检查清单

Do GA4 cookies fire before Accept?

开始免费审计

Check _ga, _gid, and gtag requests before Accept and after Reject. Consent Mode signals are not cookie proof. Not a GA4 or Consent Mode setup guide.

In brief

GA4 can set cookies such as _ga and send gtag requests on the first load when the tag is not gated. Check the jar and the network on Fresh, then again after Reject. A Consent Mode denied signal can sit next to a live _ga row. ConsentProbe can store the packs. A free US-baseline scan is not an EU or California legal conclusion. This page is not a GA4 or Consent Mode setup guide and not legal advice.

Not legal advice

This FAQ explains how to observe GA4 and gtag cookies and network activity, including _ga, _gid, and related names, relative to Accept and Reject. It is not legal advice, not a GA4 install or Consent Mode setup tutorial, and not a GDPR, ePrivacy, CPRA, or other compliance certificate. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow. Observation is not counsel permission.

Last updated September 28, 2026. The Consent Mode page owns signal versus cookie depth. The first-party analytics FAQ owns the label question. The GTM guide owns container fan-out. The before-Accept audit and the pre-consent checklist own the full first load. This page stays on observational GA4 cookie and network proof.

Short answer

GA4 can set cookies such as _ga and send gtag or Google Analytics network requests on first load when those tags are not gated. A cookie consent audit asks whether those surfaces appeared before Accept, and whether Reject All stopped them. Consent Mode default or update signals are not the same thing as cookie proof. A denied signal can sit next to a live _ga row when the runtime path is wrong.

Treat CMP or Consent Mode copy that says analytics is off as a claim. Falsify it on a clean visit. Capture _ga, _gid, and related cookies, plus gtag or Google Analytics hosts, on Fresh. Repeat after Reject. Note fan-out that continues after the click. Google's published GA4 cookie table names _ga and a _ga_ container cookie. A _gid row can still appear when an older analytics tag is on the page. Record the names you see.

Open the Consent Mode page when the question is signal versus cookie. Open the first-party analytics FAQ for labels, and the GTM guide when the tags ride a container. ConsentProbe can produce Fresh and Reject packs with request, cookie, and screenshot links. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe does not install a CMP and does not configure GA4 or Consent Mode. This page is not a GA4 install or Consent Mode setup tutorial and not legal advice.

Cookies, network, and signals

Three surfaces get mixed when a tag settings screen says analytics storage is denied. Separate the cookie row from the signal. Write the finding as _ga present before Accept, or a gtag host after Reject. Leave permission with counsel.

GA4 cookies, gtag network, and Consent Mode signals. What a browser test can record.
SurfaceWhat a browser test can seeCommon miss
_ga, _gid, and related GA4 cookiesCookie jar on Fresh, before AcceptTreating a first-party host as essential without a runtime check. The first-party analytics FAQ and the essential-cookies FAQ own that label
gtag or Google Analytics networkNetwork rows to Google Analytics or gtag hosts before AcceptTreating a Consent Mode denied state as proof that no request left
Consent Mode signalsA dashboard or CMP claim about denied or granted storageTreating signal state as cookie evidence. The Consent Mode page owns that contrast

Fresh and Reject on the storefront

These steps compare a claimed analytics-off state with cookies and requests. They do not install a GA4 property, paste a gtag snippet, or set Consent Mode defaults. The Consent Mode page holds signal versus cookie depth. The first-party analytics FAQ holds the label. The GTM guide holds container fan-out. The before-Accept audit and the pre-consent checklist hold the full method.

  1. Use a clean profile. Load the storefront once. Do not click Accept.
  2. Capture cookies and storage for _ga, _gid, and related names. Capture Network for gtag or Google Analytics hosts.
  3. Screenshot the banner state. Label the pack Fresh.
  4. Open a new clean profile, or clear storage. Click Reject All. Navigate once more.
  5. Recapture cookies and Network. Label the pack Reject. Compare it with Fresh and, if you ran one, with an Accept control.
  6. Write one finding sentence per mismatch, such as _ga on Fresh, or a gtag host after Reject.

Signals are not the cookie jar

Consent Mode can report denied while cookies or network requests still appear. That gap is why the Consent Mode page exists. This FAQ stays on the cookie and network rows you can point at.

Google's consent mode reference describes cookieless pings when analytics storage is denied. A ping is still a network row. It does not prove the jar stayed empty, and a denied signal does not prove the ping stayed off. Record both.

This page does not walk through Consent Mode default or update configuration. The question to falsify is whether _ga, _gid, or a gtag host appeared on Fresh or after Reject. Signals and cookie proof are different captures. Open the Consent Mode page for that depth.

When checking GA4 across containers gets slow

Checking GA4 cookies across templates and GTM containers by hand takes a long time. ConsentProbe runs Fresh and Reject on the storefront URL. Each finding stays tied to a request, a cookie, or a screenshot.

Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide draws that line. ConsentProbe does not install GA4, does not configure Consent Mode, does not install a CMP, and does not issue a certificate.

FAQ

Do GA4 cookies fire before Accept?

They often do when the tag is ungated. Verify _ga, _gid, and gtag network rows on a Fresh visit before you treat the banner as proof.

Does Consent Mode stop GA4 cookies automatically?

Not by itself. A denied signal and a cookie row are different captures. The Consent Mode page is that contrast.

What if Reject All still shows _ga?

Treat it as a Reject failure. The Reject leftovers guide is the network check. Keep the evidence pack.

Are first-party GA4 cookies essential?

A first-party name is a label. The first-party analytics FAQ and the essential-cookies FAQ cover that label. This page records whether the cookie appeared before Accept.

Will this page teach GA4 or Consent Mode setup?

No. This page is a Fresh and Reject check, not a GA4 or Consent Mode setup guide.

Is this legal advice?

No. These are technical observations. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.

Limits of this page

This page tells you how to check _ga, _gid, and gtag network rows on Fresh, how to repeat the check after Reject, and where to open the Consent Mode page when the question is signals versus cookies. It is not legal advice, not a GA4 or Consent Mode setup guide, and not a certificate. Observation is not counsel permission. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California legal conclusion.

Related guides

Open the Consent Mode page for signal versus cookie depth, the before-Accept audit and the pre-consent checklist for the full pass, the first-party analytics FAQ for labels, and the GTM guide when tags ride a container.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

保存一次美国基线技术记录

完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。

Accept 前的 GA4 Cookie | ConsentProbe