Consent Validator
HomeFeaturesPricingDocumentation
Sign inGet Started

Documentation

Everything you need to validate with confidence

Guides for getting started, reading reports, and keeping compliance current.

Getting started

Create an account, enter a public URL, and launch your first validation. No tag installation or DNS changes are required — we observe your site the way a visitor would.

Read more

Understanding your report

Reports are organized by severity, consent state, and category. Each finding includes what was observed and a recommended next step.

Read more

Scheduling scans

Weekly Monitor and higher plans support recurring validations in your timezone. Alerts fire when drift is detected — for example, after a CMP update or new GTM deployment.

Read more

Supported regulations

Findings map to GDPR, ePrivacy, and Google Consent Mode v2. Where IAB TCF signals are present, we report availability and related consent-string behaviour.

Read more

Google Analytics integration

Optionally connect your own Google Analytics account for a read-only GA4 configuration audit. We request read-only scopes only — analytics.readonly to read your GA4 configuration, plus optional tagmanager.readonly for the Consent Mode v2 check — never your visitors' analytics data, and we never modify your account. Disconnect anytime from Settings; it deletes the stored tokens immediately.

Read more

API access

Programmatic access is available on request for Agency and Enterprise plans. Request it from Settings → API access; we review each request and follow up with next steps and documentation.

Read more

Security & data handling

We process only URLs you submit. Evidence is stored in your workspace with row-level security. We do not sell data or use your scan results for advertising.

Read more

On this page

  • Getting started
  • Understanding your report
  • Scheduling scans
  • Supported regulations
  • Google Analytics integration
  • API access
  • Security & data handling

Getting started

Create an account, enter a public URL, and launch your first validation. No tag installation or DNS changes are required — we observe your site the way a visitor would.

  1. Sign up and confirm your email
  2. Enter the URL you want to validate
  3. Review findings grouped by consent state
  4. Export PDF or JSON for your records

Understanding your report

Reports are organized by severity, consent state, and category. Each finding includes what was observed and a recommended next step.

example.com

Scanned Jun 11, 2026

Overall compliance

74 / 100

Consent validation

68%

Tests Before Consent, Reject, and Accept in a real browser.

Analytics validation

80%

Read-only GA4 and GTM audit when Google is connected.

Key findings

  • Critical

    Meta Pixel fires before consent

    Gate the pixel behind your CMP accept action.

    Before Consent

  • Warning

    ad_user_data missing from default update

    Include all four Consent Mode v2 parameters in the update call.

    Accept

  • Warning

    Non-essential cookie set pre-consent

    Move _ga cookie creation behind affirmative consent.

    Before Consent

Export PDF · Share link · Download JSON

Full sample

Scheduling scans

Weekly Monitor and higher plans support recurring validations in your timezone. Alerts fire when drift is detected — for example, after a CMP update or new GTM deployment.

Supported regulations

Findings map to GDPR, ePrivacy, and Google Consent Mode v2. Where IAB TCF signals are present, we report availability and related consent-string behaviour.

Google Analytics integration

Optionally connect your own Google Analytics account for a read-only GA4 configuration audit. We request read-only scopes only — analytics.readonly to read your GA4 configuration, plus optional tagmanager.readonly for the Consent Mode v2 check — never your visitors' analytics data, and we never modify your account. Disconnect anytime from Settings; it deletes the stored tokens immediately.

  • Scopes requested: analytics.readonly (required) and optional tagmanager.readonly for the Consent Mode v2 (GTM) check, plus your basic profile email so we can show which Google account is connected.
  • What we read: your GA4 account and property list, data streams and measurement IDs, data-retention settings, Google-signals state, and key events — solely to generate your configuration audit.
  • What we never do: modify your Google account, read your visitors' analytics data, sell data, or use it for advertising or model training.
  • Limited Use: our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements — see the privacy policy.
  • Revoke anytime from Settings → Google Analytics → Disconnect, or from your Google Account permissions page.

API access

Programmatic access is available on request for Agency and Enterprise plans. Request it from Settings → API access; we review each request and follow up with next steps and documentation.

Security & data handling

We process only URLs you submit. Evidence is stored in your workspace with row-level security. We do not sell data or use your scan results for advertising.

  • Authentication and row-level security on all workspace data
  • Evidence retained on a rolling window per your plan
  • Validate only properties you own or are authorized to test

Ready to validate?

Create an account and run your first validation — most reports are ready in minutes.

Get Started

Product

  • Features
  • Pricing
  • Run a Scan
  • Sample Report

Resources

  • Documentation
  • Blog

Company

  • About
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy

© 2026 Consent Validator

XGitHub