Consent Inspector: Consent Mode v2, TCF & GPC
Overview
Audit Consent Mode v2, IAB TCF and GPC on any site. Catch every tag that fires before consent, then export the report.
The banner says one thing. The network says another. Consent Inspector reloads the page, watches every request from the first byte, and tells you exactly which tags fired BEFORE the user agreed — and whether your Consent Mode v2 signals are actually reaching Google. Built for the people who have to prove it: analytics engineers, measurement consultants, agencies handing a report to a client, and privacy teams checking what marketing promised. ━━━ WHAT IT CHECKS ━━━ ▸ TAGS FIRING BEFORE CONSENT Every vendor that sent data before the first consent grant, grouped by vendor and category. Advertising vendors are flagged critical — that is the finding an authority opens with. ▸ CONSENT MODE v1 MASQUERADING AS v2 Checks that ad_user_data and ad_personalization are actually declared. Plenty of setups labelled "v2" never added them, and nothing in Google's UI tells you. ▸ A DEFAULT COMMAND THAT ARRIVES TOO LATE gtag('consent','default') has to run before any tag loads. If a Google tag beat it, the consent state never applied to those hits. ▸ DENIED, AND FIRING ANYWAY Reconstructs the consent state at the moment of each request. If a vendor sent data while its governing signal read "denied", you get the timestamp and the evidence. ▸ A GPC OPT-OUT BEING IGNORED Global Privacy Control is a binding opt-out in eleven US states. If the browser is broadcasting it and advertising tags fire anyway, you will know. ▸ IAB TCF Detects __tcfapi, its policy version and CMP status, and flags the case where GDPR applies but no TC string was ever produced. ▸ COOKIES WRITTEN TOO EARLY Cookies set from JavaScript before consent — with the CMP's own cookies excluded, because those are exempt and flagging them would just be noise. ▸ WHAT GOOGLE ACTUALLY RECEIVED Reads the gcs parameter off the outgoing beacons, so you see the consent state Google recorded — not the one your tag manager believes it sent. ━━━ WHY IT RELOADS THE PAGE ━━━ Because the interesting part happens in the first 300 milliseconds. A tool that attaches after load has already missed the pixel that fired before the banner rendered — which is precisely the thing you were looking for. ━━━ USE CASES ━━━ • Agency: audit a client's site before the handover, export the report, attach it to the invoice. • In-house: check the checkout after every release, before the data goes missing. • Privacy team: verify what the marketing team says the CMP is doing. • Pre-migration: confirm a v1 setup before Google Signals retires on 15 June 2026. ━━━ PRICE ━━━ Free. All of it, permanently. No account, no sign-up, no licence, no paid tier, no trial that expires. There is nothing to upgrade to, because there is no paid version. Everything the extension does, it does for everyone. It also has no server: it makes no network requests of its own, so there is nothing behind it that can be shut down or start charging later. ━━━ HONEST ABOUT WHAT THIS IS NOT ━━━ This is not a compliance certificate, and any tool claiming to be one is selling you something. An audit captures a single page load, from one browser, in one location, with the consent choices present at that moment. Geo-targeted banners, A/B tests and server-side tagging can produce different results. It is evidence for a human to interpret — not a legal opinion. ━━━ PRIVACY ━━━ Audits are stored locally in your browser. There is no account, no analytics inside this extension, and no server that receives what you audit. The extension records hostnames, paths and parameter NAMES — parameter values are replaced by their length (except a short allow-list of consent-state parameters like gcs and gdpr), cookie values are never read, and page content is never touched. Host access is requested ONE DOMAIN AT A TIME, when you start an audit. This extension never asks for access to all your sites, and you can revoke any grant from chrome://extensions. ━━━ COMPARED WITH THE ALTERNATIVES ━━━ vs Google Tag Assistant — Tag Assistant shows what your Google tags are doing. Consent Inspector asks whether any of it should have been sent at all, covers non-Google vendors, checks GPC and TCF, and produces a report. vs a general tag debugger — a debugger inspects. This audits: it reconstructs the consent state at each request and gives you a pass/fail with evidence. vs your CMP's own dashboard — your CMP is the vendor being audited. An independent check is the point. ━━━ FAQ ━━━ Q: Does it work on localhost and staging? A: Yes. Grant permission for that origin like any other site. Q: Will it break the site I audit? A: No. It only observes; every hook delegates to the original implementation and is wrapped so a failure cannot affect the page. Q: Do I need a Google Analytics account? A: No. It reads what the page sends, not what any platform reports. Q: Why does it need permission for the site? A: To observe requests from the first byte. You grant one domain at a time and can revoke it whenever you want. Not affiliated with Google, Meta, TikTok, IAB Europe or any CMP vendor. Product names are used only to describe what the extension detects.
0 out of 5No ratings
Details
- Version1.1.0
- UpdatedSeptember 8, 2026
- Offered byfaustino20161
- Size40.22KiB
- LanguagesEnglish
- Developer
Email
faustino20161@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes