Stable seller-generated identifier for this logical change. Retries and notification re-emissions reuse this identifier.
Time the seller committed or durably observed the change. Feed order is defined by the cursor, not by this timestamp.
Optionaloccurred_Upstream business time when the change occurred, only when the seller can establish it reliably.
Optionalbatch_Optional stable identifier grouping records produced by one committed operation or one external-source ingestion batch. Each independently repairable authoritative identity still receives its own record; batch_id does not change cursor ordering or notification identity.
Stable identity of the changed resource. Resource types are open for forward compatibility. account_id is always present; resource_id identifies the changed entity and parent_ids supplies any IDs needed to disambiguate nested resources.
Open resource-type name such as account, media_buy, package, creative, creative_assignment, delivery_report, audience, event_source, catalog, or account_financials.
Seller-assigned account containing the resource.
Canonical identifier for the resource within its type. For an account change this equals account_id.
Optionalparent_ids?: { [k: string]: string | undefined }Additional canonical parent identifiers needed to repair a nested resource, for example media_buy_id and package_id for a creative assignment. Keys and values MUST NOT contain sensitive payload data.
Material change action. Standard values are created, discovered, updated, status_changed, linked, unlinked, deleted, and purged. Future standard or vendor-namespaced values are allowed; receivers MUST treat unknown values as generic invalidations.
Server-derived origin classification. The seller MUST NOT trust caller-supplied origin or actor claims.
Optionalconnection_id?: stringOpaque, non-secret reference to the connected source when safe for this caller.
Optionalresource_Post-change revision exposed by the repair read, when that resource family defines one.
Optionalchanged_Bounded set of RFC 6901 JSON Pointers naming material fields that changed. Values are intentionally omitted.
Authoritative AdCP read the receiver uses to reconcile current state. The buyer constructs safe request arguments from the structured resource identity. A deleted or legally purged resource may instead declare unavailable with a categorical reason.
Allowlisted authoritative read task. This is a repair hint, never an instruction to dispatch dynamically. The buyer constructs and validates the request locally from the authenticated feed account and resource identity.
Optionalavailable?: booleanFalse when deletion or compelled erasure makes the resource unavailable on the repair read.
Optionalunavailable_reason?: "other" | "deleted" | "legal_erasure" | "purged" | "access_revoked"OptionalactorOptional privacy-safe actor classification. Sellers MUST omit direct personal identifiers unless the authenticated caller is authorized for them.
Optionalid?: stringOpaque, redaction-safe actor reference.
OptionalreasonShort machine-readable reason code, when available.
OptionalsummaryOptional brief, untrusted human-readable summary. MUST NOT contain secrets or sensitive payload data.
OptionalextBounded vendor extensions. The entire encoded change record, including extensions, MUST NOT exceed 64 KiB and remains subject to the same secret/PII prohibitions.
Immutable metadata for one committed material change to account-scoped state recoverable through an authoritative AdCP read. The record is an ordered invalidation and audit aid, not a historical resource snapshot. Sellers MUST NOT include credentials, financial account numbers, raw audience members, raw logged events, webhook bodies, or unbounded before/after values.