Trusted Server project. Apple, whose Safari browser on iOS 27 blocks a list of ad tech and identity domains including The Trade Desk's adsrvr.org. AdTechRadar, which covered Katsur's posts on October 9, 2026.
What: Katsur used three posts on X to present Trusted Server, a Rust and WebAssembly edge runtime that acts as a reverse proxy for publishers and runs auctions server side, as the response to Safari's block, calling it "production ready TODAY!" The public repository shows active development but no tags or published releases, and the Tech Lab was still preparing its first publisher launch as of early October.
When: Katsur's posts are dated September 30, October 8 and October 9, 2026. AdTechRadar's article is dated October 9, 2026. The repository and documentation were captured on October 10, 2026.
Where: The block applies to Safari on iPhone and iPad running iOS 27. Trusted Server runs on Fastly Compute, Cloudflare Workers, Akamai's Spin or as a native Axum server, sitting at or behind a publisher's CDN.
Why: Browser-level blocking removes a buyer's demand and identity vendors' signals from Safari traffic entirely. Moving ad requests to publisher-controlled servers takes those calls out of the browser's reach, though not necessarily out of reach of IP-level blocking or of a browser maker willing to restrict the publisher's own site.
Discussion