Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Build an OpenRTB handler around two contracts: the version of the IAB protocol you implement and the specific exchange or bidder profile you connect to. The handler must receive and decode the request, validate the required structure and partner rules, pass eligible inputs to bidding logic, and return either a response that correctly references the request and impression or the partner’s defined no-bid signal.

Start with the exchange profile, not just the OpenRTB schema

OpenRTB defines the real-time transaction between a supply source and a bidder: the request describes an impression and relevant context, and the response communicates a bid or no-bid outcome. The IAB Tech Lab’s OpenRTB standards page identifies v2.6-202309 as a September 2023 release, with updates that include bid-floor guidance and changes to deals and duration-based floors.

That version is only the starting point. A partner may support a subset of the standard, define additional fields, or specify different wire-level behavior. Google’s DV360 profile, for example, documents implementation-specific nuances and says some OpenRTB fields are unsupported or parsed without affecting bidding. Do not treat one partner’s rules as universal protocol rules.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Before implementing the endpoint, record the selected profile’s requirements:

  • OpenRTB revision and any required enumerations.
  • Supported serialization formats, content types, and required headers.
  • Endpoint and timeout expectations.
  • Required, supported, and ignored fields, including partner extensions.
  • Bid and no-bid response conventions, including status codes and response bodies.

Receive and decode the HTTP request

The OpenRTB 2.6 specification uses HTTP as the base exchange-to-bidder protocol and requires HTTP POST for bid requests. It suggests JSON for request and response data; a particular integration may support other encodings. Check the partner’s content-type and serialization rules before decoding rather than assuming every request is JSON. See the IAB OpenRTB 2.6 specification and the DV360 profile.

In a production service, enforce practical payload-size limits and deadlines, and define how the endpoint handles malformed or unsupported input. These are operational safeguards for the handler; the exact limits and error behavior belong to the deployment and partner contract, not to a universal OpenRTB value.

Validate the minimum request structure, then the profile

For OpenRTB 2.6, a BidRequest requires an id and at least one imp entry. Each impression must specify at least one applicable format, such as banner, video, audio, or native. This is a technical minimum, not proof that the request contains enough information for useful bidding.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

After checking that structure, validate the fields your integration actually uses. Depending on the partner and inventory, this may include site or app context, device and user information, currency, allowed seats, blocked categories, privacy or regulatory objects, and partner-specific extensions. Optional fields may be absent, and fields present in the base specification may be unsupported by a particular partner.

Keep core protocol validation separate from profile validation. OpenRTB permits exchange-specific extensions and assigns exchanges responsibility for publishing them to bidders. AdCOM supplies enumerated values referenced by OpenRTB 2.x, so use values appropriate to the supported revision rather than accepting arbitrary strings. Consult the IAB AdCOM page alongside the selected OpenRTB specification.

Pass explicit, validated inputs to bidding logic

Translate the validated request into the bidder’s internal decision inputs while preserving identifiers needed to construct a response. Treat impression format, currency, floors, deal terms, and restrictions as explicit inputs. Do not silently substitute defaults when a missing or unrecognized value changes whether a bid is eligible or how it should be priced.

The protocol’s required fields and recommended information serve different purposes. A handler can parse a structurally valid request and still lack the business context needed for a sound bid decision. Make those policy choices in the bidder layer, where the partner’s rules and the request’s actual values can be evaluated together.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Return a bid tied to the original request—or the defined no-bid

A bid response refers to the original request ID. Each bid identifies the impression it targets through impid and includes a price. Under the specification, bid price is expressed as CPM, even though the transaction concerns one impression. Preserve the request and impression identifiers through internal processing so the response cannot accidentally refer to a different impression.

Use decimal-safe currency handling rather than binary floating-point arithmetic for prices. The IAB specification gives BigDecimal in Java as an example of an appropriate approach.

The no-bid signal depends on the integration. The IAB specification describes an empty HTTP response as a bandwidth-efficient no-bid signal. DV360 documents a more concrete profile: HTTP 204 with no body for no-bid, and HTTP 200 with a bid response for a bid. Follow the selected partner’s contract; do not generalize those DV360 status codes to all OpenRTB endpoints.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Test protocol conformance and partner behavior separately

Use canonical examples in the IAB OpenRTB 2.6 specification to build representative request and response fixtures. The IAB’s programmatic resources also list the OpenRTB Bid Validator. These resources can help check structures and fields, but they do not replace testing the actual integration profile.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Build partner-specific tests for the cases that can change whether a request is accepted or a bid is valid:

  • Valid requests for each supported impression format and relevant site or app context.
  • Missing request IDs, empty impression arrays, unsupported formats, malformed payloads, and unsupported content types.
  • Partner extensions, ignored fields, enumeration values, and currency or floor handling.
  • Bid responses that reference the correct request and impression, plus the documented no-bid status and body.
  • Timeouts and payload limits configured for your service.

Keep the implementation versioned and profile-aware

A maintainable design keeps the core parser tied to an explicit OpenRTB revision and applies partner-specific rules through separate validation and configuration. This makes it easier to update enumerations or add a partner extension without treating it as a core field, and to support different response conventions without changing the meaning of the base protocol.

When evaluating an implementation approach, compare the exact protocol revision, supported encodings, partner requirements, inventory formats handled, and validation coverage. There is no evidence here that a particular language, framework, hosting service, or bidder platform is universally best. The right choice is the one that meets the selected profile and can be tested against its wire contract.

OpenRTB materials are technical guidance, not business or legal advice, and do not warrant regulatory compliance. Treat privacy and regulatory fields as implementation inputs, and obtain the appropriate compliance guidance for your operation.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.