Skip to content

Google Tag Manager & Consent Mode

Magento 2.4.7 – 2.4.9 Luma Hyvä

A store copies its production database to staging every night, and the next morning its Analytics shows a dozen test orders. The Google Tag Manager snippet pasted into the HTML Head came along with the data. The same snippet does nothing on the checkout, where Adobe Commerce and Magento Open Source 2.4.7 and later run a strict Content Security Policy with inline scripts switched off – exactly the page where conversions happen. And Google Consent Mode v2 wants its defaults set before the container loads, which a pasted snippet never does.

Google Tag Manager & Consent Mode is an extension for Magento Open Source and Adobe Commerce that replaces the pasted snippet with a loader built for those three problems. It loads the container on every storefront page of Luma and Hyvä Theme, with the noscript fallback, and only when the store's base URL host is on a list of production hosts. Staging and local copies of the database therefore send nothing, and an empty list loads nothing anywhere – the module cannot be enabled without at least one host.

On the checkout, the loader sets the page's nonce on gtm.js and pushes it to the dataLayer as cspNonce, so Custom HTML tags can carry it too. The hosts your tags load from or send to are listed in the admin and added to the storefront policy on every page, the checkout included; the field accepts hostnames only, so it cannot be used to switch the policy off.

Consent Mode v2 defaults are set in the same script, before the container: every signal denied in the EEA, the United Kingdom and Switzerland, granted or denied elsewhere as configured, with optional ads data redaction and URL passthrough. Updates come from Magento's own cookie notice on Luma and Hyvä Theme, or are left to a consent platform.

Your tags, triggers and variables stay in Tag Manager. The extension pushes no ecommerce events, sends nothing from the server and adds no database table. It is free and open source.

Key Features

  • Google Tag Manager container on every storefront page, Luma and Hyvä Theme
  • Noscript fallback right after the opening body tag
  • Staging guard: loads only when the store's base URL host is a listed production host
  • An empty host list loads nothing; the module cannot be enabled without a host
  • The guard reads the configured base URL, never the host a browser sends
  • Page nonce set on gtm.js on the strict-CSP checkout
  • Nonce pushed to the dataLayer as cspNonce for Custom HTML tags
  • Tag hosts added to script-src, connect-src and img-src from the admin
  • Host fields accept hostnames only; *, schemes and CSP keywords are refused
  • Consent Mode v2 defaults set before the container loads
  • Every signal denied in the EEA, the UK and Switzerland; your choice elsewhere
  • Consent updates from Magento's cookie notice on Luma and Hyvä Theme
  • External consent platform mode: defaults only, the platform sends updates
  • Ads data redaction and URL passthrough switches
  • Configurable gtm.js base URL for server-side Tag Manager or Google tag gateway
  • Container ID validated and normalised on save
  • Own ACL resource for the configuration section
  • Full-page-cache friendly; no database tables

Versions

v1.0.0 Oct 09, 2026

First public release.

Added

  • Your Google Tag Manager container on every storefront page, Luma and Hyvä Theme alike, with the noscript fallback right after the opening body tag. Full-page-cache friendly.
  • Staging guard. The container loads only when the store's base URL host is on your list of production hosts, so staging and local copies of the production database send no hits and no test orders. An empty list loads nothing, and the module cannot be enabled without at least one host.
  • Strict-CSP checkout. On pages that carry a Content Security Policy nonce – the checkout since Magento 2.4.7 – the nonce is set on gtm.js and pushed to the dataLayer as cspNonce, ready for Custom HTML tags.
  • Your tag hosts in the storefront Content Security Policy. List the hosts your tags load from or send to under "Additional Tag Hosts"; they are added to the policy on every storefront page, the checkout included.
  • Google Consent Mode v2. Defaults are set before the container loads: every signal denied in the EEA, the UK and Switzerland, granted or denied elsewhere as you choose, with optional ads data redaction and URL passthrough. Updates come from Magento's own cookie notice on Luma and Hyvä Theme, or are left to your consent platform.
  • Your own gtm.js address for server-side Tag Manager or Google tag gateway, under "GTM Script Base URL".
  • Validation on save for the container ID, the host lists and the base URL; a bare * or a CSP keyword is refused.

FAQ

Adobe Commerce and Magento Open Source have no Tag Manager integration, so most stores paste the snippet into the HTML Head. That snippet travels with every copy of the database, so staging sends test traffic and test orders to the real Analytics and Ads accounts; it is blocked on the checkout, which runs under a strict Content Security Policy since 2.4.7; and it sets no Consent Mode defaults. This extension for Magento replaces the snippet with a loader that handles all three, while your tags stay in Tag Manager.

  • You manage your tags in Google Tag Manager and want the container on every page of Luma or Hyvä Theme without editing templates.
  • You copy production to staging or to developer machines and have seen test orders in your reports – or want to make sure you never will.
  • Tags must run on the checkout: a pixel in a Custom HTML tag, a conversion tag, a heatmap script.
  • You sell into the EEA, the UK or Switzerland and need Consent Mode v2 defaults set before the container, with updates from Magento's own cookie notice or from your consent platform.
  • You need GA4 ecommerce events (view_item, add_to_cart, purchase) pushed to the dataLayer. Use a data-layer module for that. Most of them also load the container, and only one module should – check before installing both.
  • You need purchases and refunds sent from the server, or Conversions API connections for other ad platforms.
  • Your store runs Hyvä Checkout (the Magewire checkout). It has not been tested with this extension.

It loads your container in the head of every storefront page and adds the noscript fallback after the opening body tag, on Luma and Hyvä Theme, without breaking full-page cache. It loads only when the store's base URL host is on your list of production hosts; an empty list loads nothing, and the module cannot be enabled without a host. On the checkout it sets the page's nonce on gtm.js and pushes it to the dataLayer as cspNonce for Custom HTML tags, and it adds the tag hosts you list to the storefront Content Security Policy. It sets Consent Mode v2 defaults before the container – denied in the EEA, the UK and Switzerland, your choice elsewhere – and updates them from Magento's cookie notice, or leaves updates to your consent platform. The gtm.js base URL can point at server-side Tag Manager or Google tag gateway. Every field is validated on save, and the section has its own admin permission.

  • No ecommerce data layer: no product, cart, checkout or purchase events.
  • No server-side events, no Measurement Protocol, no Conversions API for Meta, TikTok or other platforms.
  • No cookie banner of its own: it reads Magento's cookie notice or leaves consent to your platform, and it ships no adapters for third-party GDPR modules.
  • No tags, triggers or container templates: everything inside the container is yours.
  • Nothing loads on admin pages, and nothing for headless or GraphQL storefronts.

Reviews

No reviews yet. Be the first to share your experience.

Sign in to write a review.