Google tag gateway
Google tag gateway for advertisers serves your Google tags (Google Analytics,
Google Ads, Tag Manager) from your own domain instead of from Google's. The
Google tag loads from a path on your site, for example yoursite.com/metrics/,
and its measurement requests go through that path too. Your CDN, load balancer
or web server passes them on to Google. For Google's own explanation, see
Google tag gateway for advertisers.
How it affects consent
Google tags must receive the consent default before they run. OptSens sends the default from its script, so the script has to load before any Google tag. See Google Consent Mode v2.
The gateway is often turned on with one click at a CDN such as Cloudflare. With that setup the CDN adds the Google tag to your pages itself, and you no longer control where it loads. If the Google tag runs before the OptSens script, Google receives the consent default late.
Check whether your site uses it
- OptSens check. The Consent Mode check on the Integration page, and the per-page check that runs with the cookie scan when Consent Mode is on, recognise a Google tag served through your own domain. When it runs before the consent default, the result says Google tag gateway runs before the consent default.
- Tag Manager. In your container, go to Admin and open Google tag gateway to see whether it is set up for your tags.
- Browser. Open your site with the developer tools on the Network tab.
With the gateway, the Google tag loads from your own domain (for example
/metrics/) instead ofwww.googletagmanager.com.
If the consent default arrives late
Choose one of these. Google recommends the first.
1. Advanced Consent Mode with Google's data settings
- In OptSens, go to Frameworks and set Consent Mode type to Advanced. See Advanced and basic consent mode.
- In the Google tag settings of your Google Ads, Analytics or Campaign Manager 360 account, open Manage data transmission and choose the data transmission controls that limit what Google tags send before consent. See Data transmission controls.
- In the same Google tag settings, click Show more, open Override consent mode defaults and set consent to denied for the regions where you show a banner. Google tags then start denied there even when they load before OptSens. See Set consent mode override in Configure your Google tag settings.
Google tags then start with consent denied, send only what you allowed, and switch to the visitor's choice as soon as OptSens sends it.
2. One Tag Manager container through the gateway
Put all your Google tags in one Tag Manager container and serve that container through the gateway. Add the OptSens template to the same container with the Consent Initialization - All Pages trigger, so it sets the consent default before any other tag fires. See Google Tag Manager.
Remove any Google tag that is added to your pages outside the container, for example by the CDN. Otherwise that tag can still run first.
3. Set up the gateway yourself
Instead of the one-click CDN option, set up the gateway on your own server or CDN
rules, as described in Google's
setup guide.
You then add the Google tag to your pages yourself and can load the OptSens
script first, at the top of <head>.
Why advanced consent mode is recommended
With advanced consent mode, Google tags load under the default state and wait for the visitor's choice before they send full data. That works however the gateway is set up, including a manual gateway where you control the order yourself, which is why Google recommends it for tags served through the gateway.
Regions where no banner shows
Choose only the regions where you show an opt-in banner in Override consent mode defaults. If a region without a banner starts denied, visitors there would stay denied, because nobody asks them. OptSens also covers this: where your geo rules show no opt-in banner, it sends the rule's values as a consent update straight away, so Google tags there get what the rule says. See Defaults per region.