How to Use ads.txt, sellers.json, and SupplyChain Objects Together
A worked trace showing what ads.txt, sellers.json, and the SupplyChain object each prove about a programmatic impression, and what they cannot prove.
The short answer
Three IAB Tech Lab standards help buyers trace where their programmatic ads were bought and who was paid. Each answers a different question. None answers every question. Used together, they let a buyer check whether an impression came through an authorized path.
What each standard does
ads.txt and app-ads.txt
A text file the publisher posts on its domain (or app developer site) listing the companies authorized to sell its inventory, with account IDs and whether each is a direct seller or a reseller. See IAB Tech Lab ads.txt.
Proves: the publisher authorized this seller account. Does not prove: that the impression actually came from that publisher.
sellers.json
A file posted by an exchange or SSP listing its sellers, their IDs, names, and whether each is a publisher or intermediary. See IAB Tech Lab sellers.json.
Proves: who the exchange says the seller account belongs to. Does not prove: that the seller's information is accurate or complete.
SupplyChain object (schain)
A record attached to a bid request listing each company that handled the impression before it reached the buyer.
Proves: the path as declared by participants. Does not prove: that every participant declared honestly.
A worked trace
Suppose your log shows an impression on a health publisher's site, bought through Exchange A.
- Check schain. It shows two nodes: Reseller R, then Exchange A.
- Check Exchange A's sellers.json. Reseller R's account is listed as an intermediary.
- Check Reseller R's sellers.json. The publisher's account is listed.
- Check the publisher's ads.txt. Reseller R is listed as an authorized RESELLER with the matching account ID.
If all four checks pass, the path is consistent with authorization. If any fails, such as the reseller not appearing in ads.txt, the impression came through an unauthorized or misdeclared path.
What the standards cannot do
- They do not verify ad quality, viewability, or invalid traffic.
- They depend on participants keeping files accurate.
- They do not show how much each participant charged.
Use them alongside verification tools and fee reconciliation.
Practical uses
- Supply path optimization. Remove unauthorized paths first. See SPO for pharma.
- CTV audits. Trace app bundles to their authorized sellers. See CTV supply chain audit.
- PMP validation. Confirm deal inventory is authorized. See PMP evaluation.
Practical takeaway
For your top 20 domains or apps by spend, run the four-step trace on a sample of impressions each quarter. Remove paths that fail authorization and ask your DSP to block them.
Sources
External guidance and platform documentation change. Links were current at publication; check them again before relying on them for a decision.
Editorial note. Analysis and frameworks are the author's own and do not represent Acxiom or any current or former employer, client, or named platform. Examples labeled hypothetical or illustrative are not results from real campaigns. Nothing here is legal, regulatory, or medical advice.
New pharma programmatic breakdowns, occasionally
One email when I publish something worth reading. Benchmarks, measurement teardowns, and case studies with the caveats attached. No cadence promises, no reselling your address.
Unsubscribe any time. See the privacy policy.
Working through this decision on a real plan?
I work on health and pharma data, identity, and activation, after five years running HCP and DTC programmatic agency-side. Happy to talk through how this applies to your situation.