c15t is the stronger fit when your product team wants consent in its codebase and control over the backend. Its open-source engine, native components and vendor integrations work together.
OneTrust offers extensive consent operations and a server-side API for custom interfaces. The reason to choose c15t is control of the implementation, not exclusive access to headless consent.
<include src="../shared/comparisons/inth-hosting.mdx" />
c15t’s banner appears 607 ms sooner than OneTrust’s on desktop.
| What you need | c15t | OneTrust |
|---|---|---|
| Build application consent UI | Native components, themes and headless APIs | Web CMP UI and a headless Server-Side CMP API |
| Resolve consent on the server | Framework helpers and cached public policy | Server-Side CMP API |
| Read or change consent in code | Reactive framework state and actions | JavaScript methods and consent-change callbacks |
| Control vendor execution | Declared integrations, request rules and embeds | Automatic blocking, tag-manager integrations and script controls |
| Own the backend implementation | Apache-2.0 backend that you can deploy | OneTrust platform and APIs |
| Store consent records | Inth hosts the backend and stores records in its database. Self-hosting is optional | Consent transaction database |
| Scan authenticated or hidden pages | Not included in the c15t packages | Documented website scans |
| Compare banner layouts | Presentation experiments with your feature flags | A/B tests and template targeting |
| Run a wider privacy programme | No complete privacy operations suite in c15t | Separate OneTrust products extend the consent scope |
Sources: Cookie Consent, JavaScript methods and Server-Side CMP API.
Your developers can read, change and version c15t's Apache-2.0 source. The consent interface can use the same components and release process as the product.
A privacy settings screen can read the same state that controls a video embed or analytics integration. Use headless APIs when the stock interface does not fit.
OneTrust's headless API also lets teams build their own UI. c15t adds an engine and backend implementation that your team can run and change.
Switch a category off. Its vendors wait.
42 of 42 running
Always loads and gets consent signals.
- Cloudflare Zaraz, always loads and gets consent signals
- Google Tag Manager, always loads and gets consent signals
- Google Tag, always loads and gets consent signals
- Databuddy, always loads and gets consent signals
- Mixpanel, always loads and gets consent signals
- PostHog, always loads and gets consent signals
- Microsoft UET, always loads and gets consent signals
- Ahrefs Analytics
- Adobe Analytics
- Amplitude
- Cloudflare Web Analytics
- Microsoft Clarity
- Fathom Analytics
- Heap
- Matomo Analytics
- OneDollarStats
- Hotjar
- Hightouch
- LogRocket
- Plausible Analytics
- Promptwatch
- Pirsch
- RudderStack
- Segment
- Rybbit Analytics
- Umami Analytics
- Vercel Analytics
- Klaviyo
- Clearbit
- Meta Pixel
- OpenAI Pixel
- Pinterest Tag
- Reddit Pixel
- TikTok Pixel
- LinkedIn Insight Tag
- Snapchat Pixel
- X Pixel
- YouTube
- Crisp
- Front Chat
- Intercom
- Google Maps
Import each helper from @c15t/integrations.
Paste this line into your agent. It reads the setup brief and does each step.
The setup brief is at /SKILL.md. For the docs, agents can read /llms.txt and /llms-full.txt, or use the MCP server at with no sign-in.
The CLI plans the setup. You check the plan, then apply it.
To do each step yourself, read the quickstart. To get JSON results for scripts and agents, read the automation guide.
Inth hosts the backend, the policy rules and the IAB CMP ID.