DEV Community

Aleksander Sekowski
Aleksander Sekowski

Posted on

data:text/javascript in InteractiveCreativeFile Passes VAST 4.3. SIMID Still Loads HTML.

IAB Europe published its final CTV Measurement Framework on October 1, 2026. Buyers are now expected to ask how viewability, completion, and interactive engagement were measured, not just what number appeared on the IO. The video can play while the SIMID layer never mounts, and nothing in the campaign report explains that gap.

One XML mistake I keep seeing on migrated tags: the interactive URL is inlined as a data: URI left over from a VPAID script, not an HTML page.

<InteractiveCreativeFile apiFramework="SIMID" type="text/html">
  <![CDATA[data:text/javascript;base64,Y29uc29sZS5sb2coJ2hlbGxvJyk=]]>
</InteractiveCreativeFile>
Enter fullscreen mode Exit fullscreen mode

Trafficking tools that only XSD-check the document treat this as legal VAST 4.3. The linear <MediaFile> still points at an MP4, so preview looks fine. The player never enters SIMID mode on the iframe because the payload is not an HTML document.

What VAST 4.3 changed, and what SIMID did not

VAST 4.3 explicitly allows data: URIs where a creative URL would otherwise be HTTPS. That is useful for tiny test tags and for environments that block outbound fetches during QA.

SIMID 1.0 §3.1 is narrower: the creative loaded in the sandbox is an HTML document that implements the SIMID postMessage API. The MIME in the URI matters. data:text/html (or application/xhtml+xml) is in scope. data:text/javascript, data:application/javascript, or a base64 blob that decodes to a script is the same class of mistake as putting type="application/javascript" on the element while calling it SIMID.

The type="text/html" attribute on <InteractiveCreativeFile> does not rewrite the URI. If the CDATA declares text/javascript, you have a spec conflict even when the attribute looks correct.

What you see in production

The failure is quiet. SSAI and many CTV players play the progressive or stitched media and skip interactivity when the SIMID URL cannot load as HTML. Quartile and completion beacons on the linear asset still fire, so delivery dashboards look healthy. Product and engagement metrics tied to the interactive unit flatline.

That pattern matches other SIMID URL bugs (empty CDATA, http://, placeholder macros). The SIMID rule index groups them by rule id so you can grep CI output instead of re-learning each migration artefact.

For this specific case, vastlint reports SIMID-1.0-simid-url-data-html as an error when a SIMID URL uses a data: scheme without an HTML media type.

$ vastlint check simid-data.xml
simid-data.xml  VAST 4.3
  error    SIMID creative URL uses data: URI without text/html MIME
           SIMID-1.0-simid-url-data-html
Enter fullscreen mode Exit fullscreen mode

Whitespace-only URLs and missing CDATA bodies are a different rule (SIMID-1.0-simid-url-empty). Fix the MIME before you chase handshake bugs inside the creative.

How you catch it before the buy goes live

Start with the live tag, not a pasted fragment from the ad server UI.

The VAST tag tester fetches the tag URL, previews the media, and surfaces tracking URLs so you can confirm the MP4 or HLS path is real. If interactivity is part of the sale, paste the same URL into the VAST inspector and walk wrapper hops until you reach the <InteractiveCreativeFile> that carries SIMID.

For the handshake itself, the IAB-style VAST tester loads sample creatives and logs host transport messages. It is an independent fork, not an IAB Tech Lab product, but it exercises the same postMessage path a spec-compliant player uses. If the workbench never enters SIMID mode while the video preview plays, fix the URL and apiFramework before you open a ticket against the HTML asset.

CLI or CI after that:

$ vastlint check --severity error tag.xml
Enter fullscreen mode Exit fullscreen mode

The SIMID validation overview maps which rules apply to linear versus nonlinear 1.1 overlays. The SIMID overview restates the envelope: HTTPS or valid data:text/html, sibling <MediaFile>, and apiFramework="SIMID" exactly.

An implementation that lets a model or agent emit VAST still has to check the payload on the wire. vastlint (cargo install vastlint, npm install vastlint) is that check for the creative the buy claimed. It is independent of IAB Tech Lab and of AAO. It does not replace OMID verification in <AdVerifications>; SIMID and OMID solve different layers. When both are on the tag, validate each contract separately.

Where to go next

If you are migrating off VPAID, read how type="text/html" differs from legacy JavaScript media files, and keep a real <MediaFile> next to SIMID so players without iframe support still have video.

If your trafficking template still emits inline scripts, host a minimal HTML wrapper that loads the SIMID API and point the tag at https:// before you consider data: at all. CTV measurement frameworks assume the interactive layer can actually run; a data:text/javascript URI validates as VAST and fails as SIMID.

Top comments (0)