Consent handled
inside Umbraco
Install the package and the banner is on every page. Categories, gated scripts, appearance and translations live in the backoffice, consent statistics stay in your database, and nothing is sent to an external consent service.
Free and open source under MIT. No licence file, no domain restrictions, no tiers.
Google Consent Mode v2
out of the box
Basic and Advanced modes, off by default and switched on when you use Google tags. Each script is assigned to a category and only runs after the visitor consents to it; rejecting clears the cookies the category lists, GA4 and common marketing cookies included.
Auto or manual
Middleware injects the banner into every HTML response, or you place it yourself with the JavaScript API. Headless frontends use the REST API.
Your brand, your words
Layout, position, colours and radius under Settings. Texts translated through the Umbraco Dictionary.
Withdraw as easily as give
A floating button reopens preferences after the banner is dismissed, as GDPR requires.
Self-hosted
and Umbraco-native
Consent for Google Analytics, Matomo, Adobe Analytics and the usual marketing tags, with configuration, labels and statistics in Umbraco and no external consent service in the runtime path. A commercial CMP still makes sense for Google Ads workflows or vendor-managed compliance.
Data stays with you
Consent decisions are logged anonymously in your Umbraco database with a configurable retention - 90 days by default.
Consent statistics
Accept, reject and custom rates on a Statistics dashboard, so you can see what the banner actually does.
Open source
Wraps the widely used orestbida/cookieconsent library. MIT licence, issues and pull requests on GitHub.
FOR DEVELOPERS
Up and running in four steps
The short version. The full guide with screenshots, configuration reference and troubleshooting is in the developer docs.
-
1 · Install the package
dotnet add package Flowcourier.Umbraco.CookieConsent. Tables are created on first startup, and in Auto mode the banner is already injected on every page.
Terminal -
2 · Review the categories
Settings → Cookie Consent → Categories. Necessary is always on; enable Analytics, Marketing and Preferences as your site actually uses them.
Backoffice -
3 · Add your scripts
Replace the example scripts with your GA4, Meta Pixel or LinkedIn snippets and assign each to a category. They only execute after consent to that category.
Backoffice -
4 · Test in a private window
Accept or reject and check the console: gated scripts run only after consent. Then switch on Consent Mode v2 if you use Google tags, and translate the texts via the Dictionary.
Browser
Is it really free?
Yes. MIT licence, no licence file, no domain restrictions, no tiers.
When is this the right package?
When you need consent handling for analytics tools such as Google Analytics, Matomo or Adobe Analytics, want the configuration, labels and translations managed in the Umbraco backoffice, need Google Consent Mode v2 for the common scenarios, and prefer a self-hosted runtime with no mandatory external consent service.
How is this different from Cookiebot or another consent management platform?
It is self-hosted and Umbraco-native: configuration, translations and statistics live in your Umbraco installation, and no external service sits in the runtime path. A commercial CMP still earns its fee when your site runs Google Ads and needs Google's certified CMP workflows around ad personalisation, or when you need vendor-managed compliance processes, automatic cookie scanning and audit tooling. For a standard site with analytics and a few marketing tags, this package covers the requirements.
Which Umbraco versions?
Umbraco 17 or later on .NET 10.
Do I need consent for cookieless analytics?
Often yes. In the EU, ePrivacy Article 5(3) covers any storing of or access to information on the visitor's device, not only cookies, and the EDPB's guidelines read that to include scripts that collect screen size, language or user agent. A few countries exempt first-party audience measurement, France for example, while others do not, so the safe default is to put Plausible, Fathom or cookieless Matomo in the Analytics category and only run them consent-free where your regulator allows it. Server-side or log-based analytics that use nothing beyond the request itself fall outside Article 5(3), with GDPR still applying to the IP processing. Outside the EU the picture varies: the UK mirrors ePrivacy, while most US state laws focus on opt-out rather than a banner. Footnote for Denmark, where we are based: there is no analytics exemption, so consent applies.
Can I use it with a headless frontend?
Yes. Set the integration mode to Headless and use the NPM package with the public REST API, with CORS origins allowed for your frontend domain.
Need a hand with the consent setup?
We can install it, wire up your tags and Consent Mode, and verify the gating with you in a private window.