Skip to content

Web JS API Reference

Last updated: October 4, 2026

This reference covers documented public browser APIs for CYBEXO Web CMP Engine deployments.

window.initCybexoCMP(options?)

Purpose:

  • initializes the CYBEXO CMP runtime when using a supported manual initialization path

Most customers should use the loader script, GTM template, or CMS plugin rather than calling this directly.

window.showCMPBanner(force?)

Purpose:

  • opens or reopens the CMP UI

Parameters:

  • force (boolean, optional): when true, reopens UI even if prior consent exists

Example:

window.showCMPBanner?.(true);

window.openCMPSettings()

Purpose:

  • opens the second-layer preferences modal directly when the runtime is ready

Example:

if (typeof window.openCMPSettings === 'function') {
window.openCMPSettings();
}

A function’s existence alone does not establish readiness: the entry point opens only after configuration and applicable TCF delivery are ready. Reopening preserves an unsaved draft; closing with X cancels it. See the direct Web setup for the startup and failure checks.

window.cybexoReportConversion(detail?)

Purpose:

  • records a consent-aware conversion signal when the runtime is available

Example:

window.cybexoReportConversion?.({
event: "lead_submit",
value: 1
});

window.__tcfapi(command, version, callback, parameter?)

Purpose:

  • standard IAB TCF API endpoint exposed by the CMP runtime

Common commands:

  • ping
  • addEventListener
  • removeEventListener
  • displayConsentUi

Example:

window.__tcfapi("displayConsentUi", 2, () => {});

Use addEventListener for current and subsequent TCData instead of the deprecated getTCData command. See TCF API validation for listener lifecycle and cleanup.

window.__gpp(command, callback, parameter?, version?)

Purpose:

  • standard IAB GPP API endpoint exposed by the CMP runtime where enabled

Common commands:

  • ping
  • addEventListener
  • removeEventListener
  • getGPPData

window.cybexoDebugConsent(showUI?)

Purpose:

  • runs runtime diagnostics for Consent Mode ordering, TCF availability, and loader health

Parameters:

  • showUI (boolean, optional): when true, opens the debug overlay

Examples:

window.cybexoDebugConsent?.();
window.cybexoDebugConsent?.(true);

For direct Web CMP 1.5.30 or later, window.cybexoGetConsentState() returns:

{
ready: false,
decisionMade: false,
analyticsStorageGranted: false,
pending: false
}

All four fields are booleans. The API contains no visitor identifiers or TC String. ready means initialization and applicable consent dependencies succeeded. decisionMade means a completed visitor choice or a validated saved choice exists; a regional automatic grant alone is insufficient. Saved-choice validation for this publisher contract covers direct Web TCF and Google-ready properties; unsupported stored regional history remains undecided until a new explicit action. analyticsStorageGranted is effective permission for Google Analytics: it requires the independent Analytics choice and, in TCF, the applicable Google vendor755 consent. It is not simply the Analytics checkbox value. This gate also applies when Consent Mode commands are off. pending covers a refusal being applied, including applicable vendor withdrawal, before persistence finishes.

Listen on window for cybexo:consent-state, then call the getter again. Register the listener before the CMP loader and also read once when installing your integration, so an earlier readiness event cannot be missed. If the API is absent, throws, has an unexpected shape, is not ready, has no decision, or is pending, do not start optional Analytics.

A refusal is exposed immediately while pending is true, before downstream Google updates. Stop collection immediately; wait for the completed state with pending: false before a navigation that depends on saving. Grants become usable only after completion or validated restoration. Opening preferences or closing an unsaved draft is not a grant.

The GA4 publisher example uses this contract for Basic/full-off tag blocking. It does not derive Analytics from an advertising purpose or read private CMP storage. This API is a direct Web contract; other platform integrations have their own interfaces.

  • API availability depends on successful loader initialization.
  • Keep custom calls behind existence checks in production.
  • Consent action internals are handled by the CMP UI.