Checklist

Cookie audit vs cookie scanner: what’s the difference?

Start a free audit

A cookie scanner lists names from a crawl. A cookie audit records Fresh and Reject: cookies, storage, and Network before Accept. Not a second hub.

In brief

A cookie scanner usually lists cookie names, hosts, or tags from a crawl. A cookie audit for consent work records cookies, storage, and Network on Fresh before Accept, then again after Reject. The list can feed an inventory. It does not show whether marketing fired before Accept or whether Reject held. ConsentProbe runs that runtime check. A free US-baseline scan is not an EU or California legal conclusion. This FAQ is not a second hub and not legal advice.

Not legal advice

This FAQ compares the labels cookie audit and cookie scanner, and the observation each label usually describes. It is not legal advice, not a scored vendor bake-off, not a CMP review, and not a GDPR, ePrivacy, CPRA, or other compliance certificate. ConsentProbe reports are technical observations of what fired under labeled visits. They do not say what counsel would allow. Observation is not counsel permission.

Last updated October 1, 2026. The before-Accept audit owns the protocol. The testing hub owns which test is next. Audit versus banner owns CMP UI versus an audit. CMP claims versus runtime owns banner text versus the wire. The evidence pack owns the handoff file. This FAQ only splits inventory language from a Fresh and Reject pack. It does not open a second cookie-audit hub, and it does not define cookie audit in a separate essay.

Short answer

A cookie scanner usually means an automated inventory: cookie names, hosts, or tags discovered on a crawl. A cookie audit, in consent work, means labeled runtime evidence. That pack records cookies, storage, and Network on Fresh, before Accept, and again after Reject or another labeled state. A scanner file can feed an inventory. It does not by itself show whether marketing fired before Accept, or whether Reject held.

Marketing copy uses the two labels as synonyms. Read what the file actually records. A cookie-name table with no consent-state label is an inventory. A Fresh and Reject pack with cookies, storage, and Network is the consent-audit job.

Open the before-Accept audit for the steps, the testing hub for which test is next, audit versus banner when the mix-up is the CMP screen, CMP claims versus runtime when the banner sentence is the claim, and the evidence pack when you hand findings over. The product landing is the cookie audit page. ConsentProbe is a runtime cookie audit. It does not install a CMP, and it does not brand itself as a site-wide scanner. A free US-baseline scan is not an EU or California legal conclusion.

Labels and the job they skip

The table names the phrase people use, the file that phrase often produces, and the gap if you stop there. Prefer a sentence such as the report has no Reject label. Leave rankings and statutory duties with counsel.

Scanner, cookie audit, and banner-check labels, and what each file usually omits.
Label people sayOften meansMisses if you stop there
Cookie scanner or crawlCookie or tag inventory on one or more URLsConsent-state labels and a Reject comparison
Cookie audit for consentFresh before Accept, plus Reject, Accept, or GPC packsTreating a cookie-name PDF as a legal ruling
CMP or banner checkUI copy and controlsNetwork on Fresh and Reject

When each file is enough

Match the file to the question. An inventory and a runtime pack answer different sentences. These steps do not paste the how-to or the evidence-pack body.

  1. A privacy-notice draft that needs a cookie or tag list can start from a scanner-style inventory. Still verify runtime before you treat the list as what fired before Accept.
  2. Did tags fire before Accept? Run the Fresh protocol on the before-Accept audit: cookies, storage, and Network, with no Accept click.
  3. Does Reject stop marketing? Use a Reject pack, then the Reject leftovers guide and the marketing-pixels FAQ. Do not stop at the Accept path.
  4. Hand findings to engineering or counsel from the evidence pack surfaces. One URL, one state name, cookies, request URLs, and screenshots.
  5. Write one finding sentence per gap, such as the scanner PDF has cookie names and no Reject label, or Fresh Network shows an ads host before any click.

When the pitch was a scan

If the pitch was that someone scanned your cookies, and you still need before-Accept proof, run Fresh and Reject on the storefront URL. The cookie audit product page says what that browser recording includes. Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide draws that line.

ConsentProbe records cookies, storage, and requests under labeled visits and ties findings to a request, a cookie, or a screenshot. It does not install a CMP. A free US-baseline scan is not an EU or California legal conclusion. This FAQ is label hygiene for the two phrases. It is not a second cookie-audit hub.

FAQ

Cookie audit vs cookie scanner: what’s the difference?

A scanner is usually an inventory of cookie names, hosts, or tags. A consent cookie audit is labeled Fresh and Reject runtime: cookies, storage, and Network.

Is a cookie scanner enough before Accept?

Not by itself. You need a Fresh capture, with no Accept click, of cookies, storage, and Network. A name list does not show whether marketing fired.

Is this the same as audit versus banner?

No. Audit versus banner compares an audit with the CMP screen. This FAQ compares an audit with scanner inventory language.

Is this a second cookie-audit hub?

No. The testing hub stays the page that picks the next test. This FAQ does not open a second cookie-audit hub.

Does ConsentProbe call itself a scanner?

Product language is a runtime cookie audit before Accept. The product landing records cookies and requests in a browser. ConsentProbe does not install a CMP.

Is this legal advice?

No. These are technical observations. It is not legal advice. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.

Limits of this page

This FAQ splits a scanner-style inventory from a Fresh and Reject cookie audit. It is not legal advice, not a second cookie-audit hub, and not a definition essay for cookie audit. Observation is not counsel permission. ConsentProbe does not install a CMP. A free US-baseline scan is not an EU or California legal conclusion.

Related guides

Open the before-Accept audit for the steps, the testing hub for which test is next, audit versus banner for the CMP screen, CMP claims versus runtime for banner text, and the evidence pack for the handoff. The product landing is the cookie audit page.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

Save a US-baseline technical record

After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.

Cookie audit vs cookie scanner | ConsentProbe