Skip to main content
Introducing packages.sweber.dev
All posts
Release2 min read

Permito 0.2.0: consent that expires, Global Privacy Control and tab sync

Permito 0.2.0 asks again after a configurable number of days, honours the Global Privacy Control browser signal and applies a decision in every open tab at once.

By Seya Weber

Permito 0.2.0 is out. @permitojs/core and @permitojs/react get three features that agencies asked about most after the first release. Nothing changes for existing setups unless you turn the new options on; tab sync is the only new default.

Decisions that expire

config={{ consentVersion: "2026-10", categories, maxAgeDays: 365 }}

Once a decision is older than maxAgeDays, Permito treats it as missing and shows the banner again. It works with every storage, including localStorage, which never expires on its own. Supervisory authorities commonly recommend asking again after 6 to 13 months; the value stays your decision. snapshot.expiresAt tells you when the current decision runs out.

Global Privacy Control

Global Privacy Control is a browser signal with which visitors object to the sale and sharing of their data, and several US states require businesses to honour it. That matters for Swiss and German shops that also sell to the US and run their banner in opt-out mode there.

config={{ consentVersion: "2026-10", categories, mode: "opt-out", globalPrivacyControl: true }}

While the visitor has not decided, marketing (or the categories you list) starts declined when the signal is present. An explicit choice in the banner always wins, and opt-in setups are unaffected because optional categories are declined anyway. For server rendering, readGpcFromHeaders() from @permitojs/react/server reads the Sec-GPC header, so server and client agree.

One decision, every tab

A choice made in one tab now applies immediately in every other open tab of the same site: gated scripts, iframes and Google Consent Mode updates included. Permito uses a BroadcastChannel in the browser and still sends nothing over the network. It is on by default with the built-in cookie storage and can be turned off with syncTabs: false.

Upgrade

pnpm add @permitojs/core@^0.2.0 @permitojs/react@^0.2.0

The new guide Lifetime, GPC and tabs covers all three options.

What comes next

The next release focuses on sites without React: a drop-in banner as a script tag for WordPress, Astro or static pages, and consent bridges for Microsoft UET, Microsoft Clarity and Matomo.

Permito is technical consent infrastructure, not legal advice. Whether a service needs consent, and how long a decision should last, is your assessment.

Package in this post

Permito

Self-hosted cookie banner, preference center and consent gates for React and Next.js. No network calls, no tracking, no dark patterns.

pnpm add @permitojs/core @permitojs/react
View package

Related posts

Release

Permito 0.1.0 released

The first public release of Permito: a self-hosted cookie banner, preference center and consent gates for React and Next.js. MIT licensed, no network calls.

Permito
Release

Inverse 0.1.0 released

The withdrawal button (§ 356a BGB) and the cancellation button (§ 312k BGB) for Next.js and React: statutory labels, the two-step flow, the receipt e-mail and a page check. MIT, no backend.

Inverse