PermitoLive demo, core and Pro.
The first section runs the free core (MIT). Every section after it is produced by the Pro packages themselves. The themes and layouts run in your browser. The catalog, the cookie table and the scanner report are rendered on the server, so what reaches your browser is the finished HTML and not the packages.
The banner preview uses its own in-memory storage. Nothing you click here changes the consent of this site.
Core
Core (free, MIT)Banner, dialog and gates.
The banner, the settings dialog and the gates belong to the free core, @permitojs/react. Decide in the banner, then watch the gate and the video below react. The decision is kept in memory only and is gone on reload.
Themes
Themes and layoutsLive, in the frame below.
Pick a theme, a mode and a layout, then decide in the banner. Changing the layout shows the banner again. The decision is kept in memory only and is gone on reload.
Catalog
Service catalogFacts with a source.
The catalog holds 71 services. 8 are shown in full below. Each entry states what the provider documents, with the source page and the date it was read.
Google Analytics 4Google, Ireland
- Provider
- Hosting
- Run by the provider
- Legal entity
- Google Ireland Limited, Ireland
- Third countries
- United States
- Data Privacy Framework
- Google LLC, EU-US listed, Swiss-US listed
- Purpose
- Measurement of website usage with Google Analytics 4.
Cookies and storage
| Name | Type | Duration | Description |
|---|---|---|---|
| _ga | cookie | 2 years | According to Google, used to distinguish users. |
| _ga_<container-id> | cookie | 2 years | According to Google, used to persist session state. |
Source: https://support.google.com/analytics/answer/11397207. retrieved 2026-10-04.
Matomo On-PremiseInnoCraft, Self-hosted, runs on your infrastructure
- Provider
- InnoCraft
- Hosting
- Self-hosted, runs on your infrastructure
- Legal entity
- No provider receives data from this setup, so entity and transfers do not apply.
- Purpose
- Web analytics: Matomo records visits to the operator's website. The software runs on the operator's infrastructure.
Cookies and storage
| Name | Type | Duration | Description |
|---|---|---|---|
| _pk_id | cookie | 13 months | Stores a unique visitor ID to recognize returning visitors. |
| _pk_ses | cookie | 30 minutes | Session cookie that temporarily stores data for the visit. |
| _pk_ref | cookie | 6 months | Stores attribution information, i.e. the referrer that brought the visitor to the website. |
| _pk_cvar | cookie | 30 minutes | Session cookie that temporarily stores custom variables for the visit. |
| _pk_testcookie | cookie | Immediate expiry | Checks whether the browser supports cookies (according to Matomo, for Internet Explorer). |
| matomo_sessid | cookie | 14 days | Optional. A nonce to help prevent CSRF issues when using the opt-out feature. |
| mtm_consent_removed | cookie | 30 years | Optional. Indicates that a visitor opted out of Matomo tracking. |
| mtm_cookie_consent | cookie | 30 years | Optional. Records the visitor's consent to Matomo tracking. |
| _pk_hsr | cookie | 30 minutes | Optional. Stores heatmap and session recording data. |
| _pk_uid | cookie | 13 months | Optional, not default. Enables cross-domain visitor recognition. |
| MatomoAbTesting | localStorage | Not stated | Optional. Stores information for Matomo A/B Testing in local storage. Matomo states no expiry. |
Source: https://matomo.org/faq/general/faq_146/. retrieved 2026-10-04.
Meta PixelMeta, Ireland
- Provider
- Meta
- Hosting
- Run by the provider
- Legal entity
- Meta Platforms Ireland Limited, Ireland
- Third countries
- United States
- Data Privacy Framework
- Meta Platforms, Inc., EU-US listed, Swiss-US listed
- Purpose
- JavaScript code that, according to Meta, tracks visitor activity on a website to measure the effectiveness of advertising and analyze conversion funnels. According to Meta, the Pixel relies on Facebook cookies to match website visitors to their Facebook accounts.
Cookies and storage
| Name | Type | Duration | Description |
|---|---|---|---|
| _fbp | cookie | Not stated | Meta names this cookie as the place where the Meta browser ID is stored, under the website's domain. Meta states no duration in the documentation retrieved (including its documentation on managing fbp and fbc). |
| _fbc | cookie | Not stated | Meta names this cookie as the place where the Meta click ID is stored. Meta states no duration for the cookie set by the Pixel. For a _fbc cookie set by the website's own server, Meta's Conversions API documentation recommends a duration of 90 days. |
Source: https://developers.facebook.com/docs/meta-pixel/get-started/. retrieved 2026-10-04.
YouTube (youtube-nocookie.com)Google, Ireland
- Provider
- Hosting
- Run by the provider
- Legal entity
- Google Ireland Limited, Ireland
- Third countries
- United States
- Data Privacy Framework
- Google LLC, EU-US listed, Swiss-US listed
- Purpose
- Embedding of YouTube videos in privacy-enhanced mode through youtube-nocookie.com.
Cookies and storage
The provider documents no cookies or storage entries.
Source: https://support.google.com/youtube/answer/171780. retrieved 2026-10-04.
TWINT (Webshop)TWINT AG, Switzerland
- Provider
- TWINT AG
- Hosting
- Run by the provider
- Legal entity
- TWINT AG, Switzerland
- Third countries
- None named by the provider
- Data Privacy Framework
- Not checked
- Purpose
- Payment method in the web shop. According to TWINT, TWINT is integrated via the merchant's payment service provider or a plug-in of the shop system; payment is completed in the TWINT app via the Web2App switch.
Cookies and storage
The provider documents no cookies or storage entries.
Source: https://www.twint.ch/en/business-customers/products/twint-for-online-shops/. retrieved 2026-10-04.
Datatrans Payment Page / LightboxDatatrans AG, Switzerland
- Provider
- Datatrans AG
- Hosting
- Run by the provider
- Legal entity
- Datatrans AG, Switzerland
- Third countries
- None named by the provider
- Data Privacy Framework
- Not checked
- Purpose
- Payment processing via the Datatrans Payment Page in redirect or lightbox mode. According to Datatrans, the lightbox displays an iframe on top of the merchant page; on mobile devices it switches to redirect mode automatically.
Cookies and storage
The provider documents no cookies or storage entries.
Source: https://docs.datatrans.ch/docs/redirect-lightbox. retrieved 2026-10-04.
etracker AnalyticsJustRelate Deutschland GmbH, Germany
- Provider
- JustRelate Deutschland GmbH
- Hosting
- Run by the provider
- Legal entity
- JustRelate Deutschland GmbH, Germany
- Third countries
- None named by the provider
- Data Privacy Framework
- Not checked
- Purpose
- Web analytics: etracker Analytics records the use of the operator's website. According to etracker, data is processed and stored exclusively in Germany.
Cookies and storage
| Name | Type | Duration | Description |
|---|---|---|---|
| et_allow_cookies | localStorage | 480 days | Signals whether etracker may set cookies via API call. Set when _etracker.enableCookies() is called and deleted on disableCookies(). |
| et_oi_v2 | localStorage | 50 years (value "no"), 480 days (value "yes") | Implements the objection function (opt-out) and serves an opt-in where used. |
| et_oi_services | localStorage | 720 days | Stores the user's choice (acceptance or refusal) per category or provider. |
| _et_coid | localStorage | 720 days (configurable) | Used to recognize users by means of a virtual expiry timestamp. |
| isSdEnabled | cookie | 24 hours | Indicates whether scroll depth measurement is active. |
| et_scroll_depth | sessionStorage | Session | Buffers scroll measurement data for ScrollMap reports. Set when scroll tracking is enabled. |
| et_cssSelectors | sessionStorage | Session | Cache for the configuration of events defined by CSS selectors. |
| et_tagManagerEntries | sessionStorage | Session | Cache for the trigger configuration of the etracker Tag Manager. |
| et_tagManagerVars | sessionStorage | Session | Cache for the variable configuration of the etracker Tag Manager. |
Source: https://help.etracker.com/en/article/cookies-used/. retrieved 2026-10-04.
Friendly CaptchaFriendly Captcha GmbH, Germany
- Provider
- Friendly Captcha GmbH
- Hosting
- Run by the provider
- Legal entity
- Friendly Captcha GmbH, Germany
- Third countries
- None named by the provider
- Data Privacy Framework
- Not checked
- Purpose
- Bot detection on forms. According to Friendly Captcha, the data is only used to identify and handle potential bots and risks.
Cookies and storage
The provider documents no cookies or storage entries.
Source: https://friendlycaptcha.com/legal/privacy-end-users/. retrieved 2026-10-04.
63 more services, by name
Every entry has the same fields as the ones above.
- Adobe Fonts
- Awin Affiliate-Tracking (MasterTag)
- Brevo
- Bunny Fonts
- Calendly (embedded scheduling page)
- Cloudflare Turnstile
- Cloudflare Web Analytics
- Criteo OneTag
- econda Analytics
- Facebook (social plugins, embedded posts)
- Fathom Analytics
- Google Ads Conversion Tracking / Remarketing
- Google Fonts
- Google Maps
- Google reCAPTCHA
- Google Tag Manager
- Hotjar
- HubSpot
- Infomaniak Newsletter
- Instagram (embedded post)
- Intercom Messenger
- Klarna On-site Messaging / Checkout-Widget
- Klaviyo (onsite tracking and forms)
- LinkedIn Insight Tag
- Mailchimp
- Mapbox GL JS
- Mapp Intelligence
- Matomo Cloud
- Microsoft Advertising Universal Event Tracking (UET)
- Microsoft Clarity
- Mollie Components / Checkout
- Mouseflow
- OpenStreetMap (Tile-Server)
- PayPal
- Payrexx
- Pinterest Tag
- Piwik PRO Analytics Suite
- Plausible Analytics
- Plausible Community Edition
- PostFinance Checkout
- PostHog (self-hosted)
- PostHog Cloud
- ProvenExpert Bewertungssiegel
- Sentry
- Sentry (self-hosted)
- Shopware 6
- SoundCloud (eingebetteter Player)
- Spotify (embedded player)
- Stripe
- swisstopo maps (geo.admin.ch)
- TikTok (embedded videos)
- TikTok Pixel
- Trustpilot TrustBox
- Typeform
- Umami (self-hosted)
- Umami Cloud
- Vercel Web Analytics
- Vimeo
- Worldline Saferpay
- X (embedded posts)
- X Pixel (Conversion-Tracking)
- YouTube
- Zendesk Web Widget (Messaging)
From entry to config
The catalog contains facts with a source, not a legal assessment. The category is set by you, the operator, when you turn an entry into a service.
toConsentService takes over name, provider, purpose, cookies and privacy policy link. You add the category. The catalog cannot set it for you, and entries may not contain one.
import { catalog, toConsentService } from "@weber-development/permito-catalog"
const entry = catalog.find((e) => e.id === "google-analytics-4")
if (!entry) throw new Error("Entry not found")
// The category is your decision. The catalog never sets it.
const service = toConsentService(entry, { category: "statistics" })Scanner
ScannerA recorded run.
The scanner loads a page in headless Chromium without clicking anything and compares what it sees with your consent config. It reports and changes nothing.
This is a recorded run against a demo page, not a live check. The config for the run lists one service, Google Analytics 4.
Scanned page: http://127.0.0.1:4317/
- Not in your config
- 3
- Active before consent
- 4
- Matched, for information
- 0
Not in your config
3A cookie, storage key or third-party host that no configured service accounts for. Where the catalog knows a match, it suggests an entry. Whether it belongs in your config, and in which category, is your decision.
connect.facebook.nethostCatalog suggestions: Facebook (social plugins, embedded posts) (
facebook-embed), Meta Pixel (meta-pixel)fonts.googleapis.comhostCatalog suggestions: Google Fonts (
google-fonts)www.facebook.comhostCatalog suggestions: Meta Pixel (
meta-pixel)
Active before consent
4The entry belongs to a configured service that needs a decision, and it was present before any consent existed. This is an observation, not an assessment. A possible cause is a script that is not gated or a tag manager that loads it regardless.
_ga_DEMO123456cookieService:
google-analytics-4, Category:statistics_gacookieService:
google-analytics-4, Category:statisticsregion1.google-analytics.comhostService:
google-analytics-4, Category:statisticswww.googletagmanager.comhostService:
google-analytics-4, Category:statistics
Run it yourself
npx permito scan https://client.example --config consent.config.tsExit code
This run: 1
0No findings.1At least one finding, not in your config or active before consent.2Error during the run, for example an unreachable page or a missing Chromium.
A clean run is a snapshot, not proof. The scanner does not click, scroll or log in, so it misses what loads only after an interaction.
Consent log
Consent logStored on your server.
The log package is not part of this demo, so nothing is recorded here. This is what it stores per change of consent, and the route handler that receives it.
One record
{
"id": "6f1c0b0e-4a52-4d0e-9b57-0e2a3f6c8d11",
"visitorHash": "9b1d5c3a7e0f42a8c6d4b2e19f08a7d3c5e6b4a1f2d0c9e8b7a6f5d4c3b2a190",
"timestamp": "2026-10-05T09:41:12.000Z",
"consentVersion": "2026-10",
"categories": { "necessary": true, "statistics": true, "marketing": false },
"services": {},
"source": "banner",
"region": "CH",
"language": "de-CH"
}Example record with made-up values.
- Stored
- The record is kept in a store you choose, on your infrastructure. The visitor ID is hashed with a secret salt and the ID itself is not stored.
- Not stored
- No IP address and no user agent. Fields the client adds are discarded.
Once the log runs, you process personal data. The retention period is required and has no default. Whether and how you use it is your decision.
Next.js route handler
// lib/consent-log.ts
import { createConsentLog } from "@weber-development/permito-log"
import { fileStore } from "@weber-development/permito-log/file"
export const log = createConsentLog({
store: fileStore(process.env.CONSENT_LOG_FILE ?? "./data/consent-log.jsonl"),
salt: process.env.CONSENT_LOG_SALT!, // at least 32 characters
retentionDays: 90, // your decision, there is no default
})
// app/api/consent-log/route.ts
import { createConsentLogRoute } from "@weber-development/permito-log/next"
import { log } from "@/lib/consent-log"
export const runtime = "nodejs"
export const { POST } = createConsentLogRoute(log, {
allowedOrigins: ["https://www.example.ch"],
})Two files: the log, and the route that receives the browser's POST.
Next step
Use it in your own projectPricing is per person.
After checkout, Polar gives your GitHub account access. The Pro packages then install from GitHub Packages with a read-only token.
Permito is technical consent infrastructure, not legal advice.