Skip to content

TCF API Validation

Last updated: October 4, 2026

Use this guide to verify that TCF API signals are available and consistent.

typeof window.__tcfapi

Expected: function.

If not available:

  • confirm CMP script loaded successfully
  • confirm no CSP block
  • confirm no duplicate or outdated CMP script

Use the event-listener API rather than the deprecated getTCData command:

let listenerId;
window.__tcfapi('addEventListener', 2, (data, success) => {
if (!success || !data) return;
listenerId = data.listenerId;
console.log({
cmpStatus: data.cmpStatus,
eventStatus: data.eventStatus,
gdprApplies: data.gdprApplies,
enableAdvertiserConsentMode: data.enableAdvertiserConsentMode
});
});

Expect current valid TCData and later updates as the relevant state changes. A visible first-choice UI reports cmpuishown, restored consent reports tcloaded, and a completed choice reports useractioncomplete. The separate Analytics preference may change without changing the TC string. Function existence alone does not establish successful initialization or consent.

if (listenerId !== undefined) {
window.__tcfapi('removeEventListener', 2, removed => {
console.log('Listener removed:', removed);
}, listenerId);
}

Do not leave repeated diagnostic listeners installed indefinitely. A dependency failure must not publish invented consent: inspect ping, error state and the recovery path, then retest the actual Google state separately.

4. Validate Disclosed Vendors Segment (High Level)

Section titled “4. Validate Disclosed Vendors Segment (High Level)”

For enterprise reviews, confirm that your decoder or verification tool indicates disclosed vendor information is present for configured vendor sets.

  • cmpStatus: stub persists (CMP did not initialize fully).
  • eventStatus never moves beyond loading state.
  • TC string present but stale after preference change.

Include:

  • Settings ID
  • affected URL
  • browser and version
  • output of checks from this page
  • debug report from Cybexo Debug Tool