Skip to main content
Introducing packages.sweber.dev
Permito overview

PermitoLive demo, core and Pro.

The first section runs the free core (MIT). Every section after it is produced by the Pro packages themselves. The themes and layouts run in your browser. The catalog, the cookie table and the scanner report are rendered on the server, so what reaches your browser is the finished HTML and not the packages.

The banner preview uses its own in-memory storage. Nothing you click here changes the consent of this site.

Core

Core (free, MIT)Banner, dialog and gates.

The banner, the settings dialog and the gates belong to the free core, @permitojs/react. Decide in the banner, then watch the gate and the video below react. The decision is kept in memory only and is gone on reload.

Themes

Themes and layoutsLive, in the frame below.

Pick a theme, a mode and a layout, then decide in the banner. Changing the layout shows the banner again. The decision is kept in memory only and is gone on reload.

Catalog

Service catalogFacts with a source.

The catalog holds 71 services. 8 are shown in full below. Each entry states what the provider documents, with the source page and the date it was read.

Google Analytics 4Google, Ireland
Provider
Google
Hosting
Run by the provider
Legal entity
Google Ireland Limited, Ireland
Third countries
United States
Data Privacy Framework
Google LLC, EU-US listed, Swiss-US listed
Purpose
Measurement of website usage with Google Analytics 4.

Cookies and storage

NameTypeDurationDescription
_gacookie2 yearsAccording to Google, used to distinguish users.
_ga_<container-id>cookie2 yearsAccording to Google, used to persist session state.

Source: https://support.google.com/analytics/answer/11397207. retrieved 2026-10-04.

Matomo On-PremiseInnoCraft, Self-hosted, runs on your infrastructure
Provider
InnoCraft
Hosting
Self-hosted, runs on your infrastructure
Legal entity
No provider receives data from this setup, so entity and transfers do not apply.
Purpose
Web analytics: Matomo records visits to the operator's website. The software runs on the operator's infrastructure.

Cookies and storage

NameTypeDurationDescription
_pk_idcookie13 monthsStores a unique visitor ID to recognize returning visitors.
_pk_sescookie30 minutesSession cookie that temporarily stores data for the visit.
_pk_refcookie6 monthsStores attribution information, i.e. the referrer that brought the visitor to the website.
_pk_cvarcookie30 minutesSession cookie that temporarily stores custom variables for the visit.
_pk_testcookiecookieImmediate expiryChecks whether the browser supports cookies (according to Matomo, for Internet Explorer).
matomo_sessidcookie14 daysOptional. A nonce to help prevent CSRF issues when using the opt-out feature.
mtm_consent_removedcookie30 yearsOptional. Indicates that a visitor opted out of Matomo tracking.
mtm_cookie_consentcookie30 yearsOptional. Records the visitor's consent to Matomo tracking.
_pk_hsrcookie30 minutesOptional. Stores heatmap and session recording data.
_pk_uidcookie13 monthsOptional, not default. Enables cross-domain visitor recognition.
MatomoAbTestinglocalStorageNot statedOptional. Stores information for Matomo A/B Testing in local storage. Matomo states no expiry.

Source: https://matomo.org/faq/general/faq_146/. retrieved 2026-10-04.

Meta PixelMeta, Ireland
Provider
Meta
Hosting
Run by the provider
Legal entity
Meta Platforms Ireland Limited, Ireland
Third countries
United States
Data Privacy Framework
Meta Platforms, Inc., EU-US listed, Swiss-US listed
Purpose
JavaScript code that, according to Meta, tracks visitor activity on a website to measure the effectiveness of advertising and analyze conversion funnels. According to Meta, the Pixel relies on Facebook cookies to match website visitors to their Facebook accounts.

Cookies and storage

NameTypeDurationDescription
_fbpcookieNot statedMeta names this cookie as the place where the Meta browser ID is stored, under the website's domain. Meta states no duration in the documentation retrieved (including its documentation on managing fbp and fbc).
_fbccookieNot statedMeta names this cookie as the place where the Meta click ID is stored. Meta states no duration for the cookie set by the Pixel. For a _fbc cookie set by the website's own server, Meta's Conversions API documentation recommends a duration of 90 days.

Source: https://developers.facebook.com/docs/meta-pixel/get-started/. retrieved 2026-10-04.

YouTube (youtube-nocookie.com)Google, Ireland
Provider
Google
Hosting
Run by the provider
Legal entity
Google Ireland Limited, Ireland
Third countries
United States
Data Privacy Framework
Google LLC, EU-US listed, Swiss-US listed
Purpose
Embedding of YouTube videos in privacy-enhanced mode through youtube-nocookie.com.

Cookies and storage

The provider documents no cookies or storage entries.

Source: https://support.google.com/youtube/answer/171780. retrieved 2026-10-04.

TWINT (Webshop)TWINT AG, Switzerland
Provider
TWINT AG
Hosting
Run by the provider
Legal entity
TWINT AG, Switzerland
Third countries
None named by the provider
Data Privacy Framework
Not checked
Purpose
Payment method in the web shop. According to TWINT, TWINT is integrated via the merchant's payment service provider or a plug-in of the shop system; payment is completed in the TWINT app via the Web2App switch.

Cookies and storage

The provider documents no cookies or storage entries.

Source: https://www.twint.ch/en/business-customers/products/twint-for-online-shops/. retrieved 2026-10-04.

Datatrans Payment Page / LightboxDatatrans AG, Switzerland
Provider
Datatrans AG
Hosting
Run by the provider
Legal entity
Datatrans AG, Switzerland
Third countries
None named by the provider
Data Privacy Framework
Not checked
Purpose
Payment processing via the Datatrans Payment Page in redirect or lightbox mode. According to Datatrans, the lightbox displays an iframe on top of the merchant page; on mobile devices it switches to redirect mode automatically.

Cookies and storage

The provider documents no cookies or storage entries.

Source: https://docs.datatrans.ch/docs/redirect-lightbox. retrieved 2026-10-04.

etracker AnalyticsJustRelate Deutschland GmbH, Germany
Provider
JustRelate Deutschland GmbH
Hosting
Run by the provider
Legal entity
JustRelate Deutschland GmbH, Germany
Third countries
None named by the provider
Data Privacy Framework
Not checked
Purpose
Web analytics: etracker Analytics records the use of the operator's website. According to etracker, data is processed and stored exclusively in Germany.

Cookies and storage

NameTypeDurationDescription
et_allow_cookieslocalStorage480 daysSignals whether etracker may set cookies via API call. Set when _etracker.enableCookies() is called and deleted on disableCookies().
et_oi_v2localStorage50 years (value "no"), 480 days (value "yes")Implements the objection function (opt-out) and serves an opt-in where used.
et_oi_serviceslocalStorage720 daysStores the user's choice (acceptance or refusal) per category or provider.
_et_coidlocalStorage720 days (configurable)Used to recognize users by means of a virtual expiry timestamp.
isSdEnabledcookie24 hoursIndicates whether scroll depth measurement is active.
et_scroll_depthsessionStorageSessionBuffers scroll measurement data for ScrollMap reports. Set when scroll tracking is enabled.
et_cssSelectorssessionStorageSessionCache for the configuration of events defined by CSS selectors.
et_tagManagerEntriessessionStorageSessionCache for the trigger configuration of the etracker Tag Manager.
et_tagManagerVarssessionStorageSessionCache for the variable configuration of the etracker Tag Manager.

Source: https://help.etracker.com/en/article/cookies-used/. retrieved 2026-10-04.

Friendly CaptchaFriendly Captcha GmbH, Germany
Provider
Friendly Captcha GmbH
Hosting
Run by the provider
Legal entity
Friendly Captcha GmbH, Germany
Third countries
None named by the provider
Data Privacy Framework
Not checked
Purpose
Bot detection on forms. According to Friendly Captcha, the data is only used to identify and handle potential bots and risks.

Cookies and storage

The provider documents no cookies or storage entries.

Source: https://friendlycaptcha.com/legal/privacy-end-users/. retrieved 2026-10-04.

63 more services, by name

Every entry has the same fields as the ones above.

  • Adobe Fonts
  • Awin Affiliate-Tracking (MasterTag)
  • Brevo
  • Bunny Fonts
  • Calendly (embedded scheduling page)
  • Cloudflare Turnstile
  • Cloudflare Web Analytics
  • Criteo OneTag
  • econda Analytics
  • Facebook (social plugins, embedded posts)
  • Fathom Analytics
  • Google Ads Conversion Tracking / Remarketing
  • Google Fonts
  • Google Maps
  • Google reCAPTCHA
  • Google Tag Manager
  • Hotjar
  • HubSpot
  • Infomaniak Newsletter
  • Instagram (embedded post)
  • Intercom Messenger
  • Klarna On-site Messaging / Checkout-Widget
  • Klaviyo (onsite tracking and forms)
  • LinkedIn Insight Tag
  • Mailchimp
  • Mapbox GL JS
  • Mapp Intelligence
  • Matomo Cloud
  • Microsoft Advertising Universal Event Tracking (UET)
  • Microsoft Clarity
  • Mollie Components / Checkout
  • Mouseflow
  • OpenStreetMap (Tile-Server)
  • PayPal
  • Payrexx
  • Pinterest Tag
  • Piwik PRO Analytics Suite
  • Plausible Analytics
  • Plausible Community Edition
  • PostFinance Checkout
  • PostHog (self-hosted)
  • PostHog Cloud
  • ProvenExpert Bewertungssiegel
  • Sentry
  • Sentry (self-hosted)
  • Shopware 6
  • SoundCloud (eingebetteter Player)
  • Spotify (embedded player)
  • Stripe
  • swisstopo maps (geo.admin.ch)
  • TikTok (embedded videos)
  • TikTok Pixel
  • Trustpilot TrustBox
  • Typeform
  • Umami (self-hosted)
  • Umami Cloud
  • Vercel Web Analytics
  • Vimeo
  • Worldline Saferpay
  • X (embedded posts)
  • X Pixel (Conversion-Tracking)
  • YouTube
  • Zendesk Web Widget (Messaging)

From entry to config

The catalog contains facts with a source, not a legal assessment. The category is set by you, the operator, when you turn an entry into a service.

toConsentService takes over name, provider, purpose, cookies and privacy policy link. You add the category. The catalog cannot set it for you, and entries may not contain one.

import { catalog, toConsentService } from "@weber-development/permito-catalog"

const entry = catalog.find((e) => e.id === "google-analytics-4")
if (!entry) throw new Error("Entry not found")

// The category is your decision. The catalog never sets it.
const service = toConsentService(entry, { category: "statistics" })

Scanner

ScannerA recorded run.

The scanner loads a page in headless Chromium without clicking anything and compares what it sees with your consent config. It reports and changes nothing.

This is a recorded run against a demo page, not a live check. The config for the run lists one service, Google Analytics 4.

Scanned page: http://127.0.0.1:4317/

Not in your config
3
Active before consent
4
Matched, for information
0

Not in your config

3

A cookie, storage key or third-party host that no configured service accounts for. Where the catalog knows a match, it suggests an entry. Whether it belongs in your config, and in which category, is your decision.

  • connect.facebook.nethost

    Catalog suggestions: Facebook (social plugins, embedded posts) (facebook-embed), Meta Pixel (meta-pixel)

  • fonts.googleapis.comhost

    Catalog suggestions: Google Fonts (google-fonts)

  • www.facebook.comhost

    Catalog suggestions: Meta Pixel (meta-pixel)

Active before consent

4

The entry belongs to a configured service that needs a decision, and it was present before any consent existed. This is an observation, not an assessment. A possible cause is a script that is not gated or a tag manager that loads it regardless.

  • _ga_DEMO123456cookie

    Service: google-analytics-4, Category: statistics

  • _gacookie

    Service: google-analytics-4, Category: statistics

  • region1.google-analytics.comhost

    Service: google-analytics-4, Category: statistics

  • www.googletagmanager.comhost

    Service: google-analytics-4, Category: statistics

Run it yourself

npx permito scan https://client.example --config consent.config.ts

Exit code

This run: 1

  • 0No findings.
  • 1At least one finding, not in your config or active before consent.
  • 2Error during the run, for example an unreachable page or a missing Chromium.

A clean run is a snapshot, not proof. The scanner does not click, scroll or log in, so it misses what loads only after an interaction.

Consent log

Consent logStored on your server.

The log package is not part of this demo, so nothing is recorded here. This is what it stores per change of consent, and the route handler that receives it.

One record

{
  "id": "6f1c0b0e-4a52-4d0e-9b57-0e2a3f6c8d11",
  "visitorHash": "9b1d5c3a7e0f42a8c6d4b2e19f08a7d3c5e6b4a1f2d0c9e8b7a6f5d4c3b2a190",
  "timestamp": "2026-10-05T09:41:12.000Z",
  "consentVersion": "2026-10",
  "categories": { "necessary": true, "statistics": true, "marketing": false },
  "services": {},
  "source": "banner",
  "region": "CH",
  "language": "de-CH"
}

Example record with made-up values.

Stored
The record is kept in a store you choose, on your infrastructure. The visitor ID is hashed with a secret salt and the ID itself is not stored.
Not stored
No IP address and no user agent. Fields the client adds are discarded.

Once the log runs, you process personal data. The retention period is required and has no default. Whether and how you use it is your decision.

Next.js route handler

// lib/consent-log.ts
import { createConsentLog } from "@weber-development/permito-log"
import { fileStore } from "@weber-development/permito-log/file"

export const log = createConsentLog({
  store: fileStore(process.env.CONSENT_LOG_FILE ?? "./data/consent-log.jsonl"),
  salt: process.env.CONSENT_LOG_SALT!, // at least 32 characters
  retentionDays: 90, // your decision, there is no default
})

// app/api/consent-log/route.ts
import { createConsentLogRoute } from "@weber-development/permito-log/next"
import { log } from "@/lib/consent-log"

export const runtime = "nodejs"
export const { POST } = createConsentLogRoute(log, {
  allowedOrigins: ["https://www.example.ch"],
})

Two files: the log, and the route that receives the browser's POST.

Next step

Use it in your own projectPricing is per person.

After checkout, Polar gives your GitHub account access. The Pro packages then install from GitHub Packages with a read-only token.

See pricing

Permito is technical consent infrastructure, not legal advice.