Cookie library

The euconsent-v2 cookie

The IAB Transparency and Consent Framework string, a compact encoding of purposes and vendors that travels down the programmatic advertising chain.

Set by
IAB TCF
Classified as
functional
Typical expiry
Up to 13 months under TCF policy
Storage
First-party

What it does

`euconsent-v2` holds a Transparency and Consent Framework string. Depending on the framework version and configuration, it can encode CMP metadata, purpose-level consent and legitimate-interest signals, vendor-level signals and policy-version information. `addtl_consent` is Google’s Additional Consent string for vendors outside the TCF Global Vendor List; neither string should be paraphrased as blanket consent.

The string is used when an advertising stack, publisher, demand partner or platform such as Google Ad Manager requires the IAB Transparency and Consent Framework. Real-time bidding is a common case, not the only possible reason.

What to write in a cookie declaration

List it under necessary as a consent management cookie, and name TCF specifically: the string is meaningful to people auditing your ad stack.

FieldValue
Nameeuconsent-v2
ProviderIAB TCF
Purpose categoryfunctional
Consent categoryNecessary
ExpiryUp to 13 months under TCF policy (vendor default)
StorageFirst-party

Treat the expiry as indicative

The value above is the vendor’s documented default. Vendors change configuration and several browsers cap script-written lifetimes. Record what repeated scans observe on your own site, with the browser, region, path and interaction state; one run is not authoritative for every visitor.

Common questions

Do I need a TCF consent string?

Only if your advertising stack or partners require TCF. Real-time bidding is a common reason, but demand partners, publisher tooling, Google Ad Manager or contractual requirements can also make it relevant. Named vendors and category controls do not by themselves answer that integration question.

Does StrongPrivacy emit a TCF string?

No. It recognises and classifies one so a scan reports it accurately, but it is not a registered TCF CMP and does not produce the string.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.