Trusted Server is an open-source edge runtime from IAB Tech Lab that acts as a hyper-intelligent reverse proxy for publishers. It can sit at the CDN perimeter or behind the publisher's existing CDN as a backend in front of origin. Every page and ad request passes through it, so Trusted Server sees the content and the ad stack in the same request path and can act on both at once. It gives publishers a durable first-party identifier and stronger signal in restrictive browser environments (like Safari), auctions that run server-side at the edge instead of in the browser, and fewer third-party scripts on the page. It needs little or no change to the publisher's CMS or monetization stack. Trusted Server is written in Rust and compiled to WebAssembly. Through EdgeZero, one codebase runs on Fastly Compute, Cloudflare Workers and Akamai’s Spin, or as a native Axum server for container-based deployments.
The guide in docs/guide/ (published at the link below) is the source of truth for human-readable documentation. This README is a brief overview.
| Guide | Description |
|---|---|
| Getting Started | Installation and setup |
| Architecture | System architecture overview |
| Configuration | Configuration reference |
| Trusted Server CLI | ts CLI install and command reference |
| Integrations | Partner integrations (Prebid, Lockr, etc.) |
See the Getting Started guide for installation and setup instructions.
# Build per adapter (target-matched aliases from .cargo/config.toml)
cargo build-fastly # Fastly adapter + core (wasm32-wasip1)
cargo build-axum # Axum dev server (native)
cargo build-cloudflare # Cloudflare Workers (wasm32-unknown-unknown)
# Install the host-target CLI for your current platform
cargo install-cli
# If your shell cannot find `ts`, add Cargo's bin directory to PATH
export PATH="$HOME/.cargo/bin:$PATH"
ts --help
# Create local config, then edit placeholders before validation
ts config init
# Edit trusted-server.toml. Server auctions use map-shaped
# [auction.providers.<id>] and [auction.bidders.<id>] tables.
ts config validate
# Audit a public page with Chrome/Chromium to bootstrap a draft config
ts audit generate https://publisher.example
# Run tests (Fastly/WASM crates — requires Viceroy)
cargo test-fastly
# Run tests (Axum native adapter)
cargo test-axum
# Run tests (Cloudflare Workers adapter — native host)
cargo test-cloudflare
# Run tests (Spin adapter — native host)
cargo test-spin
# Start local server — Axum (no Fastly CLI or Viceroy required)
cargo run -p trusted-server-adapter-axum
# Start local server — Fastly (requires Fastly CLI + Viceroy)
fastly compute serve# Format code
cargo fmt
# Lint — use target-matched aliases (workspace has multiple WASM runtimes;
# broad --all-features clippy is not a reliable gate across adapters)
cargo clippy-fastly
cargo clippy-axum
cargo clippy-cloudflare
cargo clippy-spin-native
cargo clippy-spin-wasm
# Run all tests
cargo test-fastly # Fastly/WASM (requires Viceroy)
cargo test-axum # Axum native adapter
cargo test-cloudflare # Cloudflare Workers adapter (native host)
cargo test-spin # Spin adapter (native host)See CONTRIBUTING.md for contribution guidelines.
This project is licensed under the Apache License 2.0 - see the LICENSE file for details.