Prebid.js 10 Is Here: A Practical Upgrade Checklist for Publishers
Prebid.js 10.0 shipped July 1 with removed modules, changed APIs, new defaults and schain moving to first-party data. Here is what to check before you upgrade your wrapper.
Prebid.js 10.0.0 was released on July 1, and point releases have followed quickly since. Major versions of Prebid are where breaking changes land, so this is not an upgrade to push to production on a Friday afternoon. It is also not one to put off indefinitely: new adapters, fixes and features will increasingly target 10.x, and falling several major versions behind makes the eventual jump harder.
The official Prebid 10 release notes list every change. Below is a practical reading of them for publishers and ad ops teams, organized as a checklist.
1. Check your module list first
A large number of obsolete modules were removed in 10.0, and many were renamed. This is where most upgrade builds will fail.
- Removed bidder and analytics adapters. Compare your build's module list with the removals in the release notes. If a partner's adapter is gone, confirm with them whether it was replaced or retired.
- Renamed Google modules. Modules that used the old DFP naming now use GAM naming. For example, dfpAdServerVideo became gamAdServerVideo, and dfpAdPod became gamAdPod. Update your build list and any code that references them.
- Renamed partner modules. Several bidder adapters changed names. Your build will fail loudly if you list a module that no longer exists, which is better than failing silently in production.
2. Move schain into first-party data
This change affects almost every publisher that resells or works through intermediaries. In Prebid 10, the supply chain object is treated as first-party data. Publishers should provide it in ortb2.source.schain or ortb2.source.ext.schain. The schain module now simply copies its configuration into first-party data and is slated for removal in a future version.
Plan to move your schain configuration into your ortb2 settings now, then verify in bid requests that each SSP still receives a complete, correct chain. Buyers applying supply path optimization rely on schain, so an incomplete chain can quietly cost you bids.
3. Review API changes if you have custom code
Publishers who only use standard configuration may never touch these, but anyone with custom scripts, reporting hooks or a homegrown wrapper layer should check:
- Bid response methods now return arrays. getBidResponsesForAdUnitCode and getNoBidsForAdUnitCode return arrays of bids, and getBidResponses and getNoBids return an object with an array for each ad unit.
- pbadslot is gone. Legacy pbadslot support was removed. Use ortb2Imp.ext.gpid for the GPID.
- Native targeting keys. The legacy sendTargetingKeys approach for native was removed. If you still run native through it, you will need to update your implementation.
- User IDs on bids. bid.userId is no longer populated; adapters use the eids arrays instead. Custom code that read user IDs from bid objects needs updating.
4. Understand the new defaults
Some changes do not break anything but alter behavior:
- allBidsCustomTargeting now defaults to false. Custom targeting values are no longer set for non-winning bids unless you enable it. If you have Ad Manager line items or reports that depend on targeting from losing bids, set this explicitly.
- Prebid Server hosts need explicit endpoints. Default configurations for various Prebid Server host companies were removed, so the server-side adapter now needs an explicit endpoint. If you run server-side bidding, confirm your s2sConfig specifies it.
- TCF control defaults. Default behavior for publisher purpose permissions in the TCF control module now enables purposes 4 and 7 and special feature 1. If you serve EEA traffic, review your GDPR enforcement configuration with your privacy team rather than relying on defaults.
- User ID module flags. A new enforceStorageType flag warns when an ID submodule uses the wrong storage type, and future versions will block it. New autoRefresh and retainConfig flags control ID refresh behavior.
5. Look at the new storage controls
Prebid 10 adds tooling to catalog and control device storage. A storage disclosures module lets you identify keys used in first-party storage and deny access to undisclosed ones, and the build can produce an artifact describing storage use, which helps with ePrivacy disclosures. A new activity control, combined with purpose 1 enforcement, prevents bidder endpoints from setting third-party storage through set-cookie headers. These are useful for privacy teams, but test them carefully: turning on enforcement without a complete disclosure list can break ID modules.
6. Update your build environment
Node.js 20 or later is now required to build Prebid.js, and TypeScript support has landed in the codebase. Tests now target Chrome 109 as the minimum browser version. If your build pipeline pins an older Node version, update it before anything else.
A safe upgrade plan
- Inventory. List every module in your current build, every custom script that calls the pbjs API, and every Ad Manager dependency on Prebid targeting keys.
- Build in staging. Update module names, move schain into ortb2, and set explicit values for any defaults you depend on.
- Compare bid requests. Use Prebid's debug mode or your browser's network tools to compare requests from your current version and 10.x for the same pages. Look for missing schain, IDs, consent strings and floors.
- Run a split test. Send a small share of traffic to the new wrapper and compare revenue per pageview, bid rates, timeouts and render rates by bidder.
- Roll out gradually. Increase the share over days, not minutes, and keep the previous build ready for rollback.
What not to do
Do not upgrade and change timeouts, floors or bidder lists at the same time. If revenue moves, you will not know why. Upgrade first, confirm parity, then tune.
Major Prebid releases are a chance to clean up years of accumulated configuration. Teams that treat them as a maintenance window rather than a chore usually come out with a faster, cleaner wrapper. HBDR runs Prebid-based wrappers for publishers and handles these upgrades as routine; the checklist above is how we would approach it for any stack.
Related Articles
Q4 Starts in 10 Days: A Yield Checklist for Lifestyle, Retail and Travel Sites
The fourth quarter is when ad budgets peak and mistakes cost the most. A practical checklist for code freezes, floors, supply chain hygiene, direct deals and monitoring before October 1.
Amazon DSP Can Now Buy Publisher-Hosted PG Deals in GAM. Get Your Setup Ready
Amazon DSP self-service buyers can now run Google Ad Manager programmatic guaranteed deals with creatives hosted by the publisher. Here is how to package and traffic those deals before Q4.
Google Now Uses IP Addresses for Ads in Europe. Check Your TCF Strings
Since August 3, Google uses IP addresses for ad measurement and personalization in the EEA, UK and Switzerland. Publishers need their consent setup to disclose it correctly.