Skip to content
Stoqlab

Free tool

Validate an OpenRTB supply chain

Paste the schain from a bid request. Every node is checked against the sellers.json files and app-ads.txt files we already hold, and you see which hop breaks the chain and why.

The schain object, or a whole bid request with source.schain (OpenRTB 2.6) or source.ext.schain (2.5). Up to 20 nodes.

Compare with the publisher's file (optional)

With an app, node 0 must be a DIRECT line of its app-ads.txt and every later node a RESELLER line. A bid request's app.bundle or site.domain is used when you leave these empty.

Free, no sign-up. Up to 10 checks a minute from one network.

What gets checked

  • The object. complete, ver and nodes, and each node's asi, sid, hp, rid, name and domain, as OpenRTB 2.6 defines them. A seller ID sent as a number, or a complete sent as "1", is the kind of thing strict exchanges reject.
  • The ad system. Do we hold a sellers.json for each asi? Without one, nobody can confirm who the seller is.
  • The seller. Is the sid listed there today, and does its seller_type fit where it sits? Node 0 should be the publisher's own account (PUBLISHER or BOTH). Every later node is someone reselling, so INTERMEDIARY or BOTH.
  • The publisher's file. Give an app or a website and node 0 must appear as a DIRECT line in its app-ads.txt (or ads.txt), and each later node as a RESELLER line.
  • The complete flag. complete: 1 claims the chain reaches the publisher. We flag it when node 0 is an intermediary's account or isn't authorised.

How to read the result

Valid means every check passed. Warnings are things a buyer may tolerate, such as a confidential seller or a reseller that isn't declared as one. Invalid means at least one node fails outright: a seller missing from sellers.json, a publisher node that is really an intermediary, or a hop the publisher never authorised. Notes are context, not problems.

Where the data comes from

As of 10 October 2026, Stoqlab tracks 2.2M+ live apps (2M+ iOS, 250k+ Android), has checked the app-ads.txt of 500k+ developer hosts (89k+ files found) and reads the sellers.json of 1,300+ networks. Nothing is fetched when you press Validate: the check runs on our stored copies, so a file changed in the last day may not show yet. The methodology says how often each source is read. What you paste is not stored.