Skip to main content

Analytics

RudderStack

Configure RudderStack

Copy the source write key and the HTTPS data plane URL from your RudderStack source. Keep control-plane credentials out of the browser.

npm install @c15t/integrations@alpha
src/consent-scripts.ts
import { rudderstack } from '@c15t/integrations/rudderstack';

export const scripts = [
	rudderstack({
		writeKey: 'YOUR_SOURCE_WRITE_KEY',
		dataPlaneUrl: 'https://your-data-plane.example.com',
	}),
];

Register the scripts

Complete your framework quickstart first. Keep its Inth endpoint, policy, styles and consent UI. Remove the vendor's original script, SDK initializer or tag-manager entry, so the vendor loads only through c15t.

The vendor pages put the helper in src/consent-scripts.ts. If your framework quickstart already has a scripts array, such as the one in c15t.config.ts in the Next.js guide, add the helper to that array instead of creating a second file. The scripts export is a configuration, not an initializer. Add it to the c15t provider you already have, at the registration point for your framework below. These are edits to that provider, not a second provider.

Add the configuration to scripts in c15t.config.ts, next to next.config.ts:

import { defineConsentConfig } from 'c15t/next';
import { scripts } from './src/consent-scripts';

export default defineConsentConfig({ scripts });

Keep the rest of your config, such as mode and routePrefix, in the same call. ConsentRoot reads the config in the browser, so the layout keeps passing only state. App Router, Pages Router and static export all read the same file. See Next.js scripts and embeds.

Options

OptionDefaultBehavior
writeKeyRequiredSource write key. Surrounding whitespace is trimmed. An empty value logs an error and the script does not load.
dataPlaneUrlRequiredData plane URL. A missing, invalid or non-HTTPS URL logs an error and the script does not load.
consentManagementNone{ mapping } from c15t categories to RudderStack consent IDs. Switches to destination consent mode.
loadOptions{}Third argument to rudderanalytics.load(). Use JSON-serializable values only.
trackPageViewtrueQueues rudderanalytics.page() before the loader.
scriptUrlhttps://cdn.rudderlabs.com/v3/modern/rsa.min.jsLoader URL override. A non-HTTPS URL throws; a blank value uses the default.

Loading and revocation

rudderstack uses the measurement category. consentManagement picks the mode:

ModeLoadsOn consent changeOn revocation
DefaultAfter measurement is allowed, with load and page queuedNothingRemoves the script element and calls no RudderStack API
consentManagementOn every page, in RudderStack's pre-consent stateCalls rudderanalytics.consent() with the mapped IDsKeeps the SDK and calls consent() with the revoked IDs denied

consentManagement loads the RudderStack SDK before the visitor chooses. Use it only when every destination in your workspace carries a consent ID from the mapping; c15t cannot check destination settings from the browser. Add the mapping to the helper call:

rudderstack({
	writeKey: 'YOUR_SOURCE_WRITE_KEY',
	dataPlaneUrl: 'https://your-data-plane.example.com',
	consentManagement: {
		mapping: {
			measurement: ['YOUR_ANALYTICS_CONSENT_ID'],
			marketing: ['YOUR_ADVERTISING_CONSENT_ID'],
		},
	},
});

The helper sets preConsent.enabled, buffered event delivery and consentManagement.provider: 'custom' in the load options. Storage defaults to { strategy: 'none' }; a preConsent.storage value in loadOptions replaces it. Before load, the helper queues a consent() call. IDs of allowed categories go to allowedConsentIds and IDs of denied categories go to deniedConsentIds. A visitor who turns off the rudderstack vendor gets every mapped ID denied. An empty mapping, or a category with no non-blank IDs, throws.

Verify RudderStack

In the default mode, allowing measurement loads rsa.min.js with a data-rsa-write-key attribute, and a page event goes to your data plane URL.

Test in a private window with an opt-in policy. Open DevTools Network, disable the cache and filter by the vendor's domain:

  1. Load the page. No request goes to the vendor before you choose.
  2. Click Reject, then reload. There is still no vendor request.
  3. Open Privacy settings and allow the helper's category. The vendor script loads without a page reload.
  4. Turn the category off again and save. c15t reloads the page, and the new page makes no vendor request.

c15t reloads on revocation because removing a script element does not stop code that already ran. The vendor's listeners, timers and queued events stay alive until the page unloads. If you set reloadOnConsentRevoked: false, stop the vendor yourself. Register a callback-only script whose onConsentChange calls the vendor's opt-out API, as shown in custom integrations, and check the permission before each of your own event calls. The reload does not delete cookies the vendor already set; see clear on revocation for your framework.

The helper sets vendor to its script ID, so once you declare that vendor a visitor can turn it off inside an allowed category. See vendor consent for your framework. The consent verification guide covers navigation, expiry and hosting checks.

With consentManagement, the SDK loads before the choice, so check your destinations instead. Test in a private window with an opt-in policy:

  1. Load the page. rsa.min.js loads before you choose. Destinations whose consent IDs map to a denied category receive no events.
  2. Open Privacy settings and allow measurement. Without a reload, destinations with measurement IDs start receiving events. Destinations mapped only to marketing still receive none.
  3. Turn measurement off and save. c15t reloads the page, and destinations with measurement IDs receive no events from the new page.

See the consent verification guide for navigation and hosting checks.