{"_id":"@akku-work/consent-sdk","name":"@akku-work/consent-sdk","dist-tags":{"beta":"0.1.0-beta.1","latest":"0.1.0-beta.1"},"versions":{"0.1.0-beta.1":{"name":"@akku-work/consent-sdk","version":"0.1.0-beta.1","description":"Akku Consent - zero-dependency browser SDK for consent capture and preference management (~10 KB gzip).","keywords":["consent","gdpr","dpdp","privacy","cmp","preference-management","cookie-consent","cookie-banner"],"license":"UNLICENSED","author":{"name":"Akku"},"homepage":"https://bitbucket.org/cnw-bitbucket-ws/akku-consent","repository":{"type":"git","url":"git+https://bitbucket.org/cnw-bitbucket-ws/akku-consent.git","directory":"packages/consent-sdk"},"bugs":{"url":"https://bitbucket.org/cnw-bitbucket-ws/akku-consent/issues"},"//private":"PKG-006: this is the ONE workspace package that is NOT private — every other app/package keeps `private: true`. Publishing happens only from the `sdk-v*` tag pipeline in bitbucket-pipelines.yml; do not run a bare `pnpm publish -r` from the repo root.","publishConfig":{"access":"public","tag":"beta"},"type":"module","main":"./dist/index.js","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./manifest":{"types":"./dist-cdn/manifest.d.ts","default":"./dist-cdn/manifest.json"}},"dependencies":{},"devDependencies":{"jsdom":"^25.0.1","rimraf":"^6.0.1","tsup":"^8.3.5","typescript":"^5.6.3","vitest":"^3.2.6","@akku/contracts":"0.1.0"},"scripts":{"build":"tsup && node ./scripts/hash-cdn-bundle.mjs && node ./scripts/verify-cdn-manifest.mjs && node ./scripts/check-size-budget.mjs","dev":"tsup --watch","test":"vitest run","test:coverage":"vitest run --coverage","lint":"eslint .","typecheck":"tsc -p tsconfig.json --noEmit","size-check":"node ./scripts/check-size-budget.mjs","verify-cdn":"node ./scripts/verify-cdn-manifest.mjs","clean":"rimraf dist dist-cdn"},"_id":"@akku-work/consent-sdk@0.1.0-beta.1","_integrity":"sha512-zUiiG7LJlF6jpBIyyYAjWtLv8m62FV8x0Qsn3ByZYBCywlqmY8Fy/dHvukO92jasm5FohCD/Cok+v/qaLyPybA==","_resolved":"C:\\Users\\RAJAND~1\\AppData\\Local\\Temp\\22b5fbc7a0e6fba4fd0f417c43659899\\akku-work-consent-sdk-0.1.0-beta.1.tgz","_from":"file:akku-work-consent-sdk-0.1.0-beta.1.tgz","_nodeVersion":"22.22.2","_npmVersion":"10.9.7","dist":{"integrity":"sha512-zUiiG7LJlF6jpBIyyYAjWtLv8m62FV8x0Qsn3ByZYBCywlqmY8Fy/dHvukO92jasm5FohCD/Cok+v/qaLyPybA==","shasum":"dd02d809960754299e20c464649f7a5871152eeb","tarball":"https://registry.npmjs.org/@akku-work/consent-sdk/-/consent-sdk-0.1.0-beta.1.tgz","fileCount":20,"unpackedSize":603252,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDfUQPSlqRulXWryzB3BbYuMbffov59R2GvuWNFON6dOAIhAKbsQYlFPZ4a4+hrneyyhKgb6lyLGbri9c6FXeSLV1dt"}]},"_npmUser":{"name":"rajandavidt","email":"rajandavid.t@cloudnowtech.com"},"directories":{},"maintainers":[{"name":"cloudnowtech","email":"developer@cloudnowtech.com"},{"name":"rajandavidt","email":"rajandavid.t@cloudnowtech.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/consent-sdk_0.1.0-beta.1_1787299066260_0.3958039659275203"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-21T07:57:46.086Z","0.1.0-beta.1":"2026-08-21T07:57:46.392Z","modified":"2026-08-21T07:57:46.643Z"},"maintainers":[{"name":"cloudnowtech","email":"developer@cloudnowtech.com"},{"name":"rajandavidt","email":"rajandavid.t@cloudnowtech.com"}],"description":"Akku Consent - zero-dependency browser SDK for consent capture and preference management (~10 KB gzip).","homepage":"https://bitbucket.org/cnw-bitbucket-ws/akku-consent","keywords":["consent","gdpr","dpdp","privacy","cmp","preference-management","cookie-consent","cookie-banner"],"repository":{"type":"git","url":"git+https://bitbucket.org/cnw-bitbucket-ws/akku-consent.git","directory":"packages/consent-sdk"},"author":{"name":"Akku"},"bugs":{"url":"https://bitbucket.org/cnw-bitbucket-ws/akku-consent/issues"},"license":"UNLICENSED","readme":"# @akku-work/consent-sdk\r\n\r\nCookie consent and preference management for the **anonymous** web. Zero runtime dependencies,\r\naround 10 KB gzip.\r\n\r\nThis is the anonymous plane: a visitor you cannot identify, arriving on a public page. It ships its\r\nown banner and preference-centre UI because it is installed into a page it knows nothing about and\r\nhas no host component tree to hand the question to.\r\n\r\nIf the person is **signed in** to your app, use\r\n[`@akku-work/consent-sdk-auth`](https://www.npmjs.com/package/@akku-work/consent-sdk-auth) instead.\r\nConsent recorded against a signed-in subject is a different thing from consent recorded against a\r\nbrowser, and the two packages are not interchangeable.\r\n\r\n## Install\r\n\r\n```bash\r\nnpm install @akku-work/consent-sdk\r\n```\r\n\r\n```ts\r\nimport { init, onChange, hasConsent } from \"@akku-work/consent-sdk\";\r\n\r\nawait init({ siteKey: \"sk_live_9f2c…\" });\r\n\r\nif (hasConsent(\"analytics\")) {\r\n  loadAnalytics();\r\n}\r\n\r\nonChange((change) => {\r\n  // fires on every explicit visitor decision\r\n});\r\n```\r\n\r\n## A decision is only ever written by an explicit action\r\n\r\n`init()` fetches the published config, reads whatever is already cached locally, and runs the first\r\nauthoritative gating pass. It **never** writes a consent.\r\n\r\nOnly `acceptAll()`, `rejectAll()`, `updateConsent()` and `withdraw()` write, and each of them\r\ncorresponds to something the visitor actually did. There is no code path that records an implied\r\nconsent, and adding one would be a bug rather than a feature.\r\n\r\n## API\r\n\r\n| Function                     | Purpose                                              |\r\n| ---------------------------- | ---------------------------------------------------- |\r\n| `init(options)`              | Fetch config, read cache, run the first gating pass. |\r\n| `hasConsent(key)`            | Is this category granted right now?                  |\r\n| `getConsent()`               | The full current decision record.                    |\r\n| `acceptAll()` / `rejectAll()`| Record a blanket decision.                           |\r\n| `updateConsent(decisions)`   | Record a per-category decision.                      |\r\n| `withdraw()`                 | Withdraw everything previously granted.              |\r\n| `ask()` / `disclose()`       | Purpose-level prompt and disclosure.                 |\r\n| `showBanner()` / `showPreferences()` | Open a surface on demand.                    |\r\n| `onChange(listener)`         | Subscribe to decision changes.                       |\r\n| `startObserver()` / `stopObserver()` | Gate markup added after load.                |\r\n| `scanUnblocked()`            | Report trackers running without a matching consent.  |\r\n| `setSubjectAttributes(attrs)`| Attach non-identifying attributes to the record.     |\r\n\r\n## Script-tag install\r\n\r\nThe package also ships prebuilt CDN bundles under `dist-cdn/`, with a manifest carrying the\r\ncontent-hashed filename, byte size and SRI digest of each. Read integrity attributes from that\r\nmanifest rather than transcribing them — the build verifies the hash against the actual bytes, so a\r\nbundle whose digest has drifted fails CI instead of failing in a browser.\r\n\r\n```ts\r\nimport manifest from \"@akku-work/consent-sdk/manifest\";\r\n```\r\n\r\nTwo bundles: `akku-consent.global.js` is the full SDK, and `akku-head.global.js` is a ~2 KB\r\nhead-snippet that performs the same first gating pass before the main bundle arrives. Both run\r\nidentical gating logic against the same markup contract, deliberately — a page that gates one way\r\nbefore hydration and another way after is worse than one that does not gate at all.\r\n\r\n## Size budget\r\n\r\nThe bundle is size-gated in CI (~10 KB gzip for the main bundle). This is why the package has an\r\nempty `dependencies` and pulls contract types in as types only: importing a runtime validator here\r\nonce took the bundle from roughly 10 KB to 53 KB gzip against the same budget.\r\n\r\n## Licence\r\n\r\nProprietary. See [LICENSE](./LICENSE) — publication on npm grants no licence to use this software.\r\n","readmeFilename":"README.md","_rev":"1-e2ab15dbf29a49166f84f7a143e5c802"}