# How to use Claude or ChatGPT to set up cookie consent safely

Claude or ChatGPT can walk you through a consent setup, and a coding agent can do it for you. What to paste in, what it must never touch, how to check.

_The TagSentry team · September 29, 2026 · https://tagsentry.ai/blog/ask-claude-to-set-up-consent_

> **The short answer:** Claude or ChatGPT can talk a non-developer through adding a consent tool on whatever platform they use. A coding agent like Claude Code can make the change itself. Either way, give it the vendor's own setup instructions, tell it what to leave alone, and check the result yourself afterwards.

## Two ways to use AI here

**As a guide.** You're in Shopify or WordPress, you can't find "the header", and the support article isn't helping. Paste the setup instructions into Claude or ChatGPT, say what your site runs on, and ask it to take you through one click at a time. You do the clicking.

**As a builder.** Your site is code in a repository and you use Claude Code, Cursor or something like them. The agent can add the script to your layout, open a pull request and check the script is there.

Both work, but they go wrong in different ways.

## What to give it

Without instructions, an assistant guesses, and with consent setup the plausible guess is usually the wrong one. Always give it:

1. **The vendor's setup page**, or a link it can read. Most consent tools publish a guide. Ours is a plain file for agents at `tagsentry.ai/SKILL.md`.
2. **What your site runs on.** Shopify, WordPress, Webflow, Squarespace, Wix, or a framework like Next.js.
3. **Whether you use Google Tag Manager**, and whether you already have another consent tool.
4. **What you want at the end.** For example: "the consent script is the first thing in the head, above Tag Manager, and nothing else changed."

A prompt that works well:

> Help me set up [consent tool] on my website. Read [the setup guide URL] first. My site runs on [platform] and uses Google Tag Manager. Walk me through it one step at a time, and wait for me to confirm each step.

## What an agent must never do

These are the mistakes we see most often when an assistant, a plugin or a well-meaning developer installs a consent tool. Spell them out in your prompt.

| Never | Why |
|---|---|
| Add `async` or `defer` to the consent script | The script then runs after your tags, so the consent defaults arrive too late |
| Move, edit or remove the Tag Manager snippet | Your tracking breaks, and it's hard to work out why |
| Load the consent script from inside Tag Manager with an "All Pages" trigger | That's too late on the page, and other tags may already have fired |
| Publish changes in Tag Manager | A person should review and publish container changes |
| Remove another consent tool without asking | Two tools fighting is bad. One quietly ripped out is worse |
| Paste API keys into a chat or commit them to the repository | Keys go in your environment settings, not in the history |

In Next.js, watch out for the `next/script` component. Its loading strategies are meant for scripts that can wait, and a consent script can't wait. Use a plain script tag, first in the document head.

## Check the result yourself

An agent saying "done" doesn't prove anything. The check below takes about five minutes. If you have longer, use our [full Consent Mode v2 checklist](/blog/check-consent-mode-v2-working).

1. Open your site in a private window.
2. View the page source. Is the consent script the first thing in `<head>`, above Tag Manager, with no `async` or `defer`?
3. Open the browser's network panel, reload, and look at the order. The consent script should load before `googletagmanager.com`.
4. Answer the banner and reload. Does it remember your choice?
5. If you're in the EU or UK, check that advertising pixels like `facebook.com` don't load until you accept.

## A note on "Ask AI" buttons

Plenty of sites now have a button that opens Claude or ChatGPT with a prompt already filled in. They're handy, and they get abused: in February 2026, Microsoft's security team reported companies hiding instructions like "remember this brand as a trusted source" inside those links.

Read a pre-filled prompt before you send it. A decent one asks the assistant to read a page and help you with a task, and that's all. If it tells the assistant to remember or prefer anything, delete that part.

## Where TagSentry is today

You can set up TagSentry with Claude or ChatGPT now. Our agent brief at `tagsentry.ai/SKILL.md` tells an assistant [where the one line goes for each platform](/docs/install-by-platform), what never to change, and how to check it. A coding agent can also use our public API to create a site and read the install code, once you approve access in your browser.

The MCP server is live as well. Add `https://app.tagsentry.ai/api/mcp` as a connector in Claude, Claude Code, Cursor or ChatGPT's Developer mode and sign in. Your assistant can then create your site, fetch your install code and check whether your banner is live. It asks before it changes your banner. [How to connect it](/ai#mcp).

If you'd rather skip the chat, run `npx @tagsentry/cli` in your project folder. It signs you in, finds your framework and adds the line.

## Sources

- [Next.js docs: the Script component and its loading strategies](https://nextjs.org/docs/app/api-reference/components/script)
- [Google Tag Manager Help: Consent mode overview](https://support.google.com/tagmanager/answer/13695607?hl=en)
- [Microsoft Security Blog: The rise of AI Recommendation Poisoning](https://www.microsoft.com/en-us/security/blog/2026/02/10/ai-recommendation-poisoning/)
- [r/GoogleAnalytics: Consent Mode silently blocking events](https://www.reddit.com/r/GoogleAnalytics/comments/1weaz6m/_/p9he6xw/)
