From d5bb30d79ef66a5e1a46c42ec1e2b285e84ac4e6 Mon Sep 17 00:00:00 2001 From: Sunny Wu Date: Fri, 9 Oct 2026 10:16:01 +1100 Subject: [PATCH 1/8] UID2-8061: Document iOS 27 / macOS 27 WebKit block of uidapi.com Add a shared note snippet describing that WebKit on iOS 27+ and macOS 27+ (Safari) blocks browser requests to uidapi.com, and the required actions (server-side token generation, or Prebid.js server-only mode). Import it on the JavaScript SDK guides, the Prebid.js client-side guide and the SDK reference. Add short one-line notes to the Prebid.js client-server guide (Client Refresh / Server-Only modes) and the publisher web options overview. Co-Authored-By: Claude Sonnet 5.5 Ticket: UID2-8061 Branch: syw-UID2-8061-ios27-webkit-docs-note --- .../guides/integration-javascript-client-server.md | 3 +++ docs/guides/integration-javascript-client-side.md | 3 +++ docs/guides/integration-options-publisher-web.md | 4 ++++ docs/guides/integration-prebid-client-server.md | 8 ++++++++ docs/guides/integration-prebid-client-side.md | 3 +++ docs/sdks/sdk-ref-javascript.md | 3 +++ docs/snippets/_snpt-ios27-webkit-note.mdx | 14 ++++++++++++++ 7 files changed, 38 insertions(+) create mode 100644 docs/snippets/_snpt-ios27-webkit-note.mdx diff --git a/docs/guides/integration-javascript-client-server.md b/docs/guides/integration-javascript-client-server.md index 580fa28d4..a7be4658b 100644 --- a/docs/guides/integration-javascript-client-server.md +++ b/docs/guides/integration-javascript-client-server.md @@ -12,6 +12,7 @@ import Link from '@docusaurus/Link'; import SnptIntegratingWithSSO from '../snippets/_snpt-integrating-with-sso.mdx'; import SnptPreparingEmailsAndPhoneNumbers from '../snippets/_snpt-preparing-emails-and-phone-numbers.mdx'; import SnptExampleClientServerSendUid2ToSdk from '../snippets/_snpt-example-client-server-send-uid2-to-sdk.mdx'; +import SnptIos27WebkitNote from '../snippets/_snpt-ios27-webkit-note.mdx'; # Client-Server Integration Guide for JavaScript @@ -43,6 +44,8 @@ For integration scenarios for publishers that do not use the SDK for JavaScript, If you are using Google Ad Manager and want to use the secure signals feature, first follow the steps in this guide and then follow the additional steps in the [Google Ad Manager Secure Signals Integration Guide](integration-google-ss.md). ::: + + ## Integrating with Single Sign-On (SSO) diff --git a/docs/guides/integration-javascript-client-side.md b/docs/guides/integration-javascript-client-side.md index faed4b0a2..18d8b1ca0 100644 --- a/docs/guides/integration-javascript-client-side.md +++ b/docs/guides/integration-javascript-client-side.md @@ -13,6 +13,7 @@ import Tabs from '@theme/Tabs'; import TabItem from '@theme/TabItem'; import SnptIntegratingWithSSO from '../snippets/_snpt-integrating-with-sso.mdx'; import SnptPreparingEmailsAndPhoneNumbers from '../snippets/_snpt-preparing-emails-and-phone-numbers.mdx'; +import SnptIos27WebkitNote from '../snippets/_snpt-ios27-webkit-note.mdx'; # Client-Side Integration Guide for JavaScript @@ -44,6 +45,8 @@ To implement, you'll need to complete the following steps: 3. [Configure the SDK for JavaScript](#configure-the-sdk-for-javascript) 4. [Check that the token was successfully generated](#check-that-the-token-was-successfully-generated) + + ## SDK for JavaScript Version Support for client-side token generation is available in version 3.4.5 and above of the SDK. diff --git a/docs/guides/integration-options-publisher-web.md b/docs/guides/integration-options-publisher-web.md index 76dc04d11..6954a85ab 100644 --- a/docs/guides/integration-options-publisher-web.md +++ b/docs/guides/integration-options-publisher-web.md @@ -44,6 +44,10 @@ To accomplish all steps, you can combine solutions. For example, you could use t +:::note +On iOS 27+ and macOS 27+ (Safari), WebKit blocks browser requests to `uidapi.com`, so client-side token generation and refresh, and the SDK for JavaScript download, fail. Use a server-side solution to generate and refresh tokens. See [Publisher Integration Guide, Server-Side](integration-publisher-server-side.md). +::: + ## Preparing DII for Processing diff --git a/docs/guides/integration-prebid-client-server.md b/docs/guides/integration-prebid-client-server.md index 0092483a9..9e68fa532 100644 --- a/docs/guides/integration-prebid-client-server.md +++ b/docs/guides/integration-prebid-client-server.md @@ -108,6 +108,10 @@ There are two ways to refresh a UID2 token, as shown in the following table. ### Client Refresh Mode +:::note +On iOS 27+ and macOS 27+ (Safari), WebKit blocks browser requests to `uidapi.com`, so Prebid.js cannot refresh the token from the browser. Use [server-only mode](#server-only-mode) instead. +::: + You must provide the Prebid module with the full JSON response body from the applicable endpoint: - [POST /token/generate](../endpoints/post-token-generate.md) for a new UID2 token. @@ -188,6 +192,10 @@ For information on how to determine if you need to provide a new token, see [Det ### Server-Only Mode +:::note +This is the mode to use on iOS 27+ and macOS 27+ (Safari), where WebKit blocks browser requests to `uidapi.com`. Generate and refresh the token on your server. +::: + In server-only mode, only the advertising token is provided to the module. The module cannot refresh the token. You are responsible for implementing a way to refresh the token. To configure the module to use server-only mode, do **one** of the following: diff --git a/docs/guides/integration-prebid-client-side.md b/docs/guides/integration-prebid-client-side.md index c730dbb6a..26c1cf639 100644 --- a/docs/guides/integration-prebid-client-side.md +++ b/docs/guides/integration-prebid-client-side.md @@ -13,6 +13,7 @@ import SnptIntegratingWithSSO from '../snippets/_snpt-integrating-with-sso.mdx'; import SnptPreparingEmailsAndPhoneNumbers from '../snippets/_snpt-preparing-emails-and-phone-numbers.mdx'; import SnptAddPrebidjsToYourSite from '../snippets/_snpt-prebid-add-prebidjs-to-your-site.mdx'; import SnptStoreUID2TokenInBrowser from '../snippets/_snpt-prebid-storing-uid2-token-in-browser.mdx'; +import SnptIos27WebkitNote from '../snippets/_snpt-ios27-webkit-note.mdx'; # UID2 Client-Side Integration Guide for Prebid.js @@ -20,6 +21,8 @@ This guide is for publishers who have access to +**Required action:** This integration no longer works on these browsers. Consider a server-side integration (see [Publisher Integration Guide, Server-Side](integration-publisher-server-side.md)), or generate tokens on your server and use the [UID2 Client-Server Integration Guide for Prebid.js](integration-prebid-client-server.md) in [server-only mode](integration-prebid-client-server.md#server-only-mode). +::: + ## Prebid.js Version This implementation requires Prebid.js version 8.21.0 or later. For version information, see [https://github.com/prebid/Prebid.js/releases](https://github.com/prebid/Prebid.js/releases). diff --git a/docs/sdks/sdk-ref-javascript.md b/docs/sdks/sdk-ref-javascript.md index a488293a6..e796e1218 100644 --- a/docs/sdks/sdk-ref-javascript.md +++ b/docs/sdks/sdk-ref-javascript.md @@ -27,8 +27,12 @@ For integration steps for publishers, refer to one of the following: - [Client-Side Integration Guide for JavaScript](../guides/integration-javascript-client-side.md) - [Client-Server Integration Guide for JavaScript](../guides/integration-javascript-client-server.md) +:::note +**Required action:** The SDK for JavaScript no longer works on these browsers. Use a server-side integration to generate and refresh tokens instead. See [Publisher Integration Guide, Server-Side](../guides/integration-publisher-server-side.md). +::: + ## SDK Version This page describes version 4 of the UID2 SDK for JavaScript, which is the latest version. If you're using an earlier version, we recommend that you upgrade your integration, using the [migration guide](#migration-guide). If needed, documentation is also available for the following earlier versions: diff --git a/docs/snippets/_snpt-ios27-webkit-note.mdx b/docs/snippets/_snpt-ios27-webkit-note.mdx index 295d488f2..4dcab2c85 100644 --- a/docs/snippets/_snpt-ios27-webkit-note.mdx +++ b/docs/snippets/_snpt-ios27-webkit-note.mdx @@ -1,4 +1,3 @@ -:::note **iOS 27+ and macOS 27+ (Safari): impact on web integrations.** Starting with iOS 27 and macOS 27, WebKit blocks browser requests to `uidapi.com`. This affects all browsers on iOS 27+ (including Safari and Chrome) and Safari on macOS 27+. On affected browsers, the following operations fail: @@ -7,8 +6,3 @@ On affected browsers, the following operations fail: - Refreshing UID2 tokens from the browser - The Prebid.js [Client-Side integration](/docs/guides/integration-prebid-client-side) - Token refresh in the Prebid.js [Client-Server integration](/docs/guides/integration-prebid-client-server) - -**Required actions:** -- **SDK for JavaScript (Client-Side and Client-Server integrations):** Use a server-side integration to generate and refresh tokens. See [Publisher Integration Guide, Server-Side](/docs/guides/integration-publisher-server-side). -- **Prebid.js:** Generate UID2 tokens on your server and use the Client-Server integration in [server-only mode](/docs/guides/integration-prebid-client-server#server-only-mode). -::: From 5046a9c14a91c94896099e39b841dc2587a2fd0f Mon Sep 17 00:00:00 2001 From: Sunny Wu Date: Fri, 9 Oct 2026 16:15:55 +1100 Subject: [PATCH 3/8] Remove redundant Prebid.js bullets from iOS 27 note Co-Authored-By: Claude Sonnet 5.5 Ticket: UID2-8061 Branch: syw-UID2-8061-ios27-webkit-docs-note --- docs/snippets/_snpt-ios27-webkit-note.mdx | 2 -- 1 file changed, 2 deletions(-) diff --git a/docs/snippets/_snpt-ios27-webkit-note.mdx b/docs/snippets/_snpt-ios27-webkit-note.mdx index 31c6c6c15..f0a0d5c6f 100644 --- a/docs/snippets/_snpt-ios27-webkit-note.mdx +++ b/docs/snippets/_snpt-ios27-webkit-note.mdx @@ -4,5 +4,3 @@ On affected browsers, the following operations fail: - Downloading the UID2 SDK for JavaScript - Generating UID2 tokens from the browser - Refreshing UID2 tokens from the browser -- The Prebid.js [Client-side integration](/docs/guides/integration-prebid-client-side) -- Token refresh in the Prebid.js [Client-server integration](/docs/guides/integration-prebid-client-server) From fe40e6310b2093118bd9299487bc8ef2d947bfd6 Mon Sep 17 00:00:00 2001 From: Sunny Wu Date: Fri, 9 Oct 2026 16:18:03 +1100 Subject: [PATCH 4/8] Potential fix for pull request finding 'Distinguish CDN browser loading from NPM installation' Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --- docs/guides/integration-javascript-client-server.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/guides/integration-javascript-client-server.md b/docs/guides/integration-javascript-client-server.md index 7f554585f..5d91c59a0 100644 --- a/docs/guides/integration-javascript-client-server.md +++ b/docs/guides/integration-javascript-client-server.md @@ -47,7 +47,7 @@ If you are using Google Ad Manager and want to use the secure signals feature, f :::note -**Required action:** On these browsers the SDK for JavaScript can't be downloaded and tokens can't be refreshed from the browser, so this integration no longer works there. Generate and refresh tokens on your server instead. See [Publisher integration guide, server-side](integration-publisher-server-side.md). +**Required action:** On these browsers the SDK for JavaScript can't be loaded from the UID2 CDN and tokens can't be refreshed from the browser, so this integration no longer works there. Generate and refresh tokens on your server instead. See [Publisher integration guide, server-side](integration-publisher-server-side.md). ::: ## Integrating with single sign-on (SSO) From c67b8ae88c08271bf9d482c354109ca173a5ad11 Mon Sep 17 00:00:00 2001 From: Sunny Wu Date: Fri, 9 Oct 2026 16:18:26 +1100 Subject: [PATCH 5/8] Potential fix for pull request finding 'Clarify failure affects browser loading from UID2 CDN' Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --- docs/guides/integration-options-publisher-web.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/guides/integration-options-publisher-web.md b/docs/guides/integration-options-publisher-web.md index 8c134482e..a4ecf8b50 100644 --- a/docs/guides/integration-options-publisher-web.md +++ b/docs/guides/integration-options-publisher-web.md @@ -46,7 +46,7 @@ To accomplish all steps, you can combine solutions. For example, you could use t :::note -On iOS 27+ and macOS 27+ (Safari), WebKit blocks browser requests to `uidapi.com`, so client-side token generation and refresh, and the SDK for JavaScript download, fail. Use a server-side solution to generate and refresh tokens. See [Publisher integration guide, server-side](integration-publisher-server-side.md). +On iOS 27+ and macOS 27+ (Safari), WebKit blocks browser requests to `uidapi.com`, so client-side token generation and refresh, and loading the SDK for JavaScript from the UID2 CDN, fail. Use a server-side solution to generate and refresh tokens. See [Publisher integration guide, server-side](integration-publisher-server-side.md). ::: ## Integrating with single sign-on (SSO) From 4a2ebe98dded0856676c1234709a00d9e675101b Mon Sep 17 00:00:00 2001 From: Sunny Wu Date: Fri, 9 Oct 2026 16:18:43 +1100 Subject: [PATCH 6/8] Potential fix for pull request finding 'Qualify WebKit block as CDN browser-loading failure' Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --- docs/snippets/_snpt-ios27-webkit-note.mdx | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/snippets/_snpt-ios27-webkit-note.mdx b/docs/snippets/_snpt-ios27-webkit-note.mdx index f0a0d5c6f..a224bd8fe 100644 --- a/docs/snippets/_snpt-ios27-webkit-note.mdx +++ b/docs/snippets/_snpt-ios27-webkit-note.mdx @@ -1,6 +1,6 @@ **iOS 27+ and macOS 27+ (Safari): impact on web integrations.** Starting with iOS 27 and macOS 27, WebKit blocks browser requests to `uidapi.com`. This affects all browsers on iOS 27+ (including Safari and Chrome) and Safari on macOS 27+. On affected browsers, the following operations fail: -- Downloading the UID2 SDK for JavaScript +- Loading the UID2 SDK for JavaScript from the UID2 CDN - Generating UID2 tokens from the browser - Refreshing UID2 tokens from the browser From b2de2ba070ca44ad6f508eeee4a8a2a191252ef0 Mon Sep 17 00:00:00 2001 From: Sunny Wu Date: Fri, 9 Oct 2026 17:16:45 +1100 Subject: [PATCH 7/8] Address review feedback on iOS 27 WebKit notes Co-Authored-By: Claude Sonnet 5.5 Ticket: UID2-8061 Branch: syw-UID2-8061-ios27-webkit-docs-note --- docs/guides/integration-javascript-client-server.md | 2 +- docs/guides/integration-javascript-client-side.md | 2 +- docs/guides/integration-options-publisher-web.md | 5 ++++- docs/guides/integration-prebid-client-server.md | 4 ++-- docs/guides/integration-prebid-client-side.md | 2 +- docs/snippets/_snpt-ios27-webkit-note.mdx | 10 +++++----- 6 files changed, 14 insertions(+), 11 deletions(-) diff --git a/docs/guides/integration-javascript-client-server.md b/docs/guides/integration-javascript-client-server.md index 5d91c59a0..a2aec5942 100644 --- a/docs/guides/integration-javascript-client-server.md +++ b/docs/guides/integration-javascript-client-server.md @@ -47,7 +47,7 @@ If you are using Google Ad Manager and want to use the secure signals feature, f :::note -**Required action:** On these browsers the SDK for JavaScript can't be loaded from the UID2 CDN and tokens can't be refreshed from the browser, so this integration no longer works there. Generate and refresh tokens on your server instead. See [Publisher integration guide, server-side](integration-publisher-server-side.md). +**Required action:** On affected browsers, generate and refresh UID2 tokens on your server. See [Publisher integration guide, server-side](integration-publisher-server-side.md). ::: ## Integrating with single sign-on (SSO) diff --git a/docs/guides/integration-javascript-client-side.md b/docs/guides/integration-javascript-client-side.md index b8f853510..f1342b4be 100644 --- a/docs/guides/integration-javascript-client-side.md +++ b/docs/guides/integration-javascript-client-side.md @@ -48,7 +48,7 @@ To implement, you'll need to complete the following steps: :::note -**Required action:** The SDK for JavaScript no longer works on these browsers, so this integration can't generate or refresh tokens there. Use a server-side integration instead. See [Publisher integration guide, server-side](integration-publisher-server-side.md). +**Required action:** This client-side integration is not supported in affected browsers. Use a server-side integration to generate and refresh UID2 tokens. See [Publisher integration guide, server-side](integration-publisher-server-side.md). ::: ## SDK for JavaScript version diff --git a/docs/guides/integration-options-publisher-web.md b/docs/guides/integration-options-publisher-web.md index a4ecf8b50..d7f25a347 100644 --- a/docs/guides/integration-options-publisher-web.md +++ b/docs/guides/integration-options-publisher-web.md @@ -8,6 +8,7 @@ displayed_sidebar: sidebarPublishers import Link from '@docusaurus/Link'; import SnptIntegratingWithSSO from '../snippets/_snpt-integrating-with-sso.mdx'; import SnptUidVerifyInspect from '../snippets/_snpt-uid-verify-inspect.mdx'; +import SnptIos27WebkitNote from '../snippets/_snpt-ios27-webkit-note.mdx'; import SnptPreparingEmailsAndPhoneNumbers from '../snippets/_snpt-preparing-emails-and-phone-numbers.mdx'; # Publisher web integration overview @@ -46,7 +47,9 @@ To accomplish all steps, you can combine solutions. For example, you could use t :::note -On iOS 27+ and macOS 27+ (Safari), WebKit blocks browser requests to `uidapi.com`, so client-side token generation and refresh, and loading the SDK for JavaScript from the UID2 CDN, fail. Use a server-side solution to generate and refresh tokens. See [Publisher integration guide, server-side](integration-publisher-server-side.md). + + +**Required action:** On affected browsers, use a server-side solution to generate and refresh UID2 tokens. See [Publisher integration guide, server-side](integration-publisher-server-side.md). ::: ## Integrating with single sign-on (SSO) diff --git a/docs/guides/integration-prebid-client-server.md b/docs/guides/integration-prebid-client-server.md index b742e6734..1ebb252a7 100644 --- a/docs/guides/integration-prebid-client-server.md +++ b/docs/guides/integration-prebid-client-server.md @@ -113,7 +113,7 @@ There are two ways to refresh a UID2 token, as shown in the following table. ### Client Refresh mode :::note -On iOS 27+ and macOS 27+ (Safari), WebKit blocks browser requests to `uidapi.com`, so Prebid.js cannot refresh the token from the browser. Use [server-only mode](#server-only-mode) instead. +Client Refresh mode is not supported in all browsers on iOS 27 or later or in Safari on macOS 27 or later because Prebid.js cannot refresh UID2 tokens in the browser. Use [server-only mode](#server-only-mode) instead. ::: You must provide the Prebid module with the full JSON response body from the applicable endpoint: @@ -197,7 +197,7 @@ For information on how to determine if you need to provide a new token, see [Det ### Server-only mode :::note -This is the mode to use on iOS 27+ and macOS 27+ (Safari), where WebKit blocks browser requests to `uidapi.com`. Generate and refresh the token on your server. +Use this mode for all browsers on iOS 27 or later and Safari on macOS 27 or later. Generate and refresh UID2 tokens on your server. ::: In server-only mode, only the advertising token is provided to the module. The module cannot refresh the token. You are responsible for implementing a way to refresh the token. diff --git a/docs/guides/integration-prebid-client-side.md b/docs/guides/integration-prebid-client-side.md index 64bc5ebfd..6a987e3b4 100644 --- a/docs/guides/integration-prebid-client-side.md +++ b/docs/guides/integration-prebid-client-side.md @@ -24,7 +24,7 @@ To integrate with UID2 using Prebid.js, you'll need to make changes to the HTML :::note -**Required action:** This integration no longer works on these browsers. Consider a server-side integration (see [Publisher integration guide, server-side](integration-publisher-server-side.md)), or generate tokens on your server and use the [Client-server integration guide for Prebid.js](integration-prebid-client-server.md) in [server-only mode](integration-prebid-client-server.md#server-only-mode). +**Required action:** This client-side integration is not supported in affected browsers. Use either the [Publisher integration guide, server-side](integration-publisher-server-side.md) or the [Client-server integration guide for Prebid.js](integration-prebid-client-server.md) in [server-only mode](integration-prebid-client-server.md#server-only-mode). ::: ## Prebid.js version diff --git a/docs/snippets/_snpt-ios27-webkit-note.mdx b/docs/snippets/_snpt-ios27-webkit-note.mdx index a224bd8fe..989edace4 100644 --- a/docs/snippets/_snpt-ios27-webkit-note.mdx +++ b/docs/snippets/_snpt-ios27-webkit-note.mdx @@ -1,6 +1,6 @@ -**iOS 27+ and macOS 27+ (Safari): impact on web integrations.** Starting with iOS 27 and macOS 27, WebKit blocks browser requests to `uidapi.com`. This affects all browsers on iOS 27+ (including Safari and Chrome) and Safari on macOS 27+. +**Web integration limitations on iOS 27 and macOS 27.** Starting with iOS 27 and macOS 27, WebKit blocks client-side requests to `uidapi.com`. This affects all browsers on iOS 27 or later, including Safari and Chrome, and Safari on macOS 27 or later. -On affected browsers, the following operations fail: -- Loading the UID2 SDK for JavaScript from the UID2 CDN -- Generating UID2 tokens from the browser -- Refreshing UID2 tokens from the browser +As a result, affected browsers cannot: +- Load the UID2 SDK for JavaScript from the UID2 CDN +- Generate UID2 tokens in the browser +- Refresh UID2 tokens in the browser From 8366383c4b32a0f36698403bfbe0c143ade786ac Mon Sep 17 00:00:00 2001 From: Sunny Wu Date: Fri, 9 Oct 2026 17:20:18 +1100 Subject: [PATCH 8/8] Add iOS 27 WebKit note to documentation updates Co-Authored-By: Claude Sonnet 5.5 Ticket: UID2-8061 Branch: syw-UID2-8061-ios27-webkit-docs-note --- docs/ref-info/updates-doc.md | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/docs/ref-info/updates-doc.md b/docs/ref-info/updates-doc.md index 60c732167..144c95ae6 100644 --- a/docs/ref-info/updates-doc.md +++ b/docs/ref-info/updates-doc.md @@ -19,6 +19,24 @@ Check out the latest updates to our UID2 documentation resources. Use the Tags toolbar to view a subset of documentation updates. ::: +## Q4 2026 + +The following documents were released in the fourth quarter of 2026. + + + +### iOS 27 and macOS 27 web integration limitations + +October 9, 2026 + +Starting with iOS 27 and macOS 27, WebKit blocks client-side requests to `uidapi.com`. We've added notes to the web integration guides and the SDK for JavaScript reference explaining that, in affected browsers, the SDK can't be loaded from the UID2 CDN and tokens can't be generated or refreshed in the browser. The notes link to server-side alternatives. + +For details, see [Publisher integration guide, server-side](../guides/integration-publisher-server-side.md) and [SDK for JavaScript reference guide](../sdks/sdk-ref-javascript.md). + + + + + ## Q2 2026 The following documents were released in the second quarter of 2026.