Middleware is software that sits between other pieces of software and lets them talk to each other. It is neither the application the user sees nor the operating system or network underneath. It translates formats, moves messages and handles authentication so that applications built by different people on different machines behave as one system. The category exists because connecting every program directly to every other program does not scale: ten systems wired to each other need 45 separate integrations, while ten systems wired to a shared layer need ten.

In advertising the word is rarely printed on a product, but the thing is everywhere. A mediation software development kit (SDK), a header bidding wrapper, a consent banner, a server-side tag container and a Model Context Protocol (MCP) server all stand between a publisher or advertiser and its partners, deciding what passes through.

How middleware works

An application calls the middleware through a standard interface instead of calling the destination directly. The middleware then does some combination of five things: it translates the request into the format the destination expects, routes it to one or more destinations, queues it if the destination is busy, enforces rules about who may see what, and records the exchange. Replies travel back the same way.

Textbooks divide the field into families. Message-oriented middleware passes messages through queues, so sender and receiver need not be online at once; IBM's MQSeries, released in 1993, is the classic case. Transaction processing monitors such as Tuxedo, which AT&T began building in 1983, ensure a group of database updates all succeed or all fail. Object request brokers (ORBs) let a program call a function on a remote machine as if it were local. An enterprise service bus (ESB) combines these into one backbone for a whole company. Application programming interface (API) gateways, the modern descendant, handle authentication, rate limits and logging in front of web services.

Advertising middleware maps onto those families closely. In app monetisation, a developer installs a mediation SDK and, alongside it, an adapter for each ad network, a thin layer of code translating between the two SDKs. When an ad slot opens, the mediation layer calls each adapter in turn and moves on when a network returns no ad, or runs an auction among bidding networks first. On the web, Prebid does the same job for header bidding. Publishers pick bidder adapters from a catalogue of more than 300 demand partners, and Prebid recommends an auction timeout of 1,000 milliseconds or less. The wrapper is the container that holds those adapters and sets the rules.

Consent follows the pattern. A consent management platform (CMP) loads a stub script before other tags, holds back tracking until a visitor decides, and then exposes a JavaScript function called __tcfapi that vendor scripts query for the answer. The answer travels onwards as a TC String in OpenRTB bid requests. At the end of 2025, IAB Europe counted 181 registered CMPs and 953 vendors.

Measurement has moved the layer onto servers. In server-side tagging, the browser sends one stream of events to an endpoint on the site's own subdomain. A server container, a Node.js application packaged as a Docker image, reshapes those events and forwards them to each vendor. The pattern overlaps with the reverse proxy, a network-level version of the same idea.

Composable customer data platforms (CDPs) such as Hightouch activate data directly from a company's warehouse, an approach often called reverse ETL (extract, transform, load). Hightouch's Exposure Log Matching product, launched with The Trade Desk on June 1, 2026, matches ad exposure logs to a brand's customer IDs there. Clean rooms need connectors of their own: Google's PAIR protocol, which reached version 1.0 in January 2025, lets clean rooms operated by different companies match records against each other.

Origin and evolution

The word appeared in print at the NATO Software Engineering Conference, held in Garmisch, Germany, from October 7 to 11, 1968. A. J. d'Agapeyeff described an "inverted pyramid" of software layers and told delegates: "Further up we have what I call middleware." In the report, edited by Peter Naur and Brian Randell and published in January 1969, middleware sits between application programs and the service routines below.

The term spread in the 1980s. The Object Management Group, founded in 1989, released version 1.0 of its Common Object Request Broker Architecture (CORBA) in October 1991. CORBA 2.0 followed in August 1996, adding the IIOP protocol so brokers from different vendors could interoperate.

The academic definition settled the same year. Philip Bernstein published "Middleware: A Model for Distributed System Services" in Communications of the ACM, volume 39, issue 2, in February 1996. He treated it as general-purpose services with standard interfaces and protocols, shared by many applications above a platform.

Roy Schulte of Gartner is credited with the first published use of "enterprise service bus" in 2002.

Advertising built its own layers in the 2010s. Prebid.js was written at AppNexus in early 2015 by Matt Kendall and Paul Yang, with Nick Jacob of the publisher Aplus, and Prebid.org formally launched on September 11, 2017. Google opened server-side tagging in public beta in August 2020. Anthropic published MCP in November 2024, letting AI models call outside tools through servers that translate their requests. The Ad Context Protocol (AdCP) launched on October 15, 2025 with six founding companies, building advertising tasks on MCP, and Anthropic donated MCP to the Linux Foundation's Agentic AI Foundation on December 9, 2025.

Why it matters for marketers

Middleware decides how much of a budget reaches the media, how fast a page loads and which data leaves a company.

Agentic buying has made the layer more visible. Amazon Ads put its MCP server into open beta on February 2, 2026, describing an intermediary that turns plain-language requests into structured Amazon Ads API calls, so one prompt can create a Sponsored Products campaign that needs three or more API operations. Prebid.org took over stewardship of the open-source Prebid Sales Agent on January 29, 2026, extending its role from auction middleware to agent middleware.

Publishers are moving middleware onto their own servers. IAB Tech Lab's Trusted Server, which PPC Land described as publisher-controlled edge cloud middleware acting as an ad router, collects consent and context signals, rewrites third-party calls as first-party ones and stitches the winning creative into the page. Auctions stay with Prebid Server or another supply-side platform (SSP).

Limitations, costs and disputes

Latency is the oldest complaint. Every layer adds a hop, and in sequential chains the delays compound. Prebid's own documentation acknowledges that holding up ad serving can lose impressions from visitors who leave quickly.

Fees and opacity grow with each intermediary. A study by ISBA, the Incorporated Society of British Advertisers, and PwC, published in May 2020, found publishers receiving 51% of advertiser spend, with 15% attributable to no participant at all. A January 2023 follow-up restated those figures to 57% and 17% on a narrower basis and then found the unattributed share down to 3%. Every middleware fee sits inside that arithmetic.

Single points of failure come with centralisation. AdMob rewarded video on Android failed to render for about 188 hours in August 2026, and mediation could not route around a winning ad that would not display. Microsoft's free public Prebid Cache shut down on April 30, 2026; one analyst put it at more than 60% of configured endpoints.

Lock-in and control are the newest disputes. Google's developer policies of August 31, 2026 ban programmatic proxies, a definition that names MCP servers and covers any service that "solely replicates, wraps, or re-exposes Google Ads programmatic capabilities." They also prohibit credentials embedded in "middleware that obfuscate the origin of the automated action." Cost is another limit: Draft Digital's owner, Lars Postmus, collapsed twelve MCP calls into a single buyer agent after his team kept hitting model usage limits. "Many buyers. Many tools. Tokens burn on every call," he wrote.

Visibility is contested too. Moving middleware server-side hides it from browsers and ad blockers, and filter lists began naming server-side Google Tag Manager subdomains individually in May 2026.

Not the same as

Orchestration layer. An orchestration layer decides the order of tasks and holds the goal. Middleware moves and translates the messages. Many orchestration products contain middleware, but routing a request is not the same as planning a campaign.

API. An API is a contract that defines how to ask a system for something. Middleware is running software that often exposes APIs, calls them and converts between them.

SDK. An SDK is a package of code a developer installs. A mediation SDK is middleware delivered as an SDK; an analytics SDK that only sends data to its maker is not.

Platform. A demand-side platform (DSP) or SSP makes buying or selling decisions and usually keeps a margin on them. Middleware in the strict sense passes decisions between systems, though vendors increasingly blur the line.

Recent developments

Apple's iOS 27, rolled out from September 14, 2026, stopped Safari loading requests to a list of ad tech domains, including The Trade Desk's adsrvr.org. IAB Tech Lab's chief executive, Anthony Katsur, promoted Trusted Server in response, writing on October 8 that it was "production ready TODAY!" A PPC Land review of its GitHub repository on October 10 found 343 commits but no tagged releases and 13 contributors. Cloudflare's x402 proxy template, updated in January 2026, works as a catch-all middleware that checks paths against protected patterns before charging AI crawlers. As of October 2026, the question in advertising is less whether middleware is needed than who operates it, and on whose servers.

Timeline

  • October 7-11, 1968: A. J. d'Agapeyeff uses the word middleware at the NATO Software Engineering Conference in Garmisch
  • January 1969: The conference report, edited by Peter Naur and Brian Randell, is published
  • 1983: AT&T begins developing the Tuxedo transaction processing monitor
  • 1989: The Object Management Group is founded
  • October 1991: CORBA 1.0 is released
  • 1993: IBM releases MQSeries message-oriented middleware
  • February 1996: Philip Bernstein publishes "Middleware: A Model for Distributed System Services" in Communications of the ACM
  • August 1996: CORBA 2.0 adds the IIOP interoperability protocol
  • 2002: Gartner's Roy Schulte publishes the term enterprise service bus
  • Early 2015: Prebid.js is written at AppNexus
  • September 11, 2017: Prebid.org formally launches
  • May 2020: ISBA and PwC report a 15% unattributable share in the programmatic supply chain
  • August 2020: Google opens server-side tagging in public beta
  • January 2023: The ISBA and PwC follow-up finds the unattributable share at 3%
  • November 2024: Anthropic publishes the Model Context Protocol
  • October 15, 2025: AdCP launches with six founding companies
  • December 9, 2025: Anthropic donates MCP to the Agentic AI Foundation
  • January 29, 2026: Prebid.org takes over the Prebid Sales Agent
  • February 2, 2026: Amazon Ads opens its MCP server in open beta
  • April 30, 2026: Microsoft's free public Prebid Cache shuts down
  • June 1, 2026: Hightouch and The Trade Desk launch Exposure Log Matching
  • August 31, 2026: Google's developer policies ban programmatic proxies for the Google Ads API
  • September 14, 2026: Apple begins rolling out iOS 27
  • October 8, 2026: IAB Tech Lab declares Trusted Server production ready

Summary

Who. Software vendors and open-source communities build middleware, from IBM, Oracle and the Object Management Group in enterprise computing to Prebid.org, CMP vendors, Google, Amazon, Hightouch and IAB Tech Lab in advertising. Publishers, advertisers, agencies and platforms run it.

What. Middleware is software that sits between applications, operating systems and networks, translating, routing, queuing and policing the requests that pass between them so separate systems can work together.

When. The term was first recorded at the NATO Software Engineering Conference in October 1968, formalised by Philip Bernstein in 1996 and adopted by advertising through mediation SDKs, Prebid from 2015, server-side tagging from 2020 and MCP-based agent tooling from 2024.

Where. It runs inside apps as SDKs and adapters, on web pages as wrappers and consent scripts, on servers and edge networks as tag containers and proxies, and in data warehouses and clean rooms as connectors.

Why. It reduces the number of integrations each party needs and gives one place to enforce rules. It also adds latency, fees and points of failure, and whoever operates it controls what data and money pass through.