Checklist

Does Microsoft Clarity (and Hotjar-class heatmaps/replay) fire before Accept?

Start a free audit

Check Microsoft Clarity and Hotjar-class tools before Accept. Fresh and Reject steps for cookies and requests. Not a Clarity or Hotjar setup guide.

In brief

Microsoft Clarity and Hotjar-class heatmap tools can load a script, set cookies or storage, and call their hosts on the first view. Check those surfaces on Fresh, then again after Reject All. Clarity is the named check. Hotjar is the same class, not a ranked alternative. ConsentProbe can store Fresh and Reject packs. A free US-baseline scan is not an EU or California legal conclusion. This page is not a setup guide and not legal advice.

Not legal advice

This guide explains how to observe Microsoft Clarity, and Hotjar-class heatmap or session-replay tools, relative to Accept and Reject. It is not legal advice, not a Clarity or Hotjar install tutorial, not a vendor ranking, and not a GDPR, ePrivacy, CPRA, or other compliance certificate. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow. Observation is not counsel permission.

Last updated September 28, 2026. The combined replay and heatmap checklist owns the category pass. The replay-versus-heatmaps FAQ owns which surface to check first. The before-Accept audit and the pre-consent checklist own the full first load. The first-party versus third-party guide owns party labels. This page stays on a named Clarity check, with Hotjar-class hosts recorded on the same capture.

Short answer

Microsoft Clarity and Hotjar-class heatmap or session-replay tools can inject scripts, set cookies or storage, and call their hosts on first load. A cookie consent audit asks whether those surfaces appeared before Accept, and whether Reject All stopped them. Treat CMP copy that says analytics or UX recording is off as a claim. Falsify it on a clean visit.

Capture Clarity hosts, including clarity.ms and related hosts you actually see, plus any Hotjar-class host already in inventory, on Fresh. Repeat after Reject. Note fan-out that continues after the click. Microsoft's cookie documentation names _clck and _clsk among the cookies Clarity can set. Those names are things to look for in the jar. A missing name does not prove the host stayed quiet, and a present name is a Fresh finding, not a legal verdict.

Clarity is the named runtime check on this page. Hotjar sits in the same class for observation. This page does not score one vendor against the other. Open the combined checklist for the category pass, and the replay-versus-heatmaps FAQ for check order. ConsentProbe can produce Fresh and Reject packs with request, cookie, and screenshot links. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe does not install a CMP and does not configure Clarity or Hotjar. This page is not a Clarity or Hotjar setup guide and not legal advice.

What a browser test can see

Three surfaces get mixed when a dashboard says UX recording is blocked. Separate the host you saw from the banner sentence. Write the finding as a Clarity cookie on Fresh, or a Hotjar-class host after Reject. Leave permission with counsel.

Clarity, Hotjar-class tools, and a CMP claim. What a browser test can record.
SurfaceWhat a browser test can seeNote
Microsoft ClarityCookies, storage, and Network rows to clarity.ms or related Clarity hosts before AcceptNamed-tool focus of this page. Microsoft documents cookies such as _clck and _clsk
Hotjar-class heatmaps or replaySame-class hosts, IDs, and beacons on the same Fresh captureSame observation method. Not a vendor scorecard
CMP analytics or recording-off claimA screenshot of the banner or the category labelMatching runtime on Fresh and Reject

Fresh and Reject on the storefront

These steps compare a claimed wait-for-Accept state with cookies and requests. They do not install Clarity, open a Hotjar dashboard, or pick a vendor. The combined checklist holds the wider UX-recording pass. The replay-versus-heatmaps FAQ holds check order. The before-Accept audit, the pre-consent checklist, and the party-label guide hold the neighboring method.

  1. Use a clean profile. Load the storefront once. Do not click Accept.
  2. Capture cookies and storage, and Network rows, for Clarity hosts such as clarity.ms and for any Hotjar-class host already in the inventory.
  3. Screenshot the banner state. Label the pack Fresh.
  4. Open a new clean profile, or clear storage. Click Reject All. Navigate once more.
  5. Recapture cookies and Network. Label the pack Reject. Compare it with Fresh and, if you ran one, with an Accept control.
  6. Write one finding sentence per mismatch, such as a Clarity cookie on Fresh, or a Hotjar-class host after Reject.

Same class, not a scorecard

Hotjar and similar heatmap or replay products share Clarity's audit question. Did the script, cookie, or request appear before Accept? Name the hosts you actually see on that visit. This page does not publish a ranked list, and it does not tell you which host to block.

If the inventory lists Clarity only, still sweep the same Fresh capture for other UX-analytics hosts. A second host on that capture is another finding, not a product comparison.

Example, not a customer capture: Fresh Network shows a request to www.clarity.ms before any banner click. After Reject and one more navigation, the same host is still there, or a Hotjar-class host from the inventory appears. That pair is a finding about the browser. It does not rank the tools.

Category depth lives on the combined replay and heatmap checklist and on the replay-versus-heatmaps FAQ. This page stays on Clarity plus the same-class note.

When checking heatmap hosts gets slow

Checking Clarity and Hotjar-class hosts across templates by hand takes a long time. ConsentProbe runs Fresh and Reject on the storefront URL. Each finding stays tied to a request, a cookie, or a screenshot.

Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide draws that line. ConsentProbe does not install or configure Clarity or Hotjar, does not install a CMP, and does not issue a certificate.

FAQ

Does Microsoft Clarity (and Hotjar-class heatmaps/replay) fire before Accept?

They often do when the script is ungated. Verify Network and cookies on a Fresh visit, including clarity.ms and related hosts, before you treat the banner as proof.

Is Hotjar the same check?

Same class of heatmap or replay observation. Capture Hotjar-class hosts on the same Fresh visit. This page does not rank Hotjar against Clarity.

What if Reject All still shows Clarity hosts?

Treat it as a Reject failure. The Reject leftovers guide is the network check. Keep the evidence pack.

How is this different from the replay checklist and the replay-versus-heatmaps FAQ?

The checklist is the combined category pass. The FAQ is the check-order comparison. This page is the named Clarity check, with Hotjar-class hosts on the same capture.

Will this page teach Clarity or Hotjar setup?

No. This page is a Fresh and Reject check, not a Clarity or Hotjar setup guide.

Is this legal advice?

No. These are technical observations. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.

Limits of this page

This page tells you how to check Clarity hosts and cookies on Fresh, how to include Hotjar-class hosts on the same capture, and how to repeat the check after Reject. It is not legal advice, not a Clarity or Hotjar setup guide, not a vendor ranking, and not a certificate. Observation is not counsel permission. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California legal conclusion.

Related guides

Open the combined checklist for replay and heatmaps, the replay-versus-heatmaps FAQ for check order, and the before-Accept audit plus the pre-consent checklist for the full pass. The party-label guide covers first-party versus third-party names.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

Save a US-baseline technical record

After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.

Does Microsoft Clarity Fire Before Accept? | ConsentProbe