Skip to content

CYBEXO Web CMP Engine Setup

Last updated: October 4, 2026

Use this guide for direct website installations. Copy the complete snippet from your property’s Integration page after publishing its settings. Use the exact App ID shown in your dashboard, such as CYB-YOUR_APP_ID; do not substitute another property’s ID. Existing IDs remain valid unless your account has completed an explicit migration.

Put the complete block first in <head> on every page, before Google tag initialization, other measurement scripts and TCF consumers. Keep the small TCF bootstrap synchronous; the main loader is asynchronous. Both assets come from the same production release host.

The default installation enables Consent Mode:

<!-- CYBEXO CMP: place first in <head>, before Google tags and TCF consumers. -->
<script>
window.dataLayer = window.dataLayer || [];
window.gtag = window.gtag || function () { window.dataLayer.push(arguments); };
window.gtag('set', 'developer_id.dZTNmYW', true);
if (!window.__nxgCMDefaultSet) {
window.gtag('consent', 'default', {
ad_storage: 'denied',
analytics_storage: 'denied',
ad_user_data: 'denied',
ad_personalization: 'denied',
wait_for_update: 500
});
window.__nxgCMDefaultSet = true;
}
</script>
<script src="https://cmp.cybexo.com/tcf-bootstrap.js"></script>
<script async
id="cybexo-cmp"
data-settings-id="CYB-YOUR_APP_ID"
data-consent-mode="on"
data-api-url="https://api.cybexo.io"
data-assets-url="https://cmp.cybexo.com"
src="https://cmp.cybexo.com/loader.js">
</script>
<!-- End CYBEXO CMP. Google tags may follow when your chosen mode permits. -->

Google tag configuration may follow this block in advanced mode. The four initial defaults are denied while configuration loads. Validated regional policy and saved or new visitor choices produce later updates. An intentionally hidden regional banner can grant the configured Google state; a blocked or invalid dependency cannot be treated as that scenario. The 500 ms wait is a bounded Google delay, not a substitute for early defaults.

If the main loader fails, the independent default remains denied and the TCF API remains a stub. Do not run optional tags merely because a function or locator iframe exists. Configure your Content Security Policy to authorize the inline block with a nonce or matching hash and allow the required asset, configuration and applicable vendor-list requests. Do not add broad wildcard permissions. Apply the same nonce to all relevant script elements when your policy requires it.

Do not combine this direct installation with a second CMP or the GTM template on the same page. GTM uses its native consent APIs and its own setup instructions; do not paste this block into a Custom HTML tag.

Advanced: leave Consent Mode enabled, install the complete on snippet above, and allow consent-aware Google tags to load after the bootstrap. Verify defaults, updates and actual tag behavior in Tag Assistant.

Basic tag blocking: keep Consent Mode enabled and configure the publisher’s tag manager or integration to prevent Google tags from loading before the required affirmative choice. For one direct GA4 destination, use the complete Basic/full-off publisher example with Web CMP 1.5.30 or later. Verify no initial Google request before a grant, immediate withdrawal handling, and no Google load on the following denied page. Distinguish an already loaded tag’s transition behavior from a fresh denied page. This blocking behavior is a separate part of the publisher installation; the CMP’s Consent Mode setting alone does not block third-party scripts.

Full Consent Mode off: turn Consent Mode off in the dashboard, publish that setting, and replace the existing installation with the newly generated off snippet. Remove the old inline Google bootstrap and any separately installed gtag_enable_tcf_support = true override. The direct off snippet retains the TCF stub and consent UI, but does not queue Google defaults or updates, and disables the CMP’s advertiser-consent-mode inference flag. If Google tags remain in use, a separately implemented consent-aware blocker is required; verify it before making the page public.

<script src="https://cmp.cybexo.com/tcf-bootstrap.js"></script>
<script async
id="cybexo-cmp"
data-settings-id="CYB-YOUR_APP_ID"
data-consent-mode="off"
data-api-url="https://api.cybexo.io"
data-assets-url="https://cmp.cybexo.com"
src="https://cmp.cybexo.com/loader.js">
</script>

Changing a dashboard setting cannot undo inline defaults already executed by an older snippet. To return to advanced mode, publish Consent Mode on, replace the full installation with the on snippet, and remove only the intentional Google-tag blocking rules after verifying consent behavior. Preserve unrelated security and consent controls.

These direct-script off instructions do not replace the GTM template’s ownership configuration. See Google Consent Mode validation and Google’s basic and advanced definitions.

Keep a visible privacy choices link or button on each page. The built-in floating control uses the same preferences entry point. A publisher control can call:

if (typeof window.openCMPSettings === 'function') {
window.openCMPSettings();
}

The entry point opens only when configuration and applicable TCF delivery are ready. A function’s existence alone is not a readiness check. Opening preferences is not consent. Repeated opening preserves an unsaved draft; closing with X cancels that draft. Choices change only through an explicit completed action.

Use a fresh browser session and Tag Assistant. Check:

  1. Correct App ID and approved domain; current bootstrap, loader, configuration and vendor list load successfully.
  2. In advanced mode, all four denied defaults precede Google initialization; acceptance and mixed choices produce the expected updates.
  3. Turn only Analytics off, then reload. Analytics remains denied even when the TCF advertising-purpose string is unchanged.
  4. Reject All and reload; optional consent stays denied and the privacy control still opens.
  5. Block each required dependency in a controlled test and verify no fabricated consent grant, then remove the block and verify recovery.
  6. Separately test your configured no-banner regional case. A primary worldwide-TCF demonstration is a different configuration.
  7. In basic/full-off installations, verify the publisher’s actual network blocking and withdrawal behavior, not just the CMP switch.

For an observable command log, this handles both arrays and the standard gtag arguments objects:

(window.dataLayer || [])
.map(entry => Array.isArray(entry) ? entry :
Object.prototype.toString.call(entry) === '[object Arguments]' ? Array.from(entry) : null)
.filter(entry => entry && entry[0] === 'consent');

Queued commands are not proof of effective Google consent or collection. Use Tag Assistant for that distinction. For late signals, first verify whether the Google tag uses Google tag gateway. See TCF API validation and Web consent receipts for the related checks.