Skip to content
Devix Open Source

Reference

Options

createCookieConsent(options)

Option Type Default What it does
categories Category[] — Required.
version string | number 1 A change re-asks everyone.
storage StorageOptions cookie, 182 days Where the decision lives.
regime string | Regime | 'auto' 'default' Which rules apply.
country string | () => string | Promise<string> — 'DE', 'US-CA'.
regimes Record<string, Regime> — Your own rule sets.
honourSignals boolean the regime decides GPC and DNT as a refusal.
consentMode boolean | ConsentModeOptions false Google Consent Mode v2.
nonce string — Copied onto every script we unblock.
reloadOnWithdraw boolean false Reload when something already running loses consent.
noticeHash string — Stored with the decision as proof of the wording.
report (record) => void — Send the decision to your server.
layout 'box' | 'bar' | 'center' 'box'
position 'bottom-left' | … | 'top-center' 'bottom-left'
modal boolean false Dim and block the page until a choice is made.
language string | 'auto' 'auto' Reads <html lang>.
policyUrl string — Link in the notice.
headingTag 'h1'…'h4' | 'p' | 'div' 'h2' Keeps your page outline intact.
theme 'light' | 'dark' | 'auto' 'auto'
container HTMLElement document.body
classNames Partial<Record<ConsentPart, string>> — Your classes on every part.
strings / translations see below English Every word.
autoShow boolean true Show the notice as soon as a decision is needed.

A category

{
  id: 'analytics',
  label: 'Analytics',                   // or { en: 'Analytics', ar: 'التحليلات' }
  description: 'How the site is used',
  required: false,                      // cannot be switched off
  preselected: false,                   // pre-ticked in an opt-out regime
  autoClear: [{ name: '_ga_.*', pattern: true }],
  cookies: [{ name: 'x', duration: '1 year', description: '…' }],
  services: [/* … */],
}

A service

{
  id: 'ga4',
  label: 'Google Analytics 4',
  description: 'Counts visits',
  url: 'https://policies.google.com/privacy',
  needs: ['gtm'],        // stays off until gtm is on
  defaultOn: true,       // on when its category is accepted wholesale
  cookies: [/* … */],
}

Storage

Option Default
name 'dx_consent' Cookie or storage key.
mode 'cookie' 'local' to use localStorage instead — your server then cannot read it.
days 182 Also how long before the decision expires and is asked again.
domain — .example.com shares one decision across subdomains.
sameSite, secure, path Lax, on HTTPS, /

The instance

Call Does
record() The stored decision, or null.
allowed() A set of category ids, service ids and category/service keys.
accepted(key)
needsDecision() Nobody decided, it expired, or your version moved on.
acceptAll() / rejectAll() / save(keys) / withdraw()
show() / hide() / showPreferences() / hidePreferences()
language() / setLanguage(code)
regime() The rule set in force.
on(event, handler) firstconsent, change, show, hide, showpreferences, hidepreferences. Returns an unsubscribe.
apply() Re-run blocking and Consent Mode — after you inject new markup.
destroy()

The record

{
  "id": "3f2a…",
  "createdAt": "2026-09-12T09:14:22.881Z",
  "updatedAt": "2026-09-12T09:14:22.881Z",
  "categories": ["necessary", "analytics"],
  "services": ["analytics/ga4"],
  "refused": ["marketing"],
  "version": 1,
  "via": "custom",
  "regime": "gdpr",
  "language": "en-GB",
  "noticeHash": "sha256-…",
  "revision": 2
}

via is one of accept-all, reject-all, custom, gpc, dnt, api or implied.

The core, with no UI

import { createConsentState, applyBlocking, consentModeUpdate, readConsent } from '@devix-labs/cookie-consent/core';

Drive consent from your own settings screen, or read the decision on the server from the dx_consent cookie — it is JSON.

Updated 15 Sep 2026