OpenRTB is the open technical standard that governs how a seller of advertising space and a prospective buyer communicate during an automated auction. It defines the message an exchange sends when an impression becomes available, the bid request, and the message a buying platform returns, the bid response, field by field. IAB Tech Lab, the standards arm of the Interactive Advertising Bureau (IAB), maintains it under a Creative Commons licence. The point is interoperability: a demand-side platform (DSP) can bid into dozens of supply-side platforms (SSPs) and exchanges without building a separate integration for each.

From ad request to bid

It starts when a page, app, streaming player or digital screen asks for an ad. The SSP or exchange converts that call into a bid request and posts it over HTTP to each connected bidder, usually as JSON, although binary formats such as Protocol Buffers are allowed. Its x-openrtb-version header names the version in use.

Only two attributes are strictly required: an exchange-assigned id and an imp array holding at least one impression. A site, app or dooh (digital out-of-home) object describes where the ad will appear. Device carries the user agent, IP address, operating system and, in apps, the advertising identifier, ifa. User holds the exchange's user ID, a buyeruid mapped through cookie syncing, audience segments and extended identifiers. Source carries the transaction ID, tid, and the SupplyChain object listing each paid intermediary. Regs carries legal flags such as coppa, gdpr and a Global Privacy Platform string.

Each imp object names the formats on offer - banner, video, audio or native - and sets bidfloor, the minimum price per thousand impressions (CPM), in bidfloorcur, which defaults to US dollars. Private marketplace deals ride in a pmp object. At the top level, tmax sets how many milliseconds the exchange will wait, network latency included, and at declares the pricing rule, 1 for first price and 2 for second price plus. Block lists sit alongside: bcat for advertiser categories, badv for advertiser domains, bseat for buyer seats.

The window is short. According to Google's Authorized Buyers documentation, Google waits 80 to 1,000 milliseconds depending on format and auction type. Passing means HTTP status 204 with an empty body, or a no-bid reason code. Bidding means returning a BidResponse echoing the request id, with a seatbid per buyer seat holding bid objects. Each bid names the impid it targets, a price expressed as CPM although a single impression is being bought, the advertiser domain in adomain, a creative ID and either ad markup in adm or a win notice URL in nurl.

In a worked example, an exchange offers one 300x250 banner with bidfloor 0.80, bidfloorcur EUR, at set to 1 and tmax set to 120. A DSP answers inside the window at 2.10. On winning, the exchange calls the win notice URL, and later the billing URL, burl, once the impression becomes billable under its own policy. Before each call it substitutes macros such as ${AUCTION_PRICE}, the clearing price, which at first price without discounts is 2.10.

Exchanges and SSPs, among them Magnite, PubMatic and Index Exchange, build the requests; DSPs such as The Trade Desk, Display & Video 360 (DV360) and Amazon DSP parse them.

The specification separates required attributes, whose absence would break a transaction, from recommended ones the market expects, and concedes that a request with only the former says little about what is for sale. DV360 treats site or app, device and user as required, according to its integration guide.

Any object may also carry ext, an extension object of undefined structure that each exchange documents itself, so one signal can sit in different places on different exchanges. Since 2.6, enumerated lists such as device types have lived in the Advertising Common Object Model (AdCOM), a companion specification, so they can change without a protocol release.

Origin and evolution

OpenRTB began in November 2010 as a pilot between three DSPs, DataXu, MediaMath and Turn, and three sell-side platforms, Admeld, PubMatic and The Rubicon Project. Block lists came first, in December 2010. Nexage proposed a mobile bidding interface, published in February 2011, and a video subcommittee merged the strands into OpenRTB 2.0, a unified standard released in June 2011. The IAB adopted it formally with version 2.1 in January 2012.

Later releases tracked the market. Version 2.2, dated April 2014, formalised private marketplace deals; 2.3 added native ads in November 2014 and 2.4 audio in March 2016. Version 2.5, in December 2016, added the Source object for header bidding and separate billing and loss notices.

OpenRTB 3.0 attempted a rebuild. Opened for public comment in September 2018 alongside AdCOM and ads.cert, a scheme for cryptographically signing bid requests, it split the protocol into four layers - transport, format, transaction and domain - and made HTTPS compulsory. It was not backward compatible. Media.net announced adoption in early 2019, but the market stayed on 2.x. An April 2026 guide from IAB Spain noted that most platforms still run 2.5 or 2.6.

Version 2.6 imported pieces instead. Opened for comment on December 9, 2021 and published in April 2022, it added ad pods for connected television (CTV), a structured user agent and formal places for the SupplyChain object and extended identifiers, while deprecating year of birth, gender and hashed device IDs. "As more CTV is bought programmatically, a standard yet flexible protocol is critical," Shailley Singh, senior vice president of product at IAB Tech Lab, said in the announcement.

From November 2022 the version number stopped moving. Releases carry a date suffix instead: 2.6-202303 replaced the video placement attribute with plcmt to separate in-stream from outstream video, and 2.6-202409 added fields recording who inserted an identifier and how it was matched. Only breaking changes increment the number, so implementers must tolerate fields they do not recognise.

Why it matters

Most impressions a DSP buys arrive as OpenRTB requests, so the fields a seller fills decide what a buyer can target, price and verify. The most prominent exception was Google, whose exchange used its own Authorized Buyers protocol. Google announced its retirement in March 2024 with a February 15, 2025 deadline, later extended to April 30; its release notes record the sunset on May 1, 2025.

Amazon Publisher Services extended its Signal IQ reporting to the full OpenRTB bidstream in May 2026, benchmarking whether publishers pass fields such as the Global Placement ID and transaction ID. PubMatic, which handles about 2.7 trillion bid requests a day, began charging publishers $0.001 CPM for requests above their caps on April 16, 2026.

Limitations and disputes

OpenRTB is voluntary, and nothing certifies compliance. A HUMAN Security diagnostic in November 2023 found that 79% of requests carried a SupplyChain object but only 42% of those objects passed full validation.

The sharpest dispute concerns tid. The specification says the transaction ID must be common across all participants, which lets a buyer recognise one impression arriving through several exchanges. On August 27, 2025, Prebid, the open-source header bidding framework, made the identifier bidder-specific after publishers argued it let buyers stitch data across sellers. IAB Tech Lab declared that the change materially violated OpenRTB, and its chief executive, Anthony Katsur, said the body did not endorse the approach.

Privacy is the most persistent criticism. Each request can send IP address, device identifier, location and page URL to every invited bidder, bidding or not. A January 2025 complaint by the Electronic Privacy Information Center (EPIC) and the Irish Council for Civil Liberties (ICCL) said Google's bidding system broadcast data about US individuals roughly 31 billion times a day. Under a US settlement over that system, approved on March 26, 2026, Google must offer users a control that strips encrypted user identifiers, device advertising IDs and IP addresses from bid requests. The protocol transports consent strings; it cannot police what recipients do with the data.

Not the same as

Real-time bidding. The practice of auctioning impressions one at a time. OpenRTB is one protocol for it; proprietary alternatives exist.

AdCOM. The companion object model defining shared objects and lists. It describes the goods; OpenRTB defines the transaction.

VAST. The Video Ad Serving Template is the XML a video bidder often returns inside adm. OpenRTB carries it but does not define it.

Prebid. Prebid is software that runs header bidding auctions. Prebid Server accepts OpenRTB 2.x requests, according to its documentation, but Prebid implements the standard rather than writing it.

Recent developments

Live television drove the latest release, 2.6-202606, published on June 11, 2026 after a comment period opened on April 28. It adds realtime and firstbroadcast to the Content object, separating a live match from a replay, plus two macros, ${AUCTION_DISCOUNT_PCT} and ${AUCTION_DISCOUNT_CPM}, that report any seller discount.

IAB Tech Lab's agentic roadmap of January 6, 2026 promised mappings of OpenRTB to Protocol Buffers and gRPC, a remote procedure call framework, rather than a replacement. The Agentic RTB Framework, which lets containerised partner code propose changes to a live bid request, was declared final on August 12, 2026. On September 14, 2026 the body made GitHub Markdown the reference text for its standards in place of PDFs.

Two consultations are open as of September 2026. Programmatic Best Practices 1.0, released on September 16 with comments due by October 16, asks companies to support the most recent widely deployed OpenRTB version. Version 3.0 of the Agentic Advertising Management Protocols (AAMP), whose OpenProposal specification passes agreed proposals to OpenRTB 2.6, OpenDirect 2.1 or the Deals API for execution, takes comments until October 22.

Timeline

  • November 2010: OpenRTB launches as a pilot between DataXu, MediaMath, Turn, Admeld, PubMatic and The Rubicon Project
  • December 2010: OpenRTB block list specification 1.0 released
  • February 2011: OpenRTB Mobile 1.0 released after a proposal from Nexage
  • June 2011: OpenRTB 2.0 unifies display, mobile and video
  • January 2012: The IAB adopts OpenRTB as a standard with version 2.1
  • April 2014: OpenRTB 2.2 formalises private marketplace deals
  • November 2014: OpenRTB 2.3 adds native ads
  • March 2016: OpenRTB 2.4 adds audio
  • December 2016: OpenRTB 2.5 adds the Source object, billing notices and loss notices
  • September 2018: OpenRTB 3.0, AdCOM and ads.cert released for public comment
  • November 2018: Initial release of OpenRTB 3.0
  • December 9, 2021: OpenRTB 2.6 opens for a 60-day comment period
  • March 2022: Latest revision of the OpenRTB 3.0 document
  • April 2022: OpenRTB 2.6 published with CTV ad pods and a structured user agent
  • November 2022: Dated releases begin with 2.6-202211, adding the DOOH object and Global Privacy Platform fields
  • April 2023: 2.6-202303 replaces the video placement attribute with plcmt
  • March 29, 2024: Google announces retirement of its proprietary Authorized Buyers bidding protocol
  • September 2024: 2.6-202409 adds identifier provenance fields
  • January 24, 2025: Google extends its protocol deadline from February 15 to April 30, 2025
  • May 1, 2025: Google records the sunset of its proprietary protocol
  • August 27, 2025: Prebid makes transaction IDs bidder-specific; IAB Tech Lab calls it a violation of OpenRTB
  • January 6, 2026: IAB Tech Lab's agentic roadmap commits to extending OpenRTB with Protocol Buffers and gRPC mappings
  • April 28, 2026: Content liveness attributes and discount macros open for public comment
  • June 11, 2026: 2.6-202606 released with realtime, firstbroadcast and discount macros
  • August 12, 2026: Agentic RTB Framework 1.0 declared final
  • September 14, 2026: IAB Tech Lab moves its reference specifications from PDF to GitHub Markdown
  • September 16, 2026: Programmatic Best Practices 1.0 released for comment until October 16
  • September 22, 2026: AAMP 3.0 opens for comment until October 22

Summary

Who. IAB Tech Lab maintains OpenRTB through its Programmatic Supply Chain Working Group, with contributors from companies including Google, Magnite, Amazon, The Trade Desk and Index Exchange. Exchanges and SSPs send bid requests; DSPs and other bidders answer them; Prebid Server and ad servers implement it on the publisher side.

What. An open protocol defining the bid request, bid response, notices and macros exchanged during a programmatic auction, carried over HTTP in JSON or binary formats.

When. It began as a pilot in November 2010, became an IAB standard with version 2.1 in January 2012, reached 2.6 in April 2022 and has shipped dated releases since November 2022, the latest on June 11, 2026.

Where. In the server-to-server connections between sell-side and buy-side platforms across web, app, CTV, audio and digital out-of-home inventory worldwide.

Why. A common format lets any buyer bid on any seller's inventory without bespoke integrations. Its voluntary, extensible design has also produced uneven compliance, a dispute over transaction IDs and sustained privacy complaints about how much data each request broadcasts.