What it does
`CookieConsent` stores which categories the visitor allowed, so the decision survives navigation and reloads. `CookieScriptConsent` is a different vendor’s cookie: it belongs to CookieScript, not Cookiebot, and the scanner classifies it separately.
Storage limited to remembering and enforcing a choice may be necessary. Verify the payload rather than treating every cookie written by a consent vendor as automatically exempt.
What to write in a cookie declaration
List it under necessary as a consent management cookie.
| Field | Value |
|---|---|
| Name | CookieConsent |
| Provider | Cookiebot |
| Purpose category | functional |
| Consent category | Necessary |
| Expiry | 1 year (vendor default) |
| Storage | First-party |
Treat the expiry as indicative
The value above is the vendor’s documented default. Vendors change configuration and several browsers cap script-written lifetimes. Record what repeated scans observe on your own site, with the browser, region, path and interaction state; one run is not authoritative for every visitor.
Can a visitor refuse it?
No. It records the decision; refusing it would make the decision unenforceable.
A verification scan supplies runtime evidence for the pages and states it exercises. Test a fresh profile with no choice made, then after refusal, and reconcile observed storage with response headers, server-side integrations and paths the scan did not visit.
Common questions
I migrated away from Cookiebot and still see this cookie. Why?
It may be stale browser storage or a live leftover script. Test a fresh profile, look for a new Set-Cookie event and inspect theme, plugin and container loaders before deciding. If two systems really are active, remove the overlap through a controlled cutover.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- CookieScript: cookie policy and consent cookie
Vendor documentation
Checked
- StrongPrivacy technology reference
Product documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.