Web JS API Reference
Last updated: October 4, 2026
This reference covers documented public browser APIs for CYBEXO Web CMP Engine deployments.
1. Initialize CMP
Section titled “1. Initialize CMP”window.initCybexoCMP(options?)
Purpose:
- initializes the CYBEXO CMP runtime when using a supported manual initialization path
Most customers should use the loader script, GTM template, or CMS plugin rather than calling this directly.
2. Show CMP UI
Section titled “2. Show CMP UI”window.showCMPBanner(force?)
Purpose:
- opens or reopens the CMP UI
Parameters:
force(boolean, optional): whentrue, reopens UI even if prior consent exists
Example:
window.showCMPBanner?.(true);3. Open Preferences
Section titled “3. Open Preferences”window.openCMPSettings()
Purpose:
- opens the second-layer preferences modal directly when the runtime is ready
Example:
if (typeof window.openCMPSettings === 'function') { window.openCMPSettings();}A function’s existence alone does not establish readiness: the entry point opens only after configuration and applicable TCF delivery are ready. Reopening preserves an unsaved draft; closing with X cancels it. See the direct Web setup for the startup and failure checks.
4. Report Conversion
Section titled “4. Report Conversion”window.cybexoReportConversion(detail?)
Purpose:
- records a consent-aware conversion signal when the runtime is available
Example:
window.cybexoReportConversion?.({ event: "lead_submit", value: 1});5. TCF API
Section titled “5. TCF API”window.__tcfapi(command, version, callback, parameter?)
Purpose:
- standard IAB TCF API endpoint exposed by the CMP runtime
Common commands:
pingaddEventListenerremoveEventListenerdisplayConsentUi
Example:
window.__tcfapi("displayConsentUi", 2, () => {});Use addEventListener for current and subsequent TCData instead of the deprecated getTCData command. See TCF API validation for listener lifecycle and cleanup.
6. GPP API
Section titled “6. GPP API”window.__gpp(command, callback, parameter?, version?)
Purpose:
- standard IAB GPP API endpoint exposed by the CMP runtime where enabled
Common commands:
pingaddEventListenerremoveEventListenergetGPPData
7. Debug Helper
Section titled “7. Debug Helper”window.cybexoDebugConsent(showUI?)
Purpose:
- runs runtime diagnostics for Consent Mode ordering, TCF availability, and loader health
Parameters:
showUI(boolean, optional): whentrue, opens the debug overlay
Examples:
window.cybexoDebugConsent?.();window.cybexoDebugConsent?.(true);8. Independent Analytics consent state
Section titled “8. Independent Analytics consent state”For direct Web CMP 1.5.30 or later, window.cybexoGetConsentState() returns:
{ ready: false, decisionMade: false, analyticsStorageGranted: false, pending: false}All four fields are booleans. The API contains no visitor identifiers or TC String. ready means initialization and applicable consent dependencies succeeded. decisionMade means a completed visitor choice or a validated saved choice exists; a regional automatic grant alone is insufficient. Saved-choice validation for this publisher contract covers direct Web TCF and Google-ready properties; unsupported stored regional history remains undecided until a new explicit action. analyticsStorageGranted is effective permission for Google Analytics: it requires the independent Analytics choice and, in TCF, the applicable Google vendor755 consent. It is not simply the Analytics checkbox value. This gate also applies when Consent Mode commands are off. pending covers a refusal being applied, including applicable vendor withdrawal, before persistence finishes.
Listen on window for cybexo:consent-state, then call the getter again. Register the listener before the CMP loader and also read once when installing your integration, so an earlier readiness event cannot be missed. If the API is absent, throws, has an unexpected shape, is not ready, has no decision, or is pending, do not start optional Analytics.
A refusal is exposed immediately while pending is true, before downstream Google updates. Stop collection immediately; wait for the completed state with pending: false before a navigation that depends on saving. Grants become usable only after completion or validated restoration. Opening preferences or closing an unsaved draft is not a grant.
The GA4 publisher example uses this contract for Basic/full-off tag blocking. It does not derive Analytics from an advertising purpose or read private CMP storage. This API is a direct Web contract; other platform integrations have their own interfaces.
9. Notes
Section titled “9. Notes”- API availability depends on successful loader initialization.
- Keep custom calls behind existence checks in production.
- Consent action internals are handled by the CMP UI.