检查清单
Does Braze tracking fire before Accept?
Check Braze Web SDK cookies and hosts before Accept. A gated SDK does not prove Currents or SMS stayed off. Not a Braze setup guide.
In brief
Braze can load through a Web SDK or messaging pixel, and many setups also send from the server, Currents, or an API. Check cookies, storage, and requests to js.appboycdn.com, sdk.braze.com, or rest.braze.com on Fresh, then again after Reject. Gating the Web SDK does not prove those jobs stayed quiet. ConsentProbe can store both packs. A free US-baseline scan is not an EU or California legal conclusion. This page is not a Braze campaign setup guide and not legal advice.
Not legal advice
This guide explains how to observe Braze Web SDK and messaging-pixel activity, plus any related server, Currents, or API sends, relative to Accept and Reject. It is not legal advice, not a Braze Canvas, SMS, Content Card, or in-app message setup tutorial, and not a GDPR, ePrivacy, CPRA, or other compliance certificate. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow. Observation is not counsel permission.
Last updated September 29, 2026. The before-Accept audit owns the general first load. The Reject leftovers guide owns a Reject failure. The pre-consent checklist owns the pass order. The marketing-pixels FAQ owns the wider pixel question. The party-label guide owns first-party versus third-party names. Klaviyo is the sibling check for on-site messaging plus a server path. This page stays on Braze.
Short answer
Braze often loads through a Web SDK or messaging pixel for on-site messages and identity, and many setups also send events or orchestrate SMS and email from the server or from Currents. A cookie consent audit asks whether Braze cookies, storage, or requests to js.appboycdn.com, sdk.braze.com, rest.braze.com, or related hosts appeared before Accept, and whether Reject All stopped them.
Server, Currents, or API paths can still send when the Web SDK is delayed. Treat banner text that says marketing or personalization is off as a claim. Falsify it on a clean visit. Capture Braze-related hosts and cookies on Fresh. Repeat after Reject. Note any post-Reject fan-out. Host names are examples of where a browser test can look. This page does not say which Braze cookies are essential.
Downstream SMS or API sends are harder to see from DevTools alone. Ask engineering for Braze User Profile or Currents delivery logs labeled by consent state when the browser pack is clean and Braze still shows sessions or message triggers. First-party versus third-party labeling still applies when Braze cookies sit on your domain. ConsentProbe can produce Fresh and Reject packs with request, cookie, and screenshot links.
Browser SDK and Currents sends
Three layers get mixed when someone says Braze is off because the Web SDK waits for Accept. Separate the SDK from Currents, REST, and SMS orchestration. Write the finding as a Braze host before Accept, or a host after Reject.
| Layer | What a browser test can see | What you may need engineering for |
|---|---|---|
| Braze Web SDK or messaging pixel | Cookies, storage, and Network rows to js.appboycdn.com, sdk.braze.com, or related hosts before Accept | Usually nothing beyond those browser rows |
| Braze REST, Currents, or SMS orchestration | Indirect storefront clues. DevTools rarely shows the full SMS payload | User Profile or Currents delivery logs labeled by consent state |
| CMP marketing-off or personalization-off claim | A screenshot of the banner or the category | Matching runtime on Fresh and Reject |
Fresh and Reject on the browser
These steps compare a claimed wait-for-Accept state with cookies and requests. They do not create a Braze workspace, build a Canvas, or write an SMS template. The before-Accept audit and the pre-consent checklist hold the general method.
- Use a clean profile. Load the storefront once. Do not click Accept.
- Capture cookies, storage, and Network for Braze-related hosts, including js.appboycdn.com, sdk.braze.com, and rest.braze.com.
- Screenshot the banner state. Label the pack Fresh. Note an in-app message surface if one renders before any click.
- Open a new clean profile, or clear storage. Click Reject All. Navigate once more.
- Recapture cookies and Network. Label the pack Reject. Compare it with Fresh and, if you ran one, with an Accept control.
- Write one finding sentence per mismatch, such as a Braze cookie on Fresh, or the same host after Reject.
Currents and SMS when the SDK looks gated
A quiet Web SDK and a quiet Currents or SMS path are different results. Server event posts and message orchestration can still run when the page delayed the SDK.
If Fresh and Reject look clean in DevTools and Braze still shows sessions or triggered sends, ask engineering for delivery logs tagged by consent state and timestamp. Each row should carry a label, Fresh or Reject or Accept, that you can line up with the browser pack.
Example of a storefront clue, not a customer capture: Fresh Network shows a request to js.appboycdn.com before any banner click. After Reject and one more navigation, a host under sdk.braze.com is still there. Storage keys that include ab. are clues to confirm in Application, not a complete cookie list.
This page does not walk through workspace creation, Canvas build, SMS template, or Content Card config. The question to falsify is whether a Currents, REST, or SMS send happened on Fresh or after Reject. Klaviyo uses the same browser-versus-downstream split on its own page. This page stays on Braze.
When checking Braze hosts gets slow
Checking Braze hosts across templates by hand takes a long time. ConsentProbe runs Fresh and Reject on the storefront URL. Each finding stays tied to a request, a cookie, or a screenshot.
Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide draws that line. ConsentProbe does not install or configure Braze, does not install a CMP, and does not issue a certificate. A free US-baseline scan is not an EU or California legal conclusion.
FAQ
Does Braze tracking fire before Accept?
It often does when the Web SDK is ungated. Verify Network and cookies on a Fresh visit, including js.appboycdn.com and sdk.braze.com, before you treat the banner as proof.
Does gating the Web SDK stop Braze Currents or SMS?
Not by itself. Ask engineering for delivery logs labeled by consent state. A delayed SDK leaves Currents, REST, and SMS untested.
What if Reject All still shows Braze hosts?
Treat it as a Reject failure. The Reject leftovers guide is the network check. Keep the evidence pack.
Will this page teach Braze Canvas or SMS setup?
No. This page is a Fresh and Reject check, not a Braze campaign setup guide.
How does this relate to Klaviyo?
The Fresh and Reject idea matches the Klaviyo page: browser surface plus downstream sends. The hosts differ. That page stays on Klaviyo. This page stays on Braze.
Is this legal advice?
No. These are technical observations. It is not legal advice. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.
Limits of this page
This page tells you how to check Braze browser cookies and hosts on Fresh, how to repeat the check after Reject, and why a gated Web SDK leaves Currents, API, and SMS untested. It is not legal advice, not a Braze campaign setup guide, and not a certificate. Observation is not counsel permission. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California legal conclusion.
Related guides
Open the before-Accept audit for the general first load, the Reject leftovers guide when Reject still tracks, the pre-consent checklist for the pass order, the marketing-pixels FAQ for the wider pixel question, and the party-label guide for domain names. Klaviyo, HubSpot, Meta, and Segment are the sibling checks.
- How to run a cookie audit before Accept
- Reject All still tracking
- Pre-consent audit checklist
- Does Reject All stop marketing pixels?
- First-party vs third-party cookies
- Does Klaviyo tracking fire before Accept?
- Does HubSpot tracking fire before Accept?
- Meta Pixel and CAPI before Accept
- Does Segment tracking fire before Accept?
- Cookie consent evidence pack
- Free US-baseline vs paid EU and California
- CMP claims vs runtime evidence
- Cookie audit hub
- ConsentProbe methodology
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
保存一次美国基线技术记录
完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。