Documentation
Everything you need to run ZenoCookieConsent, manage sites in it, wire it into your pages and document it for your DPO.
Manuals
Operations manual
For whoever runs the server: requirements, the installer and its options, configuration reference, S3 storage, reverse proxy and TLS, backups and restores, updates, monitoring, nightly maintenance, security hardening and the admin CLI.
Organization manual
For the people using the dashboard: signing in and invitations, organizations and roles, adding domains, banner design, texts in seven languages, the cookie declaration, publishing revisions, installing and verifying the banner, the consent log, files, members and the audit log.
Integrations
For developers: placement of zeno.js, blocking markup, categories, the window.Zeno API and events, Google Consent Mode v2, the cookie declaration, single-page apps and Content Security Policy, plus a guide per platform, framework and vendor (listed below).
Legal guide
For DPOs and counsel: an overview of EU law, national rules, a compliance matrix, a site-owner checklist, product recommendations and templates for a cookie policy and a data processing agreement. Not legal advice.
Architecture
Components, repository layout, the publishing model with immutable revisions, and the stable public client contract (v1) that every integration builds on.
Examples
Minimal runnable integrations for plain HTML, React (Vite), Vue (Vite), SvelteKit, Astro and the Next.js App Router, each checked in a real browser.
Integrations
A guide for your stack.
Each guide builds on the shared concepts in the integrations overview and ends with a browser checklist.
| Sites and platforms | Covers |
|---|---|
| Plain HTML | Static sites, server-rendered templates (PHP, Rails, Django, …) |
| WordPress | functions.php, mu-plugin, plugins that inject scripts, caching plugins |
| Shopify | theme.liquid, Customer Privacy API |
| Webflow, Squarespace, Wix | Custom code injection and its limits |
| Frameworks | Covers |
|---|---|
| Next.js | App Router and Pages Router, why not next/script |
| React (Vite) | useConsent hook |
| Vue 3 and Nuxt | Plugin and composable, Nuxt 3/4 |
| Angular | index.html and ConsentService |
| Svelte and SvelteKit | app.html and a store |
| Astro | is:inline, view transitions |
| Gatsby | gatsby-ssr head ordering |
| Remix and React Router v7 | root.tsx |
| Tags and vendors | Covers |
|---|---|
| Google Tag Manager | Consent Mode v2, consent checks, dataLayer events |
| Google Analytics 4 | Consent Mode vs fully blocked |
| Matomo | Cookieless vs consent-gated cookies |
| Meta Pixel | Blocking, consent API, Conversions API |
| YouTube and Vimeo | Click-to-load placeholders |
| Hotjar and Microsoft Clarity | Blocking, Clarity consent API |
| HubSpot | Tracking code, forms, chat |
Legal guide
For DPOs and counsel.
Researched background and practical templates. Not legal advice: see the disclaimer.
| Document | What it covers |
|---|---|
| EU law overview | GDPR, the ePrivacy Directive and EDPB guidance on cookie consent |
| National rules | Germany, Denmark, Spain, France, Sweden, Norway and more |
| Compliance matrix | Each requirement mapped to the feature or setting that covers it |
| Site-owner checklist | What to check when you deploy the banner on a site, and again whenever you add a tool |
| Product recommendations | Defaults and settings we recommend |
| Cookie policy template | A starting point for your cookie policy page |
| Data processing agreement template | Art. 28 GDPR agreement for agencies or operators hosting for clients |
Quick reference
The public client contract (v1).
Stable across releases. The full contract lives in the architecture document and the integrations overview.
| Markup | Effect |
|---|---|
data-gcm | On the script tag: emit Google Consent Mode v2 default (all denied) at once and update on every choice |
data-lang="de" | On the script tag: force the banner language instead of the browser's |
data-zeno="…" | On a blocked script, iframe or image: the categories that must all be granted (necessary is always released) |
data-zeno-declaration | On any element: filled with the cookie declaration, also when added later. Use ="manual" to fill it yourself with renderDeclaration |
html.zeno-marketing | Classes zeno-<category> and zeno-no-<category> on <html> for CSS placeholders |
window.Zeno | Description |
|---|---|
show() | Open the preferences panel |
accept(...categories) | Grant categories from a page control, e.g. "Load video" |
getConsent() | Current state per category, or null |
hasConsent(c) | true if category c is granted (always for necessary) |
onChange(fn) | Call fn now (if chosen) and on every change; returns an unsubscribe function |
receiptId() | The visitor's consent receipt id |
renderDeclaration(el) | Render the cookie declaration into el (queued until the config has loaded) |
Events on document: zeno:ready when the API is available, zeno:consent with the state in event.detail, fired after released scripts have run. Categories: necessary, functional, analytics, marketing.