Consent Mode v2 Payload Inspector & Parameter Debugger
Browser-based debugger that inspects live Google Analytics and Google Ads payloads to verify gcd and gcs Consent Mode v2 compliance.
Consent Mode v2 Signal Architecture
Traces user consent state from CMP consent banner choices to gtag.js consent API, Google tag interceptors, and network hit query parameters (&gcd= and &gcs=) delivered to Google servers.
Consent Mode v2 Payload Inspector & Parameter Debugger Configurator
Google Consent Mode v2 — Network Payload & Parameter Debugger
Diagnostic inspection and validation of Consent Mode v2 network parameters (gcd=13t3t3t3t5 & gcs=G111).
1 Input Parameters & Assumptions
| Parameter | Value | Context & Provenance |
|---|---|---|
| GCD Parameter Value | 13t3t3t3t5 URL Parameter | Consent Mode v2 4-signal state string |
| GCS Parameter Value | G111 Legacy Parameter | Legacy 3-character consent header |
| Diagnostic Target | EEA / DMA Compliance Regulatory Standard | European Economic Area Digital Markets Act advertising mandate |
2 Explicit Mathematical Formula
GCD Parameter Extraction: gcd=13t3t3t3t5 (clean letters: t, t, t, t)
Signal 1 (ad_storage): "t" -> Granted by default
Signal 2 (analytics_storage): "t" -> Granted by default
Signal 3 (ad_user_data): "t" -> Granted by default (Consent Mode v2 Mandate)
Signal 4 (ad_personalization): "t" -> Granted by default (Consent Mode v2 Mandate)
Legacy GCS Extraction: gcs=G111 (Ad Storage: true, Analytics Storage: true)
Consent Mode v2 Compliance: PASS (Both ad_user_data and ad_personalization signals explicitly declared)3 Computed Output Metrics
| Computed Metric | Result | Interpretation & Threshold |
|---|---|---|
| Ad Storage (ad_storage) | Granted Signal Status | Cookies and browser storage for advertising authorized |
| Analytics Storage (analytics_storage) | Granted Signal Status | Analytics identifiers and measurement storage authorized |
| Ad User Data (ad_user_data) | Granted v2 Mandate | Consent Mode v2 requirement: user data transmission to Google Ads authorized |
| Ad Personalisation (ad_personalization) | Granted v2 Mandate | Consent Mode v2 requirement: remarketing and audience list matching authorized |
| Compliance Rating | PASS Audit Result | Payload fully compliant with Google Consent Mode v2 requirements |
Consent Mode v2 Payload Inspector & Parameter Debugger — Scope & Limitations
Explicit operational boundaries and constraints defining target use cases and out-of-scope scenarios.
Built For (Target Use Cases)
- Decoding and generating Google Consent Mode v2 gcd and gcs parameter strings from GA4 and Google Ads hits.
- Checking whether the ad_user_data and ad_personalization signals required by Consent Mode v2 are present.
- Pasting a raw request URL or gcd/gcs string to inspect consent signal status without a live CMP.
Not Built For (Limitations & Out-of-Scope)
- Verifying that a live Google Tag Manager or CMP is actually enforcing the decoded consent signals.
- Auditing consent signals from platforms other than Google Analytics and Google Ads network requests.
- Detecting whether a CMP fires before or after Google tags load on the page.
Operational Assumptions & Defaults
- Assumes the pasted gcd or gcs string is well-formed; malformed values are read as unspecified, not flagged.
- Treats each of the four consent signals independently and does not check cross-signal consistency.
- Only ad_user_data and ad_personalization are treated as the v2 compliance mandate signals.
Google Consent Mode v2 Inspector & Signal Generator
EEA & DMA 2026 CompliantDecode and reverse-engineer Google Tag Manager &gcd= and &gcs= hit parameters into human-readable signals. Verify European Digital Markets Act compliance and simulate cookieless pings.
Payload Parameter Input
10-Character Bitmask Mapping Reference
Google Consent Mode v2 uses a 4-position bitmask string with delimiters:1<ver><ad_storage>3<analytics>3<ad_user_data>3<ad_personalization>5. Letters represent default/explicit consent states (r/q: default granted/denied, t/u: updated granted/denied, m/p: denied with grant update).
Decoded Consent Mode Signals
4 Mandatory Signal States
ad_storageGRANTEDanalytics_storageGRANTEDad_user_dataGRANTEDad_personalizationGRANTEDDiagnostics & Recommendations
- Consent Mode v2 fully verified. All storage and advertising signals are active and granted.
Deploy Consent Mode v2 Default & Update Snippets
Place the default consent configuration BEFORE GTM or gtag.js container initialization to guarantee zero cookie drops prior to user consent.
Must run synchronously at the very top of <head> before any Google tags.
<!-- Consent Mode v2 Default State: Place before GTM/gtag.js -->
<script>
window.dataLayer = window.dataLayer || [];
function gtag(){dataLayer.push(arguments);}
gtag('consent', 'default', {
'ad_storage': 'denied',
'analytics_storage': 'denied',
'ad_user_data': 'denied',
'ad_personalization': 'denied',
'wait_for_update': 500
});
gtag('set', 'ads_data_redaction', true);
gtag('set', 'url_passthrough', true);
</script>Understanding the GCD and GCS Parameter Syntax
Under the Digital Markets Act (DMA), Google mandates four distinct consent signals: ad_storage, analytics_storage, ad_user_data, and ad_personalization. The gcd parameter encodes the default and updated states of all four signals into an alphanumeric sequence.
Parameter Debugging & Payload Inspection
Consent Mode v2 introduces two additional parameter signals (ad_user_data and ad_personalization) alongside the existing ad_storage and analytics_storage flags.
Decoding GCD and GCS Strings
When inspecting network payloads in browser developer tools:
- `gcs` Parameter: A 3-character string representing basic consent state (e.g.
G100means denied,G111means granted). - `gcd` Parameter: A structured string encoding the default and updated consent states across all four categories using specific letter codes (
1for ungranted,pfor granted).
Common Implementation Pitfalls
- Race Conditions: Firing analytics tags before the CMP banner has initialised default consent signals, leading to default grant assumptions in non-compliant regions.
- Missing Update Commands: Failing to push the
gtag('consent', 'update', ...)event immediately when a visitor accepts cookie preferences in the CMP banner. - iFrame Signal Loss: Embedded checkout forms or third-party widgets failing to inherit parent window consent parameters.
Related Resources
- Pair this inspector with our GA4 Audit Checklist for complete analytics governance.
- See our Client-Side vs Server-Side Tracking Guide for consent routing in server containers.
Changelog
- 1.0.0 (2026-08-01T08:00:00+10:00): Initial release supporting gcd string tokenisation and DMA mandate compliance rating.
Consent Mode v2 Network Verification
Inspect network requests in Chrome DevTools for &gcs= and &gcd= parameters to confirm DMA compliance before and after consent interaction.
Pre-Production Verification Checklist
Ensure initial hits carry gcs=G100 (ad_storage denied, analytics_storage denied) or G100 equivalent.
Inspect &gcd= parameter to verify presence of ad_user_data and ad_personalization signals.
Confirm subsequent network hits after clicking "Accept All" carry gcs=G111 and updated gcd bitmask.
Terminal Diagnostic & Debug Commands
Dumps current internal Google Tag consent entries and grant status directly from browser memory.
google_tag_data.ics.entriesFailure Remediation & Troubleshooting
Cause: CMP is only running Consent Mode v1 (ad_storage/analytics_storage) without v2 DMA parameters.
Fix: Upgrade CMP template in GTM and ensure gtag("consent", "default") includes all 4 parameter keys.
Cause: GTM container script was placed above the gtag("consent", "default") block in HTML.
Fix: Move the consent default initialization script to position 1 inside the <head> tag.
How to cite and attribute this tool
MIT LicenceThis resource is free, open and un-gated under the MIT Open Source Licence. You are encouraged to use, integrate and cite it with attribution:
@misc{geraghty_consent_mode_v2_inspector,
author = {Geraghty, Gordon},
title = {Consent Mode v2 Payload Inspector & Parameter Debugger},
year = {2026},
url = {https://gordongeraghty.com/resources/gtm-analytics/consent-mode-v2-inspector},
note = {Head of Performance Media, Empire Amplify}
}Changelog & Version History
v1.0.0Initial release supporting gcd string tokenisation and DMA mandate compliance rating.
Strategic Takeaway & Operational Guidelines
Without valid ad_user_data and ad_personalization signals in the gcd string, Google Ads immediately drops audience remarketing and conversion modeling for European traffic. This inspector verifies all 4 signals fire accurately.