Checklist

What is a TCF consent string decoder?

Start a free audit

Decode a TCF TCString to read the purposes and vendors a CMP claims, then check Fresh and Reject cookies and Network. Not a TCF SDK or install guide.

In brief

A TCF consent string decoder turns a TCString into a readable list of purposes and vendors the CMP encoded. That decode reads the claim. Fresh and Reject still show whether cookies, storage, and network hosts matched it. ConsentProbe can store those packs. A free US-baseline scan is not an EU or California legal conclusion. This page is not a TCF install guide, not a decoder product page, and not legal advice.

Not legal advice

This FAQ explains how to observe what a TCF or TCString decode shows next to Fresh and Reject runtime: cookies, storage, and Network. It is not legal advice, not an IAB TCF vendor, SDK, or CMP install tutorial, not a purpose-bitfield cookbook, and not a GDPR, ePrivacy, CPRA, or other compliance certificate. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow. Observation is not counsel permission.

Last updated September 30, 2026. The TCF string page owns string versus runtime. The CMP claims page owns banner text. The Consent Mode page owns those signals. The Reject leftovers guide owns a Reject failure. The evidence pack owns the handoff. This FAQ stays on the decoder. It does not paste those pages.

Short answer

A TCF consent string decoder turns an IAB TCF TCString into a readable view of the purposes and vendors the CMP encoded. In a cookie audit, that decode helps you read the claim. It does not prove marketing cookies, storage, or network hosts stayed off.

After you decode, or screenshot the CMP purpose UI, still run Fresh and Reject. Write one finding sentence when the decoded claim and the runtime disagree. Open the TCF string page, the CMP claims page, the Consent Mode page, the Reject leftovers guide, and the evidence pack for those frames.

The attestation FAQ is optional reading. This page does not install a TCF SDK, and ConsentProbe does not include a decoder. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe does not install a CMP and does not configure TCF.

Decode and runtime

A decoder, a CMP dashboard, and a labeled browser visit answer different questions. Keep the finding as decode and runtime disagree. Leave permission with counsel. Readers who want the longer falsification essay should open the TCF string page. This FAQ stays on the decoder question.

What a TCString decode shows, and what Fresh and Reject still have to record.
LayerWhat it isWhat it does not prove alone
TCString decode or decoder outputReadable purposes and vendors from the encoded stringThat cookies and network hosts stayed off
CMP dashboard or purpose UIAn operator-facing claim about the same stringThat the browser Network matched the UI
Fresh or Reject cookies and NetworkWhat the browser set and requested on a labeled visitLegal permission from counsel

Use a decoder in a cookie audit

These steps use a decode as a claim to compare. They do not teach TCString bit layout, vendor-list registration, or SDK install. Any public decoder or the CMP purpose UI is enough to read purposes and vendors as claims.

  1. Use a clean profile. Load the storefront once. Do not click Accept, or use the state under test, such as Reject or a claimed denial.
  2. Note that a TCString exists in DevTools or the CMP API. Optionally decode it, or read the purpose UI. Treat purposes and vendors as claims.
  3. Capture cookies, storage, and Network for ads, analytics, and marketing hosts. Label the pack Fresh, or Reject if that is the state you loaded.
  4. Write one finding sentence when the decode says limited or denied and Network looks like Accept.
  5. Keep the evidence pack for handoff. Open the TCF string page for the deeper frame, and the Reject leftovers guide when Reject is the failure.

When the decoded claim and Network disagree

Example, not a customer capture: a decoder lists a marketing purpose as not allowed, and Fresh Network still requests an ads host before any banner click. Save the request URL and a screenshot of the purpose UI.

A denied purpose does not cancel a request the tag already sent. The string page covers that split. A Consent Mode denial is a separate claim on the Consent Mode page.

ConsentProbe does not include a TCF decoder. It records Fresh and Reject so you can compare runtime with the decode. Hand-matching those claims across templates takes a long time.

FAQ

What is a TCF consent string decoder?

A tool or UI that turns a TCString into readable purposes and vendors. Use it to read CMP claims, then verify cookies and Network on Fresh and Reject.

How do you decode a TCF consent string for a cookie audit?

Note the string or the CMP purpose UI, read the claimed purposes and vendors, then capture Fresh and Reject cookies and Network and compare them with that claim.

Does decoding a TCString prove cookies stopped?

No. The decode is the claim layer. Fresh and Reject are the evidence layer. The TCF string page holds the longer comparison.

Is this a TCF SDK or CMP install guide?

No. This page is observation and falsification. It does not register a vendor, install a TCF SDK, or walk a purpose bitfield.

Does ConsentProbe include a TCF decoder?

No. ConsentProbe records Fresh and Reject evidence packs tied to requests, cookies, and screenshots. This page does not describe a decoder product.

Is this legal advice?

No. These are technical observations. It is not legal advice. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.

Limits of this page

This FAQ says a TCF decoder reads CMP claims about purposes and vendors, and Fresh and Reject still show what the browser did. It is not legal advice, not a TCF SDK install guide, and not a ConsentProbe decoder product page. Observation is not counsel permission. A free US-baseline scan is not an EU or California legal conclusion.

Related guides

Open the TCF string page for string versus runtime, the CMP claims page for banner text, the Consent Mode page for those signals, the Reject leftovers guide when Reject still tracks, and the evidence pack for the handoff. The attestation FAQ is the optional sibling for vendor badges.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

Save a US-baseline technical record

After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.

What Is a TCF Consent String Decoder? | ConsentProbe