Tracker library

Matomo: what it is, what it sets, and how to gate it.

Open-source analytics, often self-hosted and often chosen specifically because it can be configured to need no consent, which depends on the configuration, not the product.

Vendor
Matomo
Scanner category
analytics
Consent category
Analytics
Control
Custom script or container tag

What it is

Matomo is a self-hostable analytics platform. In its default configuration it sets first-party cookies with a visitor identifier, which puts it in the same position as any other analytics tool.

It also supports a cookieless mode with IP anonymisation and no persistent identifier, which is the configuration some supervisory authorities have described as potentially exempt from consent. Whether yours qualifies depends on exactly how it is configured, and on which authority you are answering to.

What a scan matches

A verification scan drives a real browser and records the outbound requests observed during its configured journeys, so Matomo is identified by request hosts and paths rather than by source-code claims. Requests on unvisited paths, after unperformed interactions or solely on the server remain outside that observation.

  • matomo.cloud
  • matomo.org
  • plus any self-hosted domain you deploy it to

Cookies are classified by name before domain because many analytics and advertising tags write first-party cookies through the page, which places a vendor-related identifier on your domain. Matching known names helps attribute those values without assuming that every first-party cookie came from your own application.

CookieWhat it is for
_pk_id*Visitor identifier
_pk_ses*Session state
matomo*Related Matomo state, matched by prefix

Controlling it with consent

No named adapter. If you run Matomo with cookies, gate it as a custom script attached to analytics.

If you intend to rely on a national audience-measurement exemption, document every required condition for that jurisdiction: limited purpose and scope, retention, IP handling, data sharing, user information and any required objection mechanism. Cookieless operation can help but is not, by itself, either necessary or sufficient under every authority’s guidance.

No named adapter: choose the appropriate control

The product ships named adapters for Google Tag Manager, Google Analytics, the Meta and TikTok pixels, and Klaviyo. Choose the control route that fits this technology: a custom HTTPS script declaration for a browser loader, an individual consent condition inside a tag manager, a platform or app setting, or a click-to-load placeholder for a frame. Server-side integrations need their own enforcement because a browser runtime cannot stop them.

What breaks if it is refused: audience measurement for refusing visitors, unless you are running an exempt cookieless configuration.

Verifying it

Check whether `_pk_` cookies are present, how long they persist, whether identifiers are shared across sites, how IP addresses are handled, and whether the deployment meets every condition of the exemption you rely on. The presence of a cookie does not automatically defeat every national audience-measurement exemption. Self-hosted deployments should be scanned against their real domain.

  • Before a choice: optional tracking endpoints and optional identifiers are absent; any intentionally loaded necessary or functional surface matches the control model described above
  • After rejecting optional categories: optional activity remains absent and the refusal persists across a reload
  • After granting the relevant category: the expected loader or embed appears and the feature behaves normally
  • After withdrawing: new optional activity stops; where the vendor supports a consent signal, verify that the signal is sent as well as checking network behavior

Common questions

Is Matomo consent-free?

Not inherently. A tightly limited audience-measurement configuration may qualify under some national guidance, sometimes even with narrowly controlled cookies; the exact conditions vary. Self-hosting or enabling cookieless mode does not create an exemption by itself.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.