---
title: c15t vs OneTrust
description: Choose c15t to own the consent engine, framework components and
  backend. Compare OneTrust's headless API, cookie scans and broader privacy
  operations.
group: reference
lastModified: "2026-10-11T22:43:08+01:00"
---
## Choose c15t to own the engine as well as the interface

c15t is the stronger fit when your product team wants consent in its codebase and control over the backend. Its open-source engine, native components and vendor integrations work together.

OneTrust offers extensive consent operations and a server-side API for custom interfaces. The reason to choose c15t is control of the implementation, not exclusive access to headless consent.

## Let Inth run your consent backend

You need a backend to store consent records outside the visitor's browser. [Inth](https://inth.com) builds c15t and hosts that backend and its database for c15t's framework integrations, browser package and headless API. Your consent interface and vendor controls stay in your application.

Connect your application to an Inth project with the [framework setup guide](/docs/frameworks). Inth also serves your consent policy, so static sites can use it without their own application server.

Offline mode keeps choices on the visitor's device and creates no remote consent records. Use it for development and tests, not production.

You can [self-host the c15t backend](/docs/self-host/overview) when your team needs to operate the service. Your team then owns the database, backups, updates and availability.

## Compare the features that matter

|What you need|c15t|OneTrust|
|--|--|--|
|Build application consent UI|Native components, themes and headless APIs|Web CMP UI and a headless Server-Side CMP API|
|Resolve consent on the server|Framework helpers and cached public policy|Server-Side CMP API|
|Read or change consent in code|Reactive framework state and actions|JavaScript methods and consent-change callbacks|
|Control vendor execution|Declared integrations, request rules and embeds|Automatic blocking, tag-manager integrations and script controls|
|Own the backend implementation|Apache-2.0 backend that you can deploy|OneTrust platform and APIs|
|Store consent records|Inth hosts the backend and stores records in its database. Self-hosting is optional|Consent transaction database|
|Scan authenticated or hidden pages|**Not included in the c15t packages**|Documented website scans|
|Compare banner layouts|Presentation experiments with your feature flags|A/B tests and template targeting|
|Run a wider privacy programme|**No complete privacy operations suite in c15t**|Separate OneTrust products extend the consent scope|

Sources: [Cookie Consent](https://www.onetrust.com/products/cookie-consent/), [JavaScript methods](https://developer.onetrust.com/onetrust/docs/javascript-api) and [Server-Side CMP API](https://developer.onetrust.com/onetrust/docs/server-side-cmp-api-introduction).

## Keep the implementation under your team's control

Your developers can read, change and version c15t's [Apache-2.0 source](https://github.com/c15t/c15t/blob/v3/LICENSE.md). The consent interface can use the same components and release process as the product.

A privacy settings screen can read the same state that controls a video embed or analytics integration. Use [headless APIs](/docs/frameworks/react/headless) when the stock interface does not fit.

OneTrust's headless API also lets teams build their own UI. c15t adds an engine and backend implementation that your team can run and change.

## Choose how consent affects the page

With c15t, a server can cache a public consent manifest, the document that contains the policy rules. A warm cache lets it resolve visitor inputs without a separate policy lookup for each page request.

Backend refreshes and consent saves still need a connection. See [data fetching](/docs/concepts/data-fetching).

In the Next.js App Router, the default streamed path lets the page appear first and sends the banner in a later chunk, before hydration. Await consent when the page and the banner must arrive together. That choice adds a wait.

These [rendering options](/docs/frameworks/next/rendering) let your team choose the tradeoff. Neither an API nor server rendering proves a speed advantage without a comparable test.

## What c15t does not include

* **OneTrust's website inventory service.** c15t does not crawl authenticated routes or automatically discover every tracker.
* **A full privacy operations platform.** Data-subject request case management, data discovery and organisation-wide assessments are outside the c15t packages.
* **A replacement for every current consent workflow.** Check identity, record retention, administrative access and migration needs separately.
* **Backend operations at no cost.** Inth has service terms. Your own deployment needs a database, backups and maintenance.

c15t's [document snapshot helpers](/docs/self-host/guides/legal-document-snapshot-integration) let your server check a legal-document version. They do not generate legal text or prove acceptance without an implemented acceptance flow.

## Start with the part of consent your product owns

Choose c15t when the project needs application control and backend ownership. OneTrust can be the better overall fit when a wider privacy programme is the main requirement.

Build a trial with [Inth and the framework guide](/docs/frameworks). Use a signed-in route that adds a vendor after a user action.

Register that vendor, then check rejection, acceptance, withdrawal and the saved record. Use the [verification guide](/docs/guides/verify-consent), and cost any separate inventory service that you still need.

Sources checked on 6 October 2026. The release covered here is an alpha. This page makes no claim of certification parity or a lower total price.
