Cryptographically signed consent cookies prevent tampering and ensure the integrity of every consent.
14-day money-back · Cancel anytime · GDPR-compliant · Local in WordPress
An HMAC (Hash-based Message Authentication Code) is a cryptographic method that ensures data integrity. Consenta signs every consent cookie with an HMAC-SHA256 hash. If the cookie is tampered with in the browser — e.g. to unlock blocked categories — the server detects the invalid signature and discards the cookie. The user must consent again.
Every consent cookie is signed with HMAC-SHA256. The secret key is stored securely on the server — only it can create valid signatures.
Any change to the cookie content invalidates the signature. Tampered cookies are immediately detected and discarded.
On every page load, the server validates the HMAC signature of the consent cookie. Invalid cookies are not accepted.
When tampering is detected, the invalid cookie is deleted and the consent dialog is shown again.
The consent data in the cookie cannot be manipulated in plain text. The HMAC signature protects against any alteration.
The cryptographic signature guarantees that the stored consent status exactly matches what the user selected.
HMAC signing is active by default. You don't need to configure anything — every consent cookie is automatically signed.
When the user gives consent, the cookie is signed with an HMAC-SHA256 hash and stored.
On every page load, the server checks the signature. If it is invalid, the consent dialog is shown again.
Cancel anytime
Cancel anytime · 14-day money back
Cancel anytime · 14-day money back
HMAC-SHA256 · Tamper detection · Server validation · Automatic renewal · GDPR-compliant
14-day money-back guarantee · Cancel anytime · Available in 30+ languages