Installation & Activation
Consenta is installed as a standard WordPress plugin. You need WordPress 5.8+ and PHP 7.4+.
Install Plugin
Log in at My Account and download the latest consenta.zip.
Go to WordPress Admin → Plugins → Add New → Upload Plugin. Select the ZIP file and click Install Now.
Click Activate Plugin. Consenta will appear in the left menu under Consenta.
Go to Consenta → Settings → License and enter your license key (from the confirmation email).
Activate License
Find your key in the confirmation email (format: CONSENTA-XXXX-XXXX-XXXX) or at My Account → Licenses.
Open Consenta → Settings → License, paste the key and click Activate.
After successful activation the dashboard shows Active and your plan (Starter / Pro / Agency).
Run Cookie Scan
The cookie scanner automatically searches your website for all set cookies and categorizes them into the 6 standard categories.
Go to Consenta → Cookie Scanner and click Start Scan. The scanner searches all pages of your website.
After the scan you see all found cookies with name, provider, category and duration. Review the automatic categorization.
Change the category of individual cookies via dropdown if needed. The 6 categories are: Necessary, Functional, Statistics, Marketing, Preferences and Other.
Customize Dialog / Banner / Widget
Consenta offers three consent elements: the consent dialog (modal), the cookie banner and the privacy widget (toggle). All are configurable under Consenta → Appearance.
Manage Consent Categories
Consenta uses 6 standard categories for granular cookie management:
| Category | Description |
|---|---|
| Necessary | Technically required cookies (always active, not deselectable) |
| Functional | Cookies for enhanced functionality (e.g. language, region) |
| Statistics | Analytics cookies (e.g. Google Analytics, Matomo) |
| Marketing | Advertising and remarketing cookies (e.g. Facebook Pixel, Google Ads) |
| Preferences | Cookies for personal settings (e.g. theme, layout) |
| Other | Uncategorized cookies |
Google Fonts — GDPR-compliant self-hosted v1.12
Since version 1.12.0 you can pick a Google font in the dialog or banner editor — and Consenta makes sure it is delivered fully GDPR-compliant, without IP address transfer to Google. The LG München 2022 ruling (3 EO 1361/21) is automatically satisfied.
Pick a font
Under Consenta → Settings → Dialog (or Banner) you find the Font field. Pick the entry "Google Font (GDPR-compliant self-hosted)".
A picker with 160 curated families opens (Inter, Roboto, Open Sans, Poppins, Montserrat, Playfair Display, Lora, Noto Sans JP/KR/SC, Cairo, Vazirmatn …). Search field + category filter (sans-serif / serif / display / handwriting / monospace) — live preview with the actual font.
Click Save: Consenta downloads the woff2 files (latin + latin-ext subsets) and CSS locally to wp-content/uploads/consenta-fonts/{slug}/. The same directory holds the OFL or Apache-2.0 license file (deployment requirement per OFL §3 / Apache §4(a)).
Use a different Google font (all 1500+)
If the top-160 selection isn't enough, click "Use other Google font" in the picker and type any slug from the Google Fonts catalogue (crete-round, roboto-flex, playfair-display-sc, noto-sans-display …). Consenta derives the family name from the slug and downloads it on next save. Non-existent fonts produce a concrete error.
How zero requests to Google are guaranteed
- On the frontend the CSS loads from your own domain (
wp-content/uploads/consenta-fonts/{slug}/{slug}.css) — the @font-face declarations point to local woff2 files. - There are no connections to
fonts.googleapis.comorfonts.gstatic.comon the frontend. The visitor IP stays with you. - In the admin area the Google CDN is loaded for the picker preview — legally unproblematic because the admin is a data subject of their own site and consciously works with the editor.
Auto-verify: protection against lost downloads
On every Consenta admin page load, Consenta checks whether the selected fonts are actually present locally. If a family's CSS is missing (e.g. because the initial save hit a PHP timeout or a brief outbound block), the download is silently re-attempted. If that also fails, a red admin notice surfaces with the concrete error (HTTP code, missing write permission, SSL cert problem) — no more silent fallback to system-ui.
cURL error 60: SSL certificate problem (broken CA bundle on local dev hosts or corporate proxies) Consenta retries the download once automatically with sslverify=false. The downloaded content is static fonts without credentials, woff2 URLs are whitelisted against fonts.gstatic.com — MITM risk is bounded.Manage Languages v1.8
Consenta ships all dialog, banner and widget texts in 34 languages out of the box. The current language is detected automatically via URL prefix (/en/, /fr/, …), consenta_lang cookie or WordPress locale — nothing to configure, it just works.
Customize texts
Under Consenta → Settings → Languages you find all 34 languages. Each shows its status: Default (unchanged) or X/20 customized (when you have overridden texts).
Expand the target language with "Edit" — 20 fields appear (title, description, button labels, category names, banner text etc.). Each customized field is marked with an orange border and asterisk.
Click Save to persist your changes. The dedicated consent-text hash ensures material text changes are captured in the audit trail without invalidating existing consents.
The Reset button discards all customizations for this language and reverts to the shipped defaults.
Automatic translation
In the top-right of the Languages tab you find the Translation source dropdown — defaults to German. When you open another language for editing, a small grey line with the source text appears under each field, plus a 🌐 icon for single-field translation.
The 🌐 Translate all from source button at the bottom translates all non-customized fields with one click — sequentially with a progress indicator to stay within MyMemory's free API quota. Customized fields (orange border) are skipped by default. A confirm dialog offers to override if you want to translate them anyway.
MyMemory translation service
For auto-translation MyMemory is used — free, no API key, no signup. Your site's admin email is sent as identification parameter, raising the anonymous daily limit (~5,000 chars) to ~50,000 chars/day. For most sites that's enough to fill all 20 fields × active languages.
Rich Text Editor for long texts v1.8
The three long-text fields consent-text (dialog description), banner-text (banner content) and blocked-content-desc (blocked placeholder text) use a full TinyMCE editor with toolbar — instead of a single-line text input.
Available formatting
- Bold, Italic, Underline
- Bullet lists and numbered lists
- Insert / remove link (with
target,rel) - Paragraphs (
<p>) and line breaks - Remove formatting, Undo/Redo
- Switch to Text/Code view (edit HTML directly)
<a href>, <strong>, <em>, <b>, <i>, <u>, <br>, <span class>, <p class>. <script>, <style>, inline events and style="" attributes are stripped for security.Performance
The editor loads lazily — TinyMCE instances are created only when you click "Edit" on a language and torn down when you close. Without this lazy pattern, 34 languages × 3 long-text fields would mean 102 editor instances loaded at once — the admin would freeze.
Translate Cookie Declaration v1.8
The [consenta_cookies] shortcode renders the table of all cookies, domains and resources — typically on your privacy page. Descriptions and lifespans are now output language-aware.
Lifespans: automatic in 9 languages
Lifespan strings follow a fixed vocabulary ("2 Jahre", "30 Tage", "Session / 1 Jahr") and are deterministically regex-translated — no API call, no cache, instant and reliable:
| DE | EN | FR | ES | IT |
|---|---|---|---|---|
| 2 Jahre | 2 years | 2 ans | 2 años | 2 anni |
| 30 Tage | 30 days | 30 jours | 30 días | 30 giorni |
| 24 Stunden | 24 hours | 24 heures | 24 horas | 24 ore |
| Session | Session | Session | Sesión | Sessione |
Descriptions: 3-tier fallback
When the cookie entry already has a multilingual object {de:…, en:…} (from bulk translation), the matching language slot is output directly.
Around 80 of the most common cookies and domains (Google Analytics, Meta/Facebook, YouTube, Stripe, Paddle, Cloudflare, WooCommerce, WordPress core, reCAPTCHA …) have hand-translated EN descriptions built into the plugin. Wildcard pattern: _ga_* also matches runtime-generated names like _ga_ABC123.
If neither a stored nor a dictionary entry exists, the original description (in the language it was saved — typically German) is output instead of an empty cell.
Bulk translation in admin
In each entity tab (Consenta → Cookies / Domains / Resources) you find the bar at the top Translate: DE → English (EN) with source dropdown, target dropdown (all 34 languages) and the 🌐 Translate descriptions button. One click translates all descriptions in that tab:
- Batches of 3 entries per request with progress display
- Already translated fields are skipped (idempotent — run as often as you want)
- Stored as object
{de: "Text", en: "Text", fr: "Text"}— each row then shows small badges of filled languages - Results cached 30 days in transients — identical texts don't cost quota twice
[consenta_cookies] then auto-renders the correct language based on /en/-, /fr/-, /es/-URL.Inline edit preserves translations
When you inline-edit a description that is already multilingually stored, the plugin updates only the DE slot. EN/FR/ES translations are preserved — no need to re-translate.
Google Consent Mode v2
Google Consent Mode v2 is fully supported. Consenta automatically sends the correct consent signals to Google services.
Setup
Under Consenta → Settings → Google Consent Mode enable the toggle.
Consenta automatically sets: ad_storage, analytics_storage, ad_user_data and ad_personalization based on the visitor consent decision.
Configure IAB TCF
The IAB Transparency & Consent Framework 2.0 is fully supported. TC strings are automatically generated and managed.
Under Consenta → Settings → IAB TCF enable the toggle.
Select the relevant IAB vendors for your website. The TC string is generated automatically.
Enable Geolocation
Shows the consent dialog only to visitors from the EU or configurable regions. Visitors outside the configured regions see no banner.
Under Consenta → Settings → Geolocation enable the toggle.
Select the countries/regions where the consent dialog should be shown. Default: all EU countries.
Service Worker Blocking v1.4
Consenta uses a three-layer blocking mechanism that intercepts cookies and scripts before execution. Service Worker Blocking is the third and deepest layer and activates automatically in full-consent mode.
The 3 Blocking Layers
| Layer | Description |
|---|---|
| Layer 1 — Script Blocking | Blocks known third-party scripts based on a blocklist before they are inserted into the DOM. |
| Layer 2 — Cookie Blocking | Monitors document.cookie via setter override and prevents writing unapproved cookies. |
| Layer 3 — Service Worker | Intercepts outgoing network requests at the service worker level and blocks requests to tracking endpoints before they leave the browser. |
Browser API Blocking v1.5
In full-consent mode, Consenta overrides specific browser APIs to ensure that push notifications, background sync and cache access are only possible after consent is given.
Blocked APIs
| API | Description |
|---|---|
| Notification.requestPermission | Prevents browser push notification dialogs until consent is given |
| PushManager.subscribe | Blocks registration of web push subscriptions |
| SyncManager.register | Prevents registration of background sync tasks |
| caches.open | Blocks access to the Cache Storage API (except for whitelisted prefixes) |
Whitelisted Cache Prefixes
The following cache prefixes are exempt from blocking and are always allowed:
consenta— Consenta-internal cacheswp-— WordPress core caches (e.g. wp-offline)workbox— Workbox service worker caches
Automatic Restoration
As soon as a visitor gives consent, all blocked APIs are automatically restored. Pending calls are not replayed — they must be re-executed by the application after consent.
Webhooks v1.5
Consenta can send real-time HTTP POST notifications to one or more configured HTTPS URLs when consent events occur. This lets you integrate consent events into external systems, CRMs or analytics pipelines.
Setup
Go to Consenta → Settings → Webhooks and enter an HTTPS URL. Only HTTPS endpoints are accepted.
Select which consent events should be sent to the endpoint: consent.new, consent.update, consent.revoke or consent.optout.
Click Send Test to send a test payload to the configured URL and verify the connection.
Supported Events
| Event | Description |
|---|---|
| consent.new | Visitor gives consent for the first time |
| consent.update | Visitor updates their existing consent |
| consent.revoke | Visitor fully revokes their consent |
| consent.optout | Visitor rejects all non-necessary categories |
Signature Verification (HMAC-SHA256)
Every webhook payload is signed with HMAC-SHA256. The signature is sent in the X-Consenta-Signature header. Verify it server-side to ensure payload authenticity:
$secret = 'your-webhook-secret';
$payload = file_get_contents('php://input');
$sig = $_SERVER['HTTP_X_CONSENTA_SIGNATURE'];
$expected = 'sha256=' . hash_hmac('sha256', $payload, $secret);
if (!hash_equals($expected, $sig)) { http_response_code(401); exit; }
Payload Structure
"event": "consent.new",
"uid": "a1b2c3d4e5",
"timestamp": 1713200000,
"categories": ["necessary", "functional", "statistics"],
"site_url": "https://example.com",
"version": "1.5"
}
WooCommerce v1.4
The WooCommerce integration automatically detects all cookies set by WooCommerce and assigns them to the correct consent categories. Tracking cookies from WooCommerce Analytics and marketing extensions are loaded only after consent.
Automatically Blocked Elements
- WooCommerce Analytics — Tracking cookies (
wp_woocommerce_session_*) are assigned to the Statistics category. - Marketing pixels — Facebook Pixel, Google Ads Conversion and other remarketing scripts are blocked until marketing consent is given.
- Session cookies — Cart and session cookies are categorized as Necessary and never blocked.
Declared Cookies
| Cookie | Category | Description |
|---|---|---|
| woocommerce_cart_hash | Necessary | Cart hash for cache invalidation |
| woocommerce_items_in_cart | Necessary | Stores whether items are in the cart |
| wp_woocommerce_session_* | Functional | Unique session ID for checkout |
| tk_ai | Statistics | WooCommerce Analytics tracking identifier |
Filter Hook for Developers
Use the consenta_woo_cookie_map filter to override the automatic categorization of WooCommerce cookies:
// Eigene Zuordnung hinzufügen / Override mapping
$map['my_custom_cookie'] = 'marketing';
return $map;
});
Gutenberg Blocks v1.11
Consenta ships four native Gutenberg blocks — all on block API v3 (WordPress 6.9 compatible) and bundled in their own "Consenta" category in the block inserter. Open the block inserter, search for "Consenta" or look at the top of the category list.
Cookie Declaration
Renders an auto-generated table of all cookies, domains and resources — perfect alternative to the [consenta_cookies] shortcode on your Cookie Declaration page. Attributes in the right sidebar: filter by purpose (e.g. Marketing only), toggle "Type" and "Lifespan" columns.
Consent Status
Shows the visitor their current consent status: per category a ✓ (accepted) or ✗ (rejected), plus the date of last consent and optionally an "Edit settings" button that reopens the dialog. Two display variants: Card (bordered) or inline.
Conditional Content
The most powerful block in the suite — shows or hides nested content depending on consent status. Ideal for videos, maps, tracking pixels.
The editor shows two tabs: Conditional (appears after consent) and Fallback (appears before consent). Both tabs are real InnerBlocks zones — you can drop any blocks in: images, groups, columns, custom embeds. The inactive tab remains saved, only visually hidden.
Select an existing block (YouTube embed, map, …), click Transform to → Conditional Content in the block menu — the block moves automatically into the Conditional slot, the Fallback stays empty for you to fill. Analogous to the core Group block.
In the right sidebar under Consent condition → Required category you set which consent purpose must be active: Functional, Statistics, Marketing or Media. Essential is not available — it's always granted and would defeat the purpose.
CMP Accept Button
Standalone button block to grant consent for a specific purpose or to reopen the consent dialog. Can be placed anywhere in the post — especially in the Fallback slot of Conditional Content, where it automatically inherits the purpose via block context. Full block toolbar: alignment, background/text color, gradient, font size, font family, padding, margin, border and radius.
In the sidebar under Action choose between "Accept purpose" (grants consent for a category) and "Open dialog" (reopens the consent dialog, ideal for "Edit settings" buttons).
If you place the button in the Fallback slot of a Conditional Content block, it inherits the configured purpose automatically via block context — no double-configuration needed. Outside, set the purpose manually via Purpose override.
Two style presets Primary (brand color, filled) and Secondary (outline, transparent) — fully overridable via the block toolbar if desired. The label is RichText-editable directly in the editor ("Accept", "Open settings", …).
data-consenta-accept-purpose="marketing" (or other categories) is still available — e.g. on custom buttons outside the block editor.CMP-Import v1.4
Migrate your existing cookie configuration from CookieBot, OneTrust, Usercentrics, Borlabs Cookie, Complianz or GDPR Cookie Compliance to Consenta in a few clicks. The importer transfers cookie lists, categories and descriptions.
Supported CMPs
- CookieBot — CSV export from the Cookiebot dashboard
- OneTrust — JSON export from the OneTrust administration
- Usercentrics — CSV export from the Usercentrics dashboard
- Borlabs Cookie — Detected automatically, no export needed (direct DB access)
- Complianz — Detected automatically, no export needed (direct DB access)
- GDPR Cookie Compliance — Detected automatically, no export needed (direct DB access)
Step-by-Step Guide
Export your cookie list from CookieBot (CSV), OneTrust (JSON) or Usercentrics (CSV). For Borlabs Cookie, Complianz and GDPR Cookie Compliance, Consenta detects the installed CMP automatically — no export needed.
Go to Consenta → Tools → CMP-Import and select your previous CMP from the dropdown.
Upload the exported file. Consenta detects the format automatically and shows a preview of the cookies to import.
Review the automatic category mapping. The 6 Consenta categories are mapped to the categories of the previous CMP. Adjust individual mappings if needed.
Click Import. Existing cookies are not overwritten, new ones are added.
Auto-Scan v1.4
Auto-Scan runs the cookie scan automatically at regular intervals and notifies you via email when new cookies are found.
Setup
Go to Consenta → Cookie Scanner → Auto-Scan and enable the toggle.
Choose the scan interval: Daily, Weekly or Monthly. Default: Weekly.
Enter one or more email addresses (comma-separated). You will receive an email when new or unknown cookies are found.
Consent-Proof v1.4
Generate a PDF report as proof of your GDPR-compliant cookie consent configuration. The report is suitable for audits, data protection officers and authority requests.
Generate PDF Report
Go to Consenta → Logs → Consent-Proof.
Select the time range for the report (e.g. last 30 days, quarter or custom).
Click Generate PDF. The report is created and provided as a download.
Report Contents
- Consent statistics — Acceptance rate, rejection rate, opt-in rate per category
- Cookie inventory — Complete list of all declared cookies with category, provider and duration
- Blocking configuration — Active blocking level and service worker status
- Consent log excerpt — Anonymized sample of recent consent entries as proof
- Configuration overview — GCM status, TCF status, geolocation settings, dialog configuration
Logs & Reports
Consenta logs every consent decision for GDPR proof-of-consent requirements. Under Consenta → Logs you find all entries.
Multi-Site Dashboard
Manage cookie consent settings for all your WordPress sites centrally. Consent statistics for all sites at a glance.
Consenta → Sites → Copy Site Token (generated on the main site).
On the remote site: Consenta → Settings → Multi-Site → Paste token and enter main site URL.
Click Test Connection. The remote site now sends consent data to the main site.
REST API v1.4
The REST API enables programmatic management of consent settings, cookie lists, logs and remote sites. All endpoints use the namespace /wp-json/consenta/v1/.
Authentication
All endpoints (except /log) require authentication. Generate an API token under Consenta → Settings → API and send it as a Bearer token in the Authorization header:
POST /consenta/v1/log
Stores a consent entry. This endpoint is called automatically by the frontend script and requires no authentication (public).
| Parameter | Typ | Description |
|---|---|---|
| categories | array | Accepted consent categories, e.g. ["necessary","statistics"] |
| uid | string | Anonymous visitor identifier (generated by frontend) |
| timestamp | integer | Unix timestamp of the consent decision |
| user_agent | string | Browser user agent (optional, otherwise read from request) |
| tcf_string | string | IAB TCF TC string if TCF is active (optional) |
POST /wp-json/consenta/v1/log
Content-Type: application/json
{
"categories": ["necessary", "functional", "statistics"],
"uid": "a1b2c3d4e5",
"timestamp": 1713200000
}
GET /consenta/v1/config
Returns the current consent configuration (cookie list, categories, dialog settings, blocking level). Requires API token.
| Response Field | Typ | Description |
|---|---|---|
| cookies | array | List of all declared cookies with name, category, provider, duration |
| categories | array | Configured consent categories with label and description |
| blocking_level | integer | Active blocking level (1–3) |
| gcm_enabled | boolean | Google Consent Mode v2 active |
| tcf_enabled | boolean | IAB TCF active |
| dialog_type | string | Dialog type: modal, banner or widget |
GET /wp-json/consenta/v1/config
Authorization: Bearer sk_live_xxxxxxxxxxxxx
POST /consenta/v1/revoke
Revokes a visitor consent by UID. Useful for data deletion requests (GDPR Art. 17). Requires API token.
| Parameter | Typ | Description |
|---|---|---|
| uid | string | Anonymous visitor identifier whose consent should be revoked (required) |
| reason | string | Reason for revocation, e.g. user_request or gdpr_erasure (optional) |
POST /wp-json/consenta/v1/revoke
Authorization: Bearer sk_live_xxxxxxxxxxxxx
Content-Type: application/json
{ "uid": "a1b2c3d4e5", "reason": "gdpr_erasure" }
GET /consenta/v1/stats
Returns aggregated consent statistics. Requires API token.
| Query Parameter | Typ | Description |
|---|---|---|
| from | string | Start date in format YYYY-MM-DD (optional, default: 30 days ago) |
| to | string | End date in format YYYY-MM-DD (optional, default: today) |
| group_by | string | Grouping: day, week or month (optional, default: day) |
| Response Field | Typ | Description |
|---|---|---|
| total_decisions | integer | Total number of consent decisions in the period |
| accept_rate | float | Acceptance rate (0.0–1.0) |
| reject_rate | float | Rejection rate (0.0–1.0) |
| category_rates | object | Opt-in rate per category, e.g. {"statistics": 0.72, "marketing": 0.34} |
| timeline | array | Time series with data points per group_by interval |
GET /wp-json/consenta/v1/stats?from=2026-03-01&to=2026-03-31&group_by=week
Authorization: Bearer sk_live_xxxxxxxxxxxxx
GET /consenta/v1/remote/settings
Retrieves the consent settings of a connected remote site. Used by the multi-site dashboard. Requires API token + remote token.
| Header | Description |
|---|---|
| Authorization | Bearer <api-token> — API token of the main site |
| X-Consenta-Remote-Token | <remote-token> — Token of the remote site (generated under Consenta → Sites) |
GET /wp-json/consenta/v1/remote/settings
Authorization: Bearer sk_live_xxxxxxxxxxxxx
X-Consenta-Remote-Token: rt_abc123def456
GET /consenta/v1/remote/entities
Lists all connected remote sites with status, last sync and consent summary. Requires API token.
| Response Field | Typ | Description |
|---|---|---|
| entities | array | List of remote sites |
| entities[].url | string | URL of the remote site |
| entities[].status | string | Connection status: connected, disconnected, error |
| entities[].last_sync | string | ISO 8601 timestamp of the last sync |
| entities[].total_consents | integer | Total number of stored consent entries for this site |
GET /wp-json/consenta/v1/remote/entities
Authorization: Bearer sk_live_xxxxxxxxxxxxx
Error Codes
| Code | Description |
|---|---|
| 401 | Missing or invalid API token |
| 403 | API access not included in current plan (Agency required) |
| 404 | Resource not found (e.g. unknown UID for /revoke) |
| 422 | Invalid parameters (e.g. missing required field) |
| 429 | Rate limit exceeded (max. 120 requests/minute) |
X-RateLimit-Remaining and X-RateLimit-Reset.White Label Setup
Replace Consenta branding with your own. Configurable under Consenta → Settings → White Label.
RTL-Support v1.4
Consenta supports right-to-left languages (Arabic, Hebrew, Farsi and others) fully automatically. When the HTML attribute [dir="rtl"] is set on the page, all consent elements — dialog, banner, widget and admin dashboard — are automatically mirrored.
dir="rtl" automatically when an RTL language is configured as site language. Consenta detects this and adjusts layout, text alignment and icon positions accordingly.Security v1.7
HMAC-SHA256 Consent Cookie (consenta_auth)
Since v1.7.0, every consenta_auth cookie is server-side signed with HMAC-SHA256. The WordPress AUTH_KEY from wp-config.php is used as the secret — this key is unique per WordPress installation and never leaves the server.
On every consent verification the server recomputes the expected signature and compares it using hash_equals() — this constant-time comparison prevents timing attacks. Cookie manipulation by visitors or browser extensions is reliably detected and rejected.
AUTH_KEY is set in wp-config.php and sufficiently random (at least 64 characters). New WordPress installations generate this automatically. SSRF Protection
Since v1.7.0, all outbound HTTP calls from Consenta (webhook delivery, cookie scanner, geolocation lookup) pass through an SSRF protection check. The following targets are blocked:
- Private IPv4 ranges (RFC1918): 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16
- Loopback: 127.0.0.0/8 and ::1
- Cloud metadata endpoints: 169.254.169.254 (AWS/GCP/Azure Instance Metadata Service)
Token Management
Since v1.7.0, API tokens are stored as SHA-256 hashes in the database — the plaintext token only leaves the server once, immediately after generation. It cannot be retrieved afterwards.
Go to Consenta → Settings → API and click Generate Token. The plaintext token is shown once.
Copy the token and store it securely (e.g. in a password manager). After closing the dialog the plaintext is no longer retrievable.
If a token is lost, revoke it and generate a new one. The old token immediately loses its validity.
Security Best Practices for Hosting
Troubleshooting
Consent dialog not showing
Check: (1) Is the license active? (2) Is the dialog enabled under Consenta → Appearance? (3) Are there JavaScript errors in the browser console? (4) Is a caching plugin active? Clear the cache.
Cookies set despite rejection
Check the blocking level under Consenta → Settings. Level 1 blocks only known cookies. Increase to Level 2 or 3 for more comprehensive blocking. Run a new cookie scan to detect all cookies.
Google Consent Mode not sending signals
Check: (1) Is the GCM toggle enabled under Settings? (2) Is the Consenta script loaded before the GTM script? (3) Check the browser console for errors.
License key not working
Check: (1) No spaces before/after the key. (2) The website URL matches the one used during activation. (3) The license has not expired. If problems persist: Contact support.
FAQ
Does Consenta work with caching plugins?
Yes. Consenta works entirely client-side. Cookie blocking and consent dialog work independently of server-side caching.
Do I need Consenta in addition to Google Consent Mode?
Yes. Google Consent Mode is just the interface — you need a Consent Management Platform (CMP) like Consenta that sends the consent signals.
How many languages are supported?
34 languages. Compatible with WPML and Polylang.
Where do I find my license after purchase?
In the confirmation email and at My Account → Licenses.
Still have questions?
Our support team usually responds within 24 hours.