Cookie consent banner
The Agreely cookie banner installs with one HTML tag, served from a single
origin (cdn.agreely.ca) that you add to your CSP in three lines, without
unsafe-inline. Every cookie decision produces a consent identifier (consentId)
tied to a tamper-evident proof anchored on Base. Agreely helps document and
demonstrate Law 25 compliance; your organization, as the responsible party,
remains accountable for the legal validity of its consent.
The banner is a capability of the same Agreely platform, available to every account and billed separately. Every account gets one free site, then $15/month per site in your own brand (see pricing).
Contents of this guide
- Installation - the single tag, your site key, tag-based verification, the reopen link
- CSP and CORS - the minimal allowlist, nonce, SRI
- Google Consent Mode v2 and GTM - default-deny signal and tag manager integration
- Blocking scripts -
type="text/plain", iframe placeholders - Inventory and categorization - scan, categories, "to review" queue and the publish gate
- Enforcement self-test - zero-click scan, honest per-kind count, staging origins, monthly drift alert
- Server side - httpOnly cookies, PHP and Node
- The banner designer - logo, colors, position (bottom-right by default), policy links, FR|EN language switcher
- Verification and security - tag-based verification, origin binding (403 refusal), public site key, honest boundaries
- Verify a proof - the
/verifypage, what the on-chain proof does and does not claim - Pricing - a capability of the platform, billed separately; buy places, create free sites, assign places
- Sub-processor: Anthropic - the LLM categorizer and outside-Quebec communication
- Troubleshooting - cookies still present after refusal, CSP issues, banner not showing, staging