HMAC-SHA256 Consent Cookie | Consenta

HMAC-SHA256 Consent Cookies — Real Cryptography for Tamper-Proof Consent

Since v1.7.0, Consenta signs every consent cookie with real HMAC-SHA256 and the WordPress AUTH_KEY. Server-side verification via hash_equals() makes timing attacks impossible — unsigned cookies are consistently rejected.

14-day money-back · Cancel anytime · GDPR-compliant · Local in WordPress

Consenta WordPress Cookie Consent Dashboard
LAUNCH DEAL — LIMITIERTLAUNCH DEAL — LIMITED Agency Lifetime + White-Label — 149 € 499 € Agency Lifetime + White-Label — 149 € 499 € Jetzt sichern →Get the deal →
HMAC-SHA256
Signature
AUTH_KEY
WordPress Key
hash_equals
Timing-safe
v1.7.0
Upgrade

What is an HMAC-SHA256-signed Consent Cookie?

An HMAC (Hash-based Message Authentication Code) is a cryptographic method that ensures data integrity. Since Consenta v1.7.0, every consent cookie is signed with real HMAC-SHA256 — using the WordPress AUTH_KEY as the secret key. If the cookie is tampered with in the browser — e.g. to unlock blocked categories — the server detects the invalid signature via hash_equals() and discards the cookie. Unsigned cookies are rejected entirely. The user must consent again. Note: The previous djb2-based signature from v1.6.x is only accepted as a legacy fallback for migrating existing cookies and is considered deprecated.

Features

HMAC Consent Cookie in Detail

HMAC-SHA256 with WordPress AUTH_KEY

Since v1.7.0, real HMAC-SHA256 is used with the WordPress AUTH_KEY. The secret key is unique per WordPress installation — only this server can create valid signatures.

hash_equals() — Timing-Attack Protection

Signature verification uses hash_equals() instead of direct string comparison. This makes timing attacks — where an attacker could infer the key by measuring response times — impossible.

Unsigned cookies are rejected

Cookies without a valid HMAC-SHA256 signature are consistently rejected since v1.7.0. Only the legacy fallback for djb2-signed cookies from v1.6.x is still accepted for migration.

Automatic renewal

When tampering is detected or the signature is invalid, the cookie is deleted and the consent dialog is shown again. The user must give their consent anew.

No plain text cookie

The consent data in the cookie is protected against any tampering by the HMAC signature. Changing even a single character immediately invalidates the signature.

Seamless v1.7.0 migration

Existing djb2-signed cookies from v1.6.x are recognized as legacy fallback during migration and automatically replaced by new HMAC-SHA256 cookies on the next consent.

How it works

HMAC-SHA256 Consent Cookie in 3 Steps

1

Automatically active (v1.7.0+)

HMAC-SHA256 signing is active by default — since v1.7.0 with real HMAC and WordPress AUTH_KEY. You don't need to configure anything.

2

Cookie is HMAC-SHA256-signed

When the user gives consent, the cookie is signed with real HMAC-SHA256. The WordPress AUTH_KEY serves as the secret key.

3

Server verifies via hash_equals()

On every page load, the server checks the signature via hash_equals(). Unsigned or tampered cookies are rejected, the consent dialog is shown again.

Pricing

Subscribe monthly or pay once.

LAUNCH DEAL — LIMITED
Agency Lifetime + White-Label — 499 € 149 €
All Agency features incl. White-Label Addon — unlimited sites, custom branding.
Get Bundle
STARTER
Starter
6
/month
cancel monthly · 1 WordPress site
54
/year
4.5 €/mo · 3 months free
  • 1 WordPress site
  • Consent dialog & banner
  • Cookie & script blocking
  • Cookie scanner
  • Google Consent Mode v2
  • IAB TCF 2.2
  • GPC signal (Do Not Sell)
  • Live editor (colors, logo)
  • Import/export
  • Browser API Blocking
  • Webhooks
  • Email support
Buy now

Cancel anytime

AGENCY & FREELANCER
Agency
20
/month
cancel monthly · unlimited sites
180
/year
15 €/mo · 3 months free
  • Unlimited WordPress sites
  • Everything in Pro
  • Multi-site central dashboard
  • REST API access
  • Branded reports
  • Custom consent texts
  • Dedicated support
  • + White-Label Addon from 20 €/month · available separately
Start Agency

Cancel anytime · 14-day money back

FAQ

Questions about the HMAC-SHA256 Consent Cookie

What is HMAC-SHA256 and how does it differ from djb2?
HMAC-SHA256 is a cryptographically secure signing method that combines a secret key (the WordPress AUTH_KEY) with a SHA-256 hash. The previous djb2 method from v1.6.x is a simple checksum without cryptographic strength and is considered deprecated since v1.7.0 — it is only accepted as a legacy fallback for existing cookies.
Does HMAC-SHA256 make the cookie larger?
Minimally. The HMAC-SHA256 signature adds 64 characters (32 bytes hex-encoded) to the cookie. This is negligible and has no impact on performance.
What does hash_equals() mean for security?
hash_equals() is a PHP function that compares strings in constant time — regardless of how early the strings differ. This prevents timing attacks where an attacker could infer the secret key by measuring the comparison duration.
What happens to existing cookies after updating to v1.7.0?
Existing djb2-signed cookies from v1.6.x are recognized as legacy fallback and continue to be accepted. On the next consent event, the cookie is automatically replaced by a new HMAC-SHA256-signed cookie. The migration happens seamlessly without user intervention.
Cookie Blocking Consent Dialog Cookie Banner Consent Widget Google Consent Mode v2 Local Google Fonts IAB TCF Cookie Scanner Consent Logs Geolocation Multi-Site White-Label A/B Testing Statistics Per-Service Consent WooCommerce WCAG 2.1 AA Auto-Scan Multi-Language REST API Consent Proof IP Anonymisation Gutenberg Block CMP Import Consent History Service Worker Blocking CCPA / CPRA CSV Export Webhooks RTL Support WP Privacy Tools PDF Export Browser API Blocking Security GDPR Compliant All Features

Consent cookies. HMAC-SHA256. Tamper-proof.

HMAC-SHA256 · WordPress AUTH_KEY · hash_equals() · Timing-attack-safe · Unsigned cookies rejected · GDPR-compliant

Get started — from 6 €/mo All features

14-day money-back guarantee · Cancel anytime · Available in 34 languages