Skip to content

Google Tag Manager Template Guide

Last updated: October 5, 2026

Use the Cybexo CMP Community Template to install CYBEXO CMP in a GTM web container. The template manages Google consent through native GTM APIs and loads the banner using your Web App configuration.

Release availability: The CYB-only release is available in the Gallery as Cybexo CMP. Install or update it through the normal Gallery flow and confirm the CYB App ID field before publishing your container. Do not manually edit the installed template to match this guide.

  • Copy your CYB App ID (shown as Settings ID in the dashboard) from the CYBEXO dashboard. This template release accepts only CYB- App IDs.
  • Keep Consent Mode enabled in that app’s configuration to publish visitor choices to Google through this integration.
  • Use one consent installation on each page. Remove a previous direct/CMS CMP loader and conflicting Google consent commands before switching to the template.
  • Have access to create, preview and publish tags in your GTM web container.

Adding a Gallery template does not create or publish a tag. You still need to configure a tag instance and publish the container.

For a TCF installation, the TCF API must be available before scripts that depend on it run. Paste the complete inline TCF bootstrap block near the start of each page’s <head>, before the GTM container snippet and other TCF-dependent scripts.

Keep the block synchronous: do not add async, defer or type="module", and do not put this early block in a GTM Custom HTML tag. Apply your site’s Content Security Policy nonce or script hash where required. The inline form makes the early API independent of a bootstrap network request.

You may instead load the production bootstrap synchronously:

<script src="https://cmp.cybexo.com/tcf-bootstrap.js"></script>
<!-- Your normal GTM container snippet follows. -->

With an external script, verify successful delivery and CSP permission on the actual site. You can also host the matching bootstrap file yourself and use its real deployed URL.

This block provides the early TCF API and queues requests while the CMP loads. It does not grant consent or load a second banner. GTM alone cannot provide an API before GTM executes. The block is required for TCF installations; a configuration that does not use TCF does not need it.

Section titled “2. Install and configure the Gallery template”
  1. In GTM, open Templates → Search Gallery.
  2. Search for Cybexo CMP and add the Gallery-linked template.
  3. Open Tags → New, select Cybexo CMP, and enter your CYB App ID.
  4. Review the fields below. Keep denied global defaults unless your consent configuration requires otherwise.
  5. Select Consent Initialization – All Pages as the trigger.
  6. Save and preview the workspace before publishing.
Field Behavior
CYB App ID Paste the actual CYB- Web App ID from the dashboard, without a URL or extra query parameters. Legacy IDs are rejected and consent remains denied.
Global Defaults (JSON) Set each Google key to granted or denied. Omitted or invalid values are denied. Malformed JSON denies all four values.
Region Override List (CSV, optional) Comma-separated valid country/subdivision codes, such as DE, FR, US-CA. Leave blank for global defaults only.
Region Override Defaults (JSON, optional) Overrides for the listed regions. Omitted keys or blank optional JSON inherit global defaults. Explicit invalid values deny that key; malformed nonblank JSON denies all four.
Wait for Update (ms) Accepts 500–10,000 milliseconds, inclusive. Invalid or out-of-range values use 500 milliseconds.

Denied global defaults:

{"ad_storage":"denied","analytics_storage":"denied","ad_user_data":"denied","ad_personalization":"denied"}

Regional defaults affect visitors in the specified regions; more specific subdivisions take precedence. Defaults are configuration, not a record of the visitor’s choice. The wait allows time for asynchronous restoration; it does not wait indefinitely for the visitor or prove that the CMP is ready.

The template uses setDefaultConsentState for defaults and updateConsentState for validated visitor choices, including saved choices and later changes. It covers ad_storage, analytics_storage, ad_user_data and ad_personalization, and sets the fixed developer ID dZTNmYW.

The template automatically passes data-consent-mode=off to the loader to disable its separate gtag command path. Native GTM updates remain enabled through the template. This installation flag is different from disabling Consent Mode in your app configuration; an app-level disabled setting prevents choice publication and is not overridden by the template.

Do not combine this setup with the direct Web gtag('consent', ...) installation snippet. Retain the synchronous TCF block when TCF is used, but let this template own Google defaults and updates.

Repeated execution shares the loader and does not reset an existing choice. A successful tag completion means the loader script loaded; configuration, vendor-list delivery and CMP readiness must still succeed. A failed loader or conflicting configuration reports failure and keeps consent denied. Fix the cause and reload; repeating a failed tag in the same page does not restore permission.

Consent Mode changes how supported Google tags behave. It does not automatically block every network request or every third-party tag. Configure and test additional tag consent checks or Basic blocking separately when your installation requires them. The direct GA4 Basic helper has its own scope and is not a general GTM blocker.

Test the version actually installed in your workspace, using a fresh visit and a returning visit:

  1. Confirm the CMP tag fires on Consent Initialization and the expected four defaults are available before Google initialization.
  2. Confirm developer ID dZTNmYW and successful loading from https://cmp.cybexo.com/loader.js.
  3. Accept, reject and change advertising/Analytics choices separately. Check the native consent values after each action and after reload.
  4. Confirm intended Google events are delivered when permitted and that tags respect withdrawal and rejection according to their configured consent checks.
  5. For TCF, confirm the early API answers ping before the loader runs, and queued listeners receive the loaded state when the CMP becomes ready in that document.
  6. Test delivery failures and recovery. A loader request or a tag marked successful alone is not proof of a working CMP.

Keep the relevant Tag Assistant and network evidence for the version you publish. Pulse can supplement installation diagnostics; a scan does not replace interaction testing or prove every visitor choice was honored.

Migrate legacy App IDs before updating this template. Complete a supported migration that preserves the app configuration and consent history, then copy the actual CYB- App ID from the dashboard. Do not replace an ID prefix by hand: changing a string does not migrate an app. If migration is unavailable, contact CYBEXO support before updating. Verify the migrated app configuration and use its actual ID in the tag.

Publish the tested GTM container. For an existing installation, review and accept the offered Gallery template update in the workspace, preview it, then publish the container. A new repository or Gallery version does not automatically change an already-published customer container.

Symptom Check and fix
No CMP tag in Tag Assistant Create the tag instance, select the intended template and publish the container.
Consent defaults are late Use Consent Initialization – All Pages and remove conflicting consent owners. Check tags loaded outside GTM.
Choices do not update native consent Confirm the current Gallery version, the correct Settings ID and app-level Consent Mode enabled. Check configuration/vendor-list delivery and competing CMP installations.
Early TCF API is missing Place the synchronous bootstrap before GTM and TCF-dependent scripts. Check CSP and bootstrap delivery; an asynchronous loader is insufficient for earlier consumers.
Legacy or invalid App ID Obtain the actual CYB- App ID from the dashboard. Complete supported migration before updating a legacy installation.
Loader failure or conflicting Settings IDs Fix blocked delivery or remove the conflicting tag/configuration, then reload. Repeating the failed tag is not recovery.
Duplicate banner or inconsistent choices Keep one CMP loader and one consent owner per page.
Banner does not appear A saved choice or regional policy may suppress it. Use a fresh browser context, check the Settings ID and inspect delivery errors.

If Google tags are delivered through a gateway, also follow the Google tag gateway load-order guide.