Analytics
Heap
Configure Heap
Copy the environment ID from your Heap installation snippet. The heap helper
loads that environment's heap_config.js, which then loads the heap.js
runtime. Remove the original Heap snippet.
Register the scripts
Complete your framework quickstart first. Keep its Inth endpoint, policy, styles and consent UI. Remove the vendor's original script, SDK initializer or tag-manager entry, so the vendor loads only through c15t.
The vendor pages put the helper in src/consent-scripts.ts. If your framework
quickstart already has a scripts array, such as the one in c15t.config.ts
in the Next.js guide, add the helper to that array instead of creating a
second file.
The scripts export is a configuration, not an initializer. Add it to the c15t provider you already have, at the registration
point for your framework below. These are edits to that provider, not a second
provider.
Add the configuration to scripts in c15t.config.ts, next to
next.config.ts:
Keep the rest of your config, such as mode and routePrefix, in the
same call. ConsentRoot reads the config in the browser, so the layout
keeps passing only state. App Router, Pages Router and static export all
read the same file. See
Next.js scripts and embeds.
Options
| Option | Default | Behavior |
|---|---|---|
envId | Required | Environment ID. Set as heap.envId and heap.appid, and used in the default loader URL. The helper trims it. Empty values log an error and the script does not load. |
clientConfig | {} | Client configuration set on heap.clientConfig. Values must be JSON-serializable with finite numbers; other values throw a TypeError. The helper always sets shouldFetchServerConfig: false and overrides any value you pass for it. |
scriptUrl | https://cdn.us.heap-api.com/config/<envId>/heap_config.js | Config loader URL override. A blank value falls back to the default. |
Loading and revocation
heap uses the measurement category. When measurement becomes allowed, the
helper creates window.heap with stubs for the heap.js v5 methods, which queue
calls in window.heapReadyCb. Then it loads the config script, and heap.js
replays the queued calls once it is ready.
On revocation the helper removes the config script element and calls no Heap
API. It does not call heap.stopTracking, so heap.js keeps capturing until the
page unloads. If the visitor allows measurement again before the page reloads,
the helper keeps the methods of the running heap.js instead of replacing them
with queue stubs. If you set reloadOnConsentRevoked: false, call
window.heap.stopTracking() from the onConsentChange callback of a
callback-only script. See
custom integrations.
Verify Heap
Filter DevTools Network by heap. After you allow measurement, the
heap_config.js request for your environment ID loads, followed by the heap.js
runtime it selects. window.heap.envId holds your environment ID.
Test in a private window with an opt-in policy. Open DevTools Network, disable the cache and filter by the vendor's domain:
- Load the page. No request goes to the vendor before you choose.
- Click Reject, then reload. There is still no vendor request.
- Open Privacy settings and allow the helper's category. The vendor script loads without a page reload.
- Turn the category off again and save. c15t reloads the page, and the new page makes no vendor request.
c15t reloads on revocation because removing a script element does not stop
code that already ran. The vendor's listeners, timers and queued events stay
alive until the page unloads. If you set reloadOnConsentRevoked: false, stop
the vendor yourself. Register a callback-only script whose onConsentChange
calls the vendor's opt-out API, as shown in
custom integrations, and check the
permission before each of your own event calls. The reload does not delete
cookies the vendor already set; see
clear on revocation for your framework.
The helper sets vendor to its script ID, so once you declare that vendor a
visitor can turn it off inside an allowed category. See
vendor consent for your framework. The
consent verification guide covers navigation,
expiry and hosting checks.