Google IMA view and click templates keep their opaque signatures.
Official IMA sample responses show pcs/view and pcs/click tracker fields. The pack distinguishes their endpoint shapes and checks template completeness.
Generated xai, sai and sig values remain opaque. A clean template cannot establish cryptographic validity or account state.
Apply the contracts within their published source scope.
Generated xai, sai and sig values remain opaque. A clean template cannot establish cryptographic validity or account state.
What this pack matches
Rules
Codes are stable. A finding in CI, MCP, or the playground lands on the same id.
| Field | Required | What it checks | Rule ids | Source |
|---|---|---|---|---|
xai |
recommended | Nonempty opaque signed field in the official IMA sample response. Only template completeness is observable. | vendor.google-ima-pcs.param.xai.missingvendor.google-ima-pcs.param.xai.empty |
docs |
sai |
recommended | Nonempty opaque signed field in the official IMA sample response. Only template completeness is observable. | vendor.google-ima-pcs.param.sai.missingvendor.google-ima-pcs.param.sai.empty |
docs |
sig |
recommended | Nonempty opaque signed field in the official IMA sample response. Only template completeness is observable. | vendor.google-ima-pcs.param.sig.missingvendor.google-ima-pcs.param.sig.empty |
docs |
adurl |
optional | Optional source-generated callback field. Empty adurl is explicitly emitted by the official view template. | docs | |
uach_m |
optional | Optional source-generated callback field. Empty adurl is explicitly emitted by the official view template. | docs | |
fbs_aeid |
optional | Optional source-generated callback field. Empty adurl is explicitly emitted by the official view template. | docs |
Validate a payload
pixellint validate url "$ARTIFACT" --rulepack vendor/google-ima-pcs
Or paste it into the playground. Same engine, in the browser, nothing sent anywhere.
cargo install pixellint
·
npm install pixellint