Back to Knowledge Hub

Automated Cookie Scanning: How It Works

·1 min read

The Challenge of Cookie Discovery

Modern websites can load dozens of third-party resources, each capable of setting cookies, writing browser storage, or sending identifiers over the network. Manual review alone is hard to repeat. Automated scanning creates a useful, reproducible evidence set, but it is one input to an audit rather than a final compliance verdict.


How 1Consent's Scanner Works

Headless browser: A Chromium-based browser visits configured pages and executes JavaScript in a representative automated session.

Observable evidence: The scan records cookies, localStorage and sessionStorage entries, and network resources observed during the journey.

Decision modes: A deep scan can exercise an accept-all journey, while a separate Global Privacy Control audit tests the opt-out path and records what still happens.

Classification with a review gate

1Consent first reconciles observations with a curated knowledge base and heuristics. An optional AI classifier can suggest a category when evidence remains unclear, but the result is visibly sourced and requires human review before it becomes a published consent declaration. A network destination alone cannot prove a controller's legal purpose.

Know what a scan can miss

Scanning is a point-in-time observation. Geolocation, login state, A/B tests, delayed interactions, tag-manager rules, and third-party outages can change the result. Scan representative pages and regions, test more than one decision state, review unknown items, and rerun after releases or vendor changes.

The most accurate consent banner is one that reflects exactly what your site does — not what you think it does.
A
Artur WachelkaFounder & CEO

Building transparent consent infrastructure for the modern web.