Analytics
RudderStack
Configure RudderStack
Copy the source write key and the HTTPS data plane URL from your RudderStack source. Keep control-plane credentials out of the browser.
Register the scripts
Complete your framework quickstart first. Keep its Inth endpoint, policy, styles and consent UI. Remove the vendor's original script, SDK initializer or tag-manager entry, so the vendor loads only through c15t.
The vendor pages put the helper in src/consent-scripts.ts. If your framework
quickstart already has a scripts array, such as the one in c15t.config.ts
in the Next.js guide, add the helper to that array instead of creating a
second file.
The scripts export is a configuration, not an initializer. Add it to the c15t provider you already have, at the registration
point for your framework below. These are edits to that provider, not a second
provider.
Add the configuration to scripts in c15t.config.ts, next to
next.config.ts:
Keep the rest of your config, such as mode and routePrefix, in the
same call. ConsentRoot reads the config in the browser, so the layout
keeps passing only state. App Router, Pages Router and static export all
read the same file. See
Next.js scripts and embeds.
Options
| Option | Default | Behavior |
|---|---|---|
writeKey | Required | Source write key. Surrounding whitespace is trimmed. An empty value logs an error and the script does not load. |
dataPlaneUrl | Required | Data plane URL. A missing, invalid or non-HTTPS URL logs an error and the script does not load. |
consentManagement | None | { mapping } from c15t categories to RudderStack consent IDs. Switches to destination consent mode. |
loadOptions | {} | Third argument to rudderanalytics.load(). Use JSON-serializable values only. |
trackPageView | true | Queues rudderanalytics.page() before the loader. |
scriptUrl | https://cdn.rudderlabs.com/v3/modern/rsa.min.js | Loader URL override. A non-HTTPS URL throws; a blank value uses the default. |
Loading and revocation
rudderstack uses the measurement category. consentManagement picks the
mode:
| Mode | Loads | On consent change | On revocation |
|---|---|---|---|
| Default | After measurement is allowed, with load and page queued | Nothing | Removes the script element and calls no RudderStack API |
consentManagement | On every page, in RudderStack's pre-consent state | Calls rudderanalytics.consent() with the mapped IDs | Keeps the SDK and calls consent() with the revoked IDs denied |
Map destination consent
consentManagement loads the RudderStack SDK before the visitor chooses. Use
it only when every destination in your workspace carries a consent ID from the
mapping; c15t cannot check destination settings from the browser. Add the
mapping to the helper call:
The helper sets preConsent.enabled, buffered event delivery and
consentManagement.provider: 'custom' in the load options. Storage defaults to
{ strategy: 'none' }; a preConsent.storage value in loadOptions replaces
it. Before load, the helper queues a consent() call. IDs of allowed
categories go to allowedConsentIds and IDs of denied categories go to
deniedConsentIds. A visitor who turns off the rudderstack vendor gets every
mapped ID denied. An empty mapping, or a category with no non-blank IDs, throws.
Verify RudderStack
In the default mode, allowing measurement loads rsa.min.js with a
data-rsa-write-key attribute, and a page event goes to your data plane URL.
Test in a private window with an opt-in policy. Open DevTools Network, disable the cache and filter by the vendor's domain:
- Load the page. No request goes to the vendor before you choose.
- Click Reject, then reload. There is still no vendor request.
- Open Privacy settings and allow the helper's category. The vendor script loads without a page reload.
- Turn the category off again and save. c15t reloads the page, and the new page makes no vendor request.
c15t reloads on revocation because removing a script element does not stop
code that already ran. The vendor's listeners, timers and queued events stay
alive until the page unloads. If you set reloadOnConsentRevoked: false, stop
the vendor yourself. Register a callback-only script whose onConsentChange
calls the vendor's opt-out API, as shown in
custom integrations, and check the
permission before each of your own event calls. The reload does not delete
cookies the vendor already set; see
clear on revocation for your framework.
The helper sets vendor to its script ID, so once you declare that vendor a
visitor can turn it off inside an allowed category. See
vendor consent for your framework. The
consent verification guide covers navigation,
expiry and hosting checks.
With consentManagement, the SDK loads before the choice, so check your
destinations instead. Test in a private window with an opt-in policy:
- Load the page.
rsa.min.jsloads before you choose. Destinations whose consent IDs map to a denied category receive no events. - Open Privacy settings and allow measurement. Without a reload, destinations with measurement IDs start receiving events. Destinations mapped only to marketing still receive none.
- Turn measurement off and save. c15t reloads the page, and destinations with measurement IDs receive no events from the new page.
See the consent verification guide for navigation and hosting checks.