Tracker library

Microsoft Clarity: what it is, what it sets, and how to gate it.

Free session recording and heatmaps from Microsoft. Classified as analytics, but session replay captures far more than a page-view counter and deserves a closer look.

Vendor
Microsoft
Scanner category
analytics
Consent category
Analytics
Control
Custom script or container tag

What it is

Clarity records what visitors do (movements, clicks, scrolls, and a replayable reconstruction of the session) and aggregates it into heatmaps. It is genuinely useful for finding usability problems, and it collects more than a measurement tool does.

The scanner classifies it as analytics because that is its usual purpose. Microsoft says sensitive content is masked by default and input, select and textarea values are always masked. That does not remove the need to review relaxed masking, visible page text, URLs, CSS selectors and any custom configuration.

What a scan matches

A verification scan drives a real browser and records the outbound requests observed during its configured journeys, so Microsoft Clarity is identified by request hosts and paths rather than by source-code claims. Requests on unvisited paths, after unperformed interactions or solely on the server remain outside that observation.

  • clarity.ms
  • clarity.microsoft.com

Cookies are classified by name before domain because many analytics and advertising tags write first-party cookies through the page, which places a vendor-related identifier on your domain. Matching known names helps attribute those values without assuming that every first-party cookie came from your own application.

CookieWhat it is for
_clckClarity user identifier, persisting across sessions
_clskClarity session identifier, joining page views into one recording
CLIDIdentifier set on the Clarity domain

Controlling it with consent

No named adapter. Gate it as a custom script attached to analytics, or as a container tag.

Separately from consent, review Clarity’s masking configuration on representative pages. Do not assume that default input masking also protects sensitive text rendered elsewhere in the page, URL parameters, attributes or elements you explicitly unmask.

No named adapter: choose the appropriate control

The product ships named adapters for Google Tag Manager, Google Analytics, the Meta and TikTok pixels, and Klaviyo. Choose the control route that fits this technology: a custom HTTPS script declaration for a browser loader, an individual consent condition inside a tag manager, a platform or app setting, or a click-to-load placeholder for a frame. Server-side integrations need their own enforcement because a browser runtime cannot stop them.

What breaks if it is refused: session recordings and heatmaps for refusing visitors. No visitor-facing behaviour.

Verifying it

Before consent there should be no request to clarity.ms and no _clck or _clsk. After consent, check a recording of your own session to confirm masking is doing what you expect.

  • Before a choice: optional tracking endpoints and optional identifiers are absent; any intentionally loaded necessary or functional surface matches the control model described above
  • After rejecting optional categories: optional activity remains absent and the refusal persists across a reload
  • After granting the relevant category: the expected loader or embed appears and the feature behaves normally
  • After withdrawing: new optional activity stops; where the vendor supports a consent signal, verify that the signal is sent as well as checking network behavior

Common questions

Is session replay just analytics?

It is classified as analytics because measurement is its purpose, but it collects behavioural detail that ordinary analytics does not. Treat masking configuration as part of the compliance work, not as a separate usability concern.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.