What it does
`OptanonConsent` encodes which categories the visitor allowed and when, so the banner does not reappear and gated scripts know what they may do. `OptanonAlertBoxClosed` records the dismissal timestamp.
Storage limited to remembering and enforcing the visitor’s choice is commonly treated as necessary for that preference function. Audit the fields and related services; analytics or unrelated identifiers do not become exempt because a CMP writes them.
What to write in a cookie declaration
List it under necessary, named as a consent management cookie. It belongs in the declaration even though it needs no consent: omitting it makes the list incomplete.
| Field | Value |
|---|---|
| Name | OptanonConsent |
| Provider | OneTrust |
| Purpose category | functional |
| Consent category | Necessary |
| Expiry | 1 year (vendor default) |
| Storage | First-party |
Treat the expiry as indicative
The value above is the vendor’s documented default. Vendors change configuration and several browsers cap script-written lifetimes. Record what repeated scans observe on your own site, with the browser, region, path and interaction state; one run is not authoritative for every visitor.
Can a visitor refuse it?
Do not gate storage genuinely limited to remembering the visitor’s choice. If you find it after a migration, test a fresh profile and inspect new Set-Cookie activity, requests and scripts; an old browser value can survive after OneTrust has been removed.
A verification scan supplies runtime evidence for the pages and states it exercises. Test a fresh profile with no choice made, then after refusal, and reconcile observed storage with response headers, server-side integrations and paths the scan did not visit.
Common questions
Does finding OptanonConsent mean OneTrust is still running?
Not by itself. Cookies can outlive the script that created them. Use a fresh profile and check whether the site sets it again, contacts OneTrust hosts, loads its scripts or renders its interface before concluding that the old platform is active.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- OneTrust: OneTrust cookies
Vendor documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.