Guide
Getting started
composer require devix-labs/laravel-cookie-consent
php artisan vendor:publish --tag=cookie-consent-config
php artisan migrate
1. Describe your categories
config/cookie-consent.php ships with necessary, analytics and marketing. Edit the labels,
descriptions and the cookies each category clears when it is refused:
'categories' => [
['id' => 'necessary', 'label' => 'Strictly necessary', 'required' => true],
[
'id' => 'analytics',
'label' => ['en' => 'Analytics', 'ar' => 'التحليلات'],
'autoClear' => [['name' => '_ga_.*', 'pattern' => true]],
'services' => [
['id' => 'ga4', 'label' => 'Google Analytics 4', 'url' => 'https://policies.google.com/privacy'],
],
],
],
2. Put the widget on the page
{{-- layouts/app.blade.php, before </body> --}}
<x-cookie-consent policy-url="{{ route('privacy') }}" />
It renders the stylesheet, the widget with your categories, the visitor's country from your CDN's
header, and the report() call that posts each decision to POST /consent.
Attributes: policy-url, country, :log="false" to skip the endpoint, and :options="[...]" for
anything the widget accepts (layout, position, modal, theme, translations…).
3. Gate your tags
@consent('analytics')
<script src="https://example.com/analytics.js"></script>
@endconsent
@consent('marketing')
<iframe src="https://www.youtube.com/embed/xyz" title="A video"></iframe>
@endconsent
Not printing a tag at all is stronger than printing it and blocking it in the browser — and it is one fewer thing that can go wrong in a cache layer.
In PHP:
use Devix\CookieConsent\Facades\Consent;
Consent::allows('analytics'); // category
Consent::allows('analytics/ga4'); // service
Consent::allows('ga4'); // the same service, by its own id
Consent::decided(); // has anyone answered at all?
Consent::decision()->via; // 'accept-all', 'custom', 'gpc'…
4. Serve the assets yourself
The config points at our CDN. To serve everything first-party, install the widget and point the config at your build:
npm install @devix-labs/cookie-consent
'assets' => [
'js' => Vite::asset('resources/js/cookie-consent.js'),
'css' => Vite::asset('resources/css/cookie-consent.css'),
],
Changing your policy
Bump version in the config. Everyone is asked again, and until they answer, Consent::allows()
returns false for everything — so the server stops acting on consent given to wording that no longer
applies.
'version' => env('CONSENT_VERSION', 2),