Bid Inspector Local only: nothing leaves the browser

A Chrome extension for anyone who buys, sells, or audits programmatic ads

See every bid your browser gets, even the ones that lost.

Open it on any ad-supported page and it shows the header-bidding auction as it happened: every bidder and price, the creatives that bid on you, the advertisers behind them, the IDs you carry, and exactly what targeting was sent. Then change that targeting and prove your line item serves.

Prebid.js · Amazon TAM · Google Ad Manager ~160 vendors classified Losing bids and their creatives First of its kind

Four jobs, one panel

Each one answers a question people currently answer by asking the SSP, reading DevTools, or shrugging.

See

What did the auction actually do?

Every Prebid bid with its price, outcome, latency and deal ID, on a timeline with the timeout line drawn in. Amazon TAM slots and signals. The line item and creative Google Ad Manager finally served in each slot, with an overlay that draws it on the page itself. And the part nobody else shows: the creatives that bid on you and lost, rendered in a sealed sandbox.

9 bids, 6 bidders, winner $2.41 CPM at 340 msopenx timed out at 1,310 ms. Three losing creatives captured.
Prove

Will my test line item serve?

Add a targeting rule for the site: a GPT key-value, Prebid first-party data, a test ID in a cookie, or a debug URL parameter. It is queued ahead of the site's own ad code on every load until you switch it off. Save & reload snapshots a baseline, reloads, and then reports per rule whether it landed, checked in the Prebid config and in the actual OpenRTB bid requests.

✓ Verified: arena_test=qa1 reached GPT before the first ad requestSlot /1234/home_top served line item 6789012, creative 1382900. Compare baseline to live to see the change.
Compare

What changed between these two loads?

One click snapshots a whole page load: bids, creatives, network, IDs, targeting, rules. Compare any two, or a snapshot against the live page: headline deltas, the winner and top CPM per slot, the GAM line item and creative, bidders added or removed, vendors and advertisers. Export a self-contained HTML report or an 18-sheet Excel workbook to attach to the ticket.

Auctions are noisy. A single CPM swing is weather; a changed line item on the slot you targeted is signal.Save two or three snapshots per side before you call it.
Know

What do bidders know about me?

Decoded identifiers with the vendor that set them, Prebid eIDs, cookie-sync traffic, and browser storage. TCF, GPP, and US Privacy consent strings read out in plain language. The "what bidders were told about you" profile: city and ZIP, IAB interest categories decoded through the bundled taxonomy, and the OpenRTB signals sent. Every underlined term has a hover card that says whether it is documented, inferred, or publisher-defined.

14 identifiers on this browser, 6 shared with bidders as eIDsConsent string says purposes 1, 3 and 4 granted. Two bidders received geo to the ZIP anyway.

Ad ops

Prove it before launch

"Is the test line item actually eligible?"

Inject the key, reload, read Verified, see the line item on the slot. Ten minutes instead of a Slack thread with the SSP.

Publishers & sales

Know your own stack

"Who is bidding, and who is timing out?"

Bidder latency against the timeout, ads.txt authorization for every bidder on the page, and an OpenSincera publisher record next to it.

Privacy & compliance

Evidence, redacted

"What was shared after the visitor chose 'reject'?"

Consent state, the eIDs and geo still sent, and exports that mask identifier values by default so a report can be forwarded.

Leadership

Fewer silent losses

"Why did that campaign underdeliver?"

Snapshots and a compare view turn "the platform says it's fine" into a before and after anyone can read.

What's in the panel

Overview

KPIs, plain-English findings for the page, four charts.

Auctions & Bids

Every bid, auction timelines with the timeout line, ad units, Prebid config and modules.

Creatives

Bid creatives including outbid ones, rendered on demand in an isolated sandbox.

Advertisers

Brands and domains behind the bids, win counts, max and average CPM.

Network

Every ad and marketing request, classified into ~160 vendors and 14 categories, with headers and payloads.

Identity & IDs

Decoded identifiers, cookies, Prebid eIDs, storage, cookie-sync calls.

Targeting & Consent

What bidders were told about you, TCF/GPP/USP consent, hb_* keys, GPT key-values, GAM line items per slot.

Amazon TAM

apstag detection, bid requests and slots, amzn_* signals.

TTD Open

OpenPath, OpenPass, UID2/EUID and ads.txt checks for The Trade Desk, plus OpenSincera publisher intelligence.

Injector

Targeting, identity and geo rules per site, with per-rule verification and reusable profiles.

Sessions

Snapshot library, A/B compare, HTML, Excel and JSON export, import.

Geo & locale

Nineteen city presets or custom: geolocation, time zone, language, Prebid geo, optional proxy.

Private beta

Want it for your team? Ask me for access.

Bid Inspector isn't on the Chrome Web Store. I'm giving it to a small group of ad-ops, publisher, and privacy people who want to see what the auction is doing instead of guessing. Send me a DM on LinkedIn with a line about what you'd use it for and I'll set you up with a walkthrough.

  1. Open: visit any ad-supported page, open the side panel, hit Reload so capture starts from the first byte.
  2. Read: the Overview explains the auction in plain English. Hover any term for what it means and who owns it.
  3. Change: add a targeting rule in the Injector, Save & reload, and read Verified next to it.
  4. Prove: compare baseline to live, export the report, attach it to the ticket.

How it stays safe

  • All analysis is local. Nothing is transmitted except an OpenSincera lookup you trigger yourself, with your own key.
  • HTML and Excel exports mask cookie values, decoded IDs, consent strings and ID-bearing URL parameters by default.
  • Creatives never auto-render. Rendering one loads that ad's markup in a sandbox and does fire its own tracking pixels, because that is what ad markup does.
  • Injected values are visible to scripts on that site. Use test values, never real customer data.

What it isn't

Bid Inspector shows what one browser saw on one page load. Auctions are noisy by nature, so treat a single CPM difference as weather and a changed line item as signal. It is evidence for a review, not a legal opinion, a certification of compliance, or a substitute for the SSP's own reporting. Full JSON snapshots contain your own browser's identifiers; share those carefully.

Bid Inspector · private beta · Chrome 116+ · Back to hord.brayden · Pixel Lab · Privacy