Free scan About Support Contact
Get Velo

Already have an account? Log in

How do I make Meta Signals Gateway respect cookie consent?

Server side 6 October 2026· 7 min read
The Velo mascot hands an envelope to a friendly server tower

All posts

Give the Signals Gateway Pixel its own consent check. It is separate code from the standard Meta Pixel, running on its own cbq function, so you cannot rely on a consent call to fbq reaching it. In Tag Manager, add consent settings for ad_storage, ad_user_data and ad_personalization to its tag, and fire it again on your consent update event. Without Tag Manager, hold its code back until the visitor accepts advertising.

Start with a scan.

The free scan reads your homepage HTML and public Tag Manager container, and lists the tracking tags it finds.

Free · No signup · HTML and public GTM checks

Most consent setups for Meta were built for one pixel. Signals Gateway adds a second one, and that second pixel is the one people forget to gate. Here is why it happens, how to fix it, and how to check the fix.

Why doesn’t my cookie banner already control the gateway pixel?

Because the banner talks to a different function. Meta’s consent control for the standard pixel is a command on fbq: fbq('consent', 'revoke') before init, then fbq('consent', 'grant') once the visitor agrees. Meta’s consent guide for the pixel describes exactly that pair. Most consent platforms, Velo included, send those two calls when a choice takes effect.

The Signals Gateway Pixel is installed with its own base code. It defines cbq, points it at the gateway on your own subdomain with cbq('setHost', …), and sends events from there. A revoke sent to fbq is a call to a different object, and Meta’s gateway pixel documentation says nothing about consent at all. Do not count on the standard pixel’s consent call covering the gateway pixel.

Google Consent Mode does not help here either. It is Google’s signal for Google tags. Meta’s base code does not read it on its own, and a Custom HTML tag in Tag Manager does not read it at all. Tag Manager’s consent settings are different: they decide whether a tag fires, whatever code is inside it. That leaves two places where the gateway pixel can be stopped: the tag’s consent settings in Tag Manager, or the page itself.

Two pixels. Two consent routes.

Meta Pixel

  • Runs on fbq
  • Banner sends grant or revoke
  • Revoke before init

Signals Gateway Pixel

  • Runs on cbq
  • Not covered by fbq consent
  • Gate the tag or the code
The standard Meta Pixel takes consent through fbq. The Signals Gateway Pixel is separate code, so it needs its own gate: consent settings on its Tag Manager tag, or a script held back until the visitor accepts advertising.

How do I set up the gateway pixel so it waits for consent?

The steps below assume Tag Manager, because that is how most sites install the gateway pixel. Step 4 covers code in the page.

  1. Find every copy of the gateway pixel

    Search your container for tags that call cbq, whether a gateway pixel template or a Custom HTML tag, and check the page source for the same base code. A second, ungated copy undoes the work on the first.

  2. Add consent settings to the tag

    On the gateway pixel tag, open Advanced Settings, then Consent Settings. Choose Require additional consent for tag to fire and add ad_storage, ad_user_data and ad_personalization. A tag blocked this way does not fire, so it sends nothing.

  3. Fire it again once the visitor accepts

    A page view blocked on load does not come back by itself. Add a trigger on your consent platform’s update event (with Velo it is velo_consent_update) and set Tag firing options to Once per page, so an accept fires the page view once.

  4. Without Tag Manager, hold the code back

    If the base code sits in the page, change its script type to text/plain and mark it with your consent platform’s advertising category. With Velo that is data-velo-category="ads". The code then runs only after the visitor allows advertising.

  5. Give both pixels the same event ID

    If the standard pixel and the gateway pixel both send a Purchase, Meta can count it twice. It removes duplicates most reliably when the two share an event name and event ID. Put one Tag Manager variable in the Event ID field of both tags.

  6. Test before you publish

    Run the four checks in the next section on the live site, in a fresh browser session each time.

Templates differ, so read the one you installed. Some community templates for the gateway pixel, Stape’s among them, document their own consent handling based on ad_storage. Some carry a consent field of their own, labelled Consent Granted (GDPR) in the version our Meta Pixel and Signals Gateway guide walks through; with Tag Manager consent settings in place, the guide leaves it set to True, because the consent settings already hold the tag back. If you install the gateway pixel as a Custom HTML tag, there is no such field, and the consent settings are the only gate. They work the same way whichever template you use.

How do I check the gateway pixel respects the choice?

Watch the network, not the tag list. A tag can show as blocked in Tag Manager’s preview while a copy hard coded in the theme still sends events.

  • Before any choice: open the Network panel and filter for your gateway subdomain and facebook.com/tr. Nothing should appear.
  • After accepting advertising: the page view should reach your gateway. Check it in the gateway’s event activity or in Events Manager’s Test events.
  • After rejecting: browse two pages. No requests to the gateway or to Meta.
  • After withdrawing: accept, then withdraw through the privacy button and load another page. Requests should stop from that page on.

Then check Events Manager for deduplication warnings. Our checklist for testing a cookie banner before going live has the full browser routine, and the same session hygiene applies here.

Does a gateway on my own subdomain change what consent I need?

No. The EU rule in Article 5(3) of the ePrivacy Directive is about storing or reading information on the visitor’s device. It does not ask whose domain the request goes to. Meta describes Signals Gateway as a way to receive and send events on your own infrastructure. That changes the route of the data, not the visitor’s choice about it.

It is the same answer we gave for Google’s version of the idea in does Google tag gateway need cookie consent. A first party path is a routing decision. Consent still decides whether the tag runs.

What about events the gateway sends on to the Conversions API?

If the browser pixel is gated, the gateway receives nothing from that visitor’s browser, so there is nothing to forward. The gap is elsewhere. Events your own server sends, such as a purchase posted to the Conversions API from your checkout, never pass through the banner. Apply the visitor’s advertising choice to those events before you send them, or the server route quietly ignores the decision the browser respected.

This is the same pattern as the standard pixel, one level down. Our post on why the Facebook pixel still loads when your tags are blocked covers the hard coded copies that cause most of these leaks.

Velo sends grant and revoke to the standard Meta Pixel whenever a choice takes effect. It does not yet send the choice to the Signals Gateway Pixel, so for that pixel use Tag Manager consent settings or the ads category block above.

Common questions

What people ask about this topic.

How do I make Meta Signals Gateway respect cookie consent?

Give the Signals Gateway Pixel its own consent check. It runs on its own cbq function, so you cannot rely on a consent call to fbq reaching it, and its base code does not read Google Consent Mode. In Tag Manager, add consent settings for ad_storage, ad_user_data and ad_personalization to its tag and fire it on your consent update event. Without Tag Manager, hold its code back until the visitor accepts advertising.

Does the Signals Gateway Pixel read Google Consent Mode?

Not on its own. Consent Mode is Google’s signal for Google tags. Tag Manager consent settings still work on the gateway pixel tag, because they stop the tag from firing whatever code is inside it.

Does an fbq consent revoke also stop the Signals Gateway Pixel?

Do not count on it. fbq and cbq are separate functions, and Meta’s gateway pixel documentation says nothing about consent. Give the gateway pixel its own consent check.

Do I still need a cookie banner if Meta events go through my own subdomain?

Yes. EU consent rules are about storing or reading information on the visitor’s device, not about which domain receives the request. If the standard pixel needed consent, the gateway pixel needs it too.

Will the Meta Pixel and the gateway pixel count the same purchase twice?

They can. Meta removes duplicates most reliably when both send the same event name and event ID. Use one Tag Manager variable for the Event ID field in both tags, then check Events Manager for deduplication warnings.