Back to the help center

Troubleshooting

Content Security Policy (CSP) errors

Allow consent scripts/styles when CSP blocks them

If the banner or scripts fail to load due to CSP, update your policy.

Common errors

  • Console shows blocked script/style from getcookies domains.
  • Banner missing; CSP blocks loader.js or inline styles.

Fix

  • Allow the GetCookies script domain in script-src (e.g., https://app.getcookies.co).
  • If using inline styles/scripts, add the required nonces/hashes or allow 'unsafe-inline' (least preferred).
  • Update connect-src if consent calls are blocked.

Test

  • After updating CSP, reload with DevTools open and confirm no CSP violations.
  • Verify the banner appears and network requests succeed.

Still stuck?

Email [email protected] with your domain and what you tried. Signed-in customers can also open a ticket from the dashboard.