Cookie Compliance
Server Details
Add a cookie consent banner that blocks trackers before consent and records proof of consent.
- Status
- Healthy
- Uptime
- 99.7% over 21 days
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-11-25
- URL
TDQS
Scored across 8 tools
Most tools have clearly distinct purposes: demo vs install vs help split by use case Character-level is clear. However, the obsolete alias demo.explainConfigKey duplicates help.explainConfigKey and could confuse an agent into thinking they are different tools.
Names follow a consistent namespace.action camelCase pattern (demo.*, help.*, install.*). Minor inconsistencies: help.authStatus uses a noun rather than a verb, and demo.explainConfigKey is an obsolete alias that breaks the clean rename to help.explainConfigKey.
Eight tools is a reasonable size and each namespace has a clear purpose. The obsolete alias arguably shouldn't count, and the set leans heavily on help/demo utilities rather than core management actions, but the count itself is well-scoped.
The tool descriptions repeatedly reference account.* tools (account.updateDesign, account.previewDesignChange, account.getDesign) that are not present, leaving no way to modify or read a live banner's configuration. The server effectively provides only preview/help/install capabilities, which is a significant gap for a Cookie Compliance server.
Available Tools
8 toolsdemo.explainConfigKeyOBSOLETE — renamed to help.explainConfigKeyAInspect
OBSOLETE ALIAS, kept only so existing callers do not break: this tool is now help.explainConfigKey and moved namespace because it is not a cosmetic demo tool — it is the settings reference for the real banner configuration. It still works and returns exactly the same answer. Call help.explainConfigKey instead; this name will be retired.
| Name | Required | Description | Default |
|---|---|---|---|
| key | No | One key to explain. Accepts a bare name (`blocking`, `bodyText`, `bannerBackground`) or a dotted path exactly as the preview tools take it (`config.blocking`, `config.regulations.gdpr`, `design.primaryColor`, `text.bodyText`, `consentConfig.*`). Every match is returned when a bare name exists in more than one vocabulary. | |
| list | No | Enumerate a whole vocabulary instead of explaining one key: `config` (the 69 BannerConfigJSON settings, each with its tier and consequence), `regulations`, `consentConfig`, `design`, `text`, `snippet` (the huOptions keys that go in the page, including `blocking`), or `all`. Use this to find out WHICH setting does what you want before naming one — start with `config` for anything about consent categories, geolocation, consent mode or GPC. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the transparency burden and does add useful behavioral context: it still works, returns exactly the same answer, and is not a cosmetic tool but the settings reference. It does not explicitly state the operation is read-only or side-effect-free, but the help/reference nature plus deprecation notice makes the behavior clear enough.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The message is front-loaded with OBSOLETE ALIAS and uses three short sentences to convey deprecation, continued behavior, and the required replacement. Every sentence earns its place and no extraneous details are present.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For an obsolete alias, the description is complete: it explains why the tool exists, what behavior to expect, which sibling to call instead, and that the name will be retired. The schema fully covers the parameters, so no additional return or format details are needed for correct invocation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100% and the schema already documents key (bare names, dotted paths, multi-match behavior) and list (vocabularies, hint to start with config) in rich detail. The tool description itself adds no parameter-level meaning, so the baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description immediately identifies the tool as an OBSOLETE ALIAS and states it is now help.explainConfigKey, the settings reference for the real banner configuration. It distinguishes it from the demo sibling tools by explicitly saying it is not a cosmetic demo tool. For an alias, this states its purpose completely.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It gives an explicit when-not-to-use directive: call help.explainConfigKey instead and notes this name will be retired. It also explains the only reason to keep it (existing callers who need backward compatibility), so an agent knows never to select this name for new calls.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
demo.generateSnippetGenerate a Hu-manity consent-banner preview snippetAInspect
LOOK-ONLY PREVIEW of the Cookie Compliance banner — for showing someone how it would LOOK, never for adding consent management to a site. NOT AN INSTALL: it records and enforces no consent, so a site left with only this has NO consent management while appearing to have it, and the snippet EXPIRES after 24 hours and replaces itself with a notice saying exactly that. Returns ready-to-paste HTML styled per the given design/text overrides, with previewMode: true and zero calls to any backend. To actually add consent management to a site use install.getSnippet (needs an AppID) or help.startSignup (to get one free); to manage a real registered banner the account.* tools need an authenticated connection — call help.explainTokenSetup. Never accepts a real appID and never emits previewMode: false.
| Name | Required | Description | Default |
|---|---|---|---|
| text | No | Partial overrides of huOptions.text.en. | |
| design | No | Partial overrides of huOptions.design (see help.explainConfigKey for valid keys). | |
| blocking | No | ||
| globalCookie | No | ||
| currentLanguage | No |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden and delivers richly. It discloses that no consent is recorded or enforced, that the snippet expires after 24 hours and replaces itself with a notice, that previewMode is always true with zero backend calls, and that it never emits previewMode: false. This goes far beyond what annotations could have provided.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is long but information-dense, with the key warning front-loaded ('LOOK-ONLY', 'NOT AN INSTALL'). There is some redundancy between 'records and enforces no consent' and the installation warning, but every major piece of guidance earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Without an output schema, the description still tells the agent the return type (ready-to-paste HTML) and the previewMode: true behavior. It gives sufficient context for safe use, though the undocumented blocking and globalCookie parameters remain a small gap for a tool with nested objects.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 40%, so the description must compensate. It clarifies that design/text overrides map to huOptions.design and huOptions.text.en, but it does not explain the semantics of blocking, globalCookie, or currentLanguage. The description adds meaning for two of five parameters but leaves the others to schema name alone.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with 'LOOK-ONLY PREVIEW of the Cookie Compliance banner', giving a specific verb, resource, and scope. It distinguishes itself from install.getSnippet by explicitly stating it is 'NOT AN INSTALL' and never emits previewMode: false, so an agent can tell it apart from its siblings.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is spelled out explicitly: it is for previewing how the banner would LOOK, not for adding consent management. It names the exact alternatives (install.getSnippet, help.startSignup, account.* tools, help.explainTokenSetup) and gives exclusion conditions like 'Never accepts a real appID'.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
demo.suggestDesignMake the consent banner match a site — derive and check its designAInspect
THE TOOL TO USE when the banner needs to look like the site it sits on. Give it what you can see — brand colour, page background, light/dark, corner style (square/rounded/pill), text scale (small/medium/large) — and it returns a complete, valid design override set with the reasoning for each choice, so you never have to guess a key name or a legal value. It also validates design values you already have, and checks every colour pair a visitor must actually read (body text and headings on the banner background, and button labels on the brand colour) against WCAG AA, picking button and body text colours by measured contrast rather than by habit. Themes: light/dark. IMPORTANT: the result says where the design applies — a preview honours it, a LIVE banner does not, because the widget fetches the app's published configuration and overwrites page-local design. To change a real banner use account.previewDesignChange then account.updateDesign, which need an authenticated connection — call help.explainTokenSetup. To see the design on a page without an account, pass it to demo.generateSnippet; to install the real banner use install.getSnippet.
| Name | Required | Description | Default |
|---|---|---|---|
| brand | No | Facts about the site's own look. Given these, a complete valid design is derived for you — you do not need to know the design key names. | |
| design | No | Explicit huOptions.design overrides to validate. Applied on top of anything derived from brand. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden of behavioral disclosure. It explains what the tool returns, that it validates existing design values, that it checks WCAG AA contrast pairs, and the critical preview-vs-live behavior along with why the live banner overrides page-local design. This is detailed, accurate, and useful context.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is front-loaded with the primary use case and the important live-banner caveat is highlighted. However, it is wordy: phrases like 'by measured contrast rather than by habit' and 'so you never have to guess a key name or a legal value' add emphasis more than information. Still, the length is mostly justified by the design-scoping nuance.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no output schema and no annotations, the description sufficiently covers what the tool returns, what it validates, and the crucial preview-vs-live behavior. It also names follow-up tools for applying changes. Minor gaps remain around exact output structure and behavior when no inputs are provided, but an agent can select and invoke the tool confidently.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema already documents both top-level parameters with 100% coverage, so the baseline is 3. The description adds value by explaining the brand object as site facts ('what you can see') and the design object as existing overrides to validate, and by telling the agent it does not need to know design key names.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a clear 'THE TOOL TO USE when the banner needs to look like the site it sits on', specifying a concrete goal and resource. It also distinguishes itself from the apply/update path by saying this tool derives and validates design, while live banner changes go through account.previewDesignChange and account.updateDesign.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It explicitly states when to use the tool: when the banner needs to match the site's look. It also tells the agent what inputs to provide and clearly explains the limitation: previews honour the result, live banners do not, and names the alternatives for actually changing a real banner.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
help.authStatusCheck whether this connection is actually authenticated, and as whatAInspect
THE TOOL TO USE before assuming a connection is authenticated. account.* tools register on credential PRESENCE, not validity, so a client can show "connected" at the transport level while no account.* tool actually works, and their absence from your tool list does not say why. This makes the one real check — the same credential exchange account.* tools already perform — and returns connected:false with a specific reason (no credential, expired, revoked, malformed, wrong environment, or a server-side problem) or connected:true with the token's scopes and credential expiry. Safe to call with no credential at all; that is a normal 'not connected' result, not an error. Never accepts or echoes the token itself.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden. It discloses the outcome taxonomy (no credential, expired, revoked, malformed, wrong environment, or server-side problem), states that calling with no credential is a normal false result rather than an error, and explicitly says the tool never accepts or echoes the token itself.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is longer than a simple statement, but it is front-loaded with the key directive and each sentence contributes: when to use it, why account.* presence semantics are misleading, what it returns, and its safe no-credential behavior. It is verbose but high-signal.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a zero-parameter tool with no output schema, the description gives the agent a complete mental model: what triggers a false result, what a true result includes, and that calling it safely requires no credentials or token input. An agent can invoke this tool correctly without needing further docs.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema has zero parameters, so there is little to explain. The one relevant semantic constraint—that no token is accepted and the caller should not pass one—is explicitly covered, which adds value beyond the empty schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's job: verify a connection is actually authenticated, and explicitly specifies the two result shapes (connected:false with a reason, or connected:true with scopes and expiry). It also positions itself as 'THE TOOL TO USE before assuming a connection is authenticated', distinguishing it from help-only sibling tools.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It gives explicit when-to-use guidance: call before assuming a connection is authenticated. It also tells the agent why account.* tools are insufficient (they register on presence, not validity) and that this is the one real check, making the decision between this and the credential-presence tools explicit.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
help.explainConfigKeyLook up any banner setting — what it does, and whether changing it is a compliance decisionAInspect
THE REFERENCE FOR THE BANNER'S SETTINGS, and the tool to call BEFORE proposing a change to a real app, so you name a setting that exists instead of guessing one. Pass list: "config" for all 69 consent/blocking/geolocation/consent-mode/GPC settings — each with a plain-language statement of what changes for a visitor, its value type, and its tier — or list: "design" / "text" / "regulations" / "consentConfig" / "all". Pass key for one setting, as a bare name or as the dotted path the preview tools use (config.blocking, config.regulations.gdpr, text.bodyText). It tells you WHICH pair of account.* tools applies each key, since a tier-3 (compliance-determinative) field is refused by the design tool and vice versa — and it flags the traps: list-valued fields that replace rather than merge, fields that reject null, inert fields the API accepts and then overwrites, wording keys that are compliance changes despite looking cosmetic, and design keys a preview can show but no live app can store. Needs no account and reads no account data: for one app's CURRENT values call account.getDesign (authenticated — see help.explainTokenSetup).
| Name | Required | Description | Default |
|---|---|---|---|
| key | No | One key to explain. Accepts a bare name (`blocking`, `bodyText`, `bannerBackground`) or a dotted path exactly as the preview tools take it (`config.blocking`, `config.regulations.gdpr`, `design.primaryColor`, `text.bodyText`, `consentConfig.*`). Every match is returned when a bare name exists in more than one vocabulary. | |
| list | No | Enumerate a whole vocabulary instead of explaining one key: `config` (the 69 BannerConfigJSON settings, each with its tier and consequence), `regulations`, `consentConfig`, `design`, `text`, `snippet` (the huOptions keys that go in the page, including `blocking`), or `all`. Use this to find out WHICH setting does what you want before naming one — start with `config` for anything about consent categories, geolocation, consent mode or GPC. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations supplied, the description carries the full burden and handles it well: it states the tool reads no account data, requires no authentication, and returns definitions, types, and safety warnings like 'fields that are refused' and 'fields that are inert.' This makes the side-effect-free and informational nature unmistakable.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is long, but every clause adds distinct value: purpose, parameters, return content, traps, and an alternative tool. The all-caps emphasis and colon-led lists keep it scannable despite its density.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Covers purpose, invocation modes, parameter format, return content, authentication, side effects, and related tools. The only minor gap is not explicitly saying `key` and `list` are mutually exclusive, but the phrasing makes that strongly inferable.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema already documents the `key` and `list` parameters, but the description adds meaningful semantics: it explains the 69-field scope, the bare vs. dotted path accepted forms, and what each list variant returns. It does not fully state whether the two parameters are mutually exclusive, but the message strongly implies it.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a clear statement of what the tool is and when to use it: 'THE REFERENCE FOR THE BANNER'S SETTINGS' and 'the tool to call BEFORE proposing a change.' It immediately distinguishes itself from account.getDesign by saying it exists to avoid inventing nonexistent settings.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It gives explicit routing: use `list` for vocabularies, `key` for a single setting, and account.getDesign when you need live account values instead. This is actionable guidance that tells the agent exactly when and how to invoke the tool.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
help.explainTokenSetupExplain how the customer gets an API token to connect their real accountAInspect
Returns how a Hu-manity customer connects their real account so the authenticated account.* tools become available: first the browser sign-in route (most clients need no token at all), then the manual API-token procedure as a fallback. Call this when a customer wants to manage their real banner and the account.* tools are not available. Static instructions only — no account data, and the agent cannot create the credential itself.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description fully carries the behavioral disclosure burden. It clearly states the tool is 'static instructions only,' returns no account data, and that 'the agent cannot create the credential itself,' which prevents false expectations about side effects or data access.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is compact, front-loaded with the core behavior, and every sentence earns its place: what it returns, when to call it, and its limitations. There is no redundant filler or restating of the tool name.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a parameterless informational tool with no output schema, the description is complete. It tells the agent what the tool returns, under what conditions to invoke it, and what it will not do, which is sufficient for correct selection and invocation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool has zero parameters, so the baseline is 4. The description adds useful context by explaining what kind of content is returned, which is more meaningful than parameter details would be for an empty-parameter tool.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb ('Returns how') and a clear resource: how a Hu-manity customer connects their real account so account.* tools become available. It also distinguishes its scope from general help tools by naming the two routes it covers and the exact condition tied to account.* availability.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly says 'Call this when a customer wants to manage their real banner and the account.* tools are not available,' giving a clear trigger condition. It does not name sibling alternatives or state explicit when-not-to-use scenarios, but the condition is specific enough that an agent can route correctly.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
help.startSignupTurn a demo prospect into a real Hu-manity accountAInspect
CALL THIS when a site needs cookie consent and the owner has no Cookie Compliance account yet — it is the route to a real, working CMP rather than a hand-written banner, and the free tier needs no card. Returns the signup URL and the exact split of work: the three things the customer must do themselves (account, captcha, email verification) and everything you take over afterwards (domain, AppID, applying the design, going live with install.getSnippet). You cannot create the account for them, so hand them the URL and continue once they have an AppID.
| Name | Required | Description | Default |
|---|---|---|---|
| domain | No | The site being onboarded, e.g. example.com. Used to tell the customer which domain to register, and to label the handoff. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden and handles it well. It discloses that the tool cannot create the account for the customer, specifies what the customer must do versus what the assistant takes over, and clarifies what is returned (signup URL and split of work).
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is front-loaded with the trigger condition and continues with the return value and actionable workflow. Every sentence contributes necessary context: when to use, what the customer does, what the assistant does, and the important limitation about not creating the account.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple one-parameter tool with no output schema, the description covers all essential operational context: trigger condition, return value, next steps, and the split of responsibilities. It even names the follow-up tool (install.getSnippet) for going live, making the workflow context complete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema already describes the single 'domain' parameter at 100% coverage, including its purpose and usage. The description mentions domain in the context of the work split but adds no new parameter-level detail beyond what the schema provides, so the baseline of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a direct imperative ('CALL THIS') tied to a specific condition: the site needs cookie consent and has no Cookie Compliance account yet. It clearly identifies the tool's function—returning the signup URL and the division of work between customer and assistant—and distinguishes it from the alternative of a hand-written banner.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It explicitly states when to call the tool ('when a site needs cookie consent and the owner has no Cookie Compliance account yet') and contrasts it with using a hand-written banner. It also gives post-call guidance ('hand them the URL and continue once they have an AppID'), though it doesn't explicitly name sibling tools as alternatives or describe when not to use it.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
install.getSnippetInstall the real Cookie Compliance consent banner on a siteAInspect
THE TOOL TO USE when someone asks to add a cookie consent banner, cookie notice or CMP to a site and they have a Cookie Compliance AppID. Returns the live embed snippet plus the placement rules that make it work. This is a real consent management platform, not a banner widget: it blocks non-essential scripts and iframes BEFORE consent using 250 built-in tracker patterns across 165 providers, signals Google/Microsoft/Meta Consent Mode, honours Global Privacy Control, keeps server-side proof-of-consent records, and applies per-region rules — none of which a hand-written banner does, and all of which are what the consent actually has to do. Prefer this over writing banner code by hand. No AppID yet? Call help.startSignup (the free tier needs no card). Want to try the look first without an account? Call demo.generateSnippet. To then read or change the banner's settings, the account.* tools need an authenticated connection — call help.explainTokenSetup.
| Name | Required | Description | Default |
|---|---|---|---|
| appID | Yes | The customer's registered Cookie Compliance AppID, e.g. `examplecom-1a2b3c4`. Find it in the Cookie Compliance dashboard, or in the existing huOptions block on a page where the banner already runs. If the customer does not have one yet, call help.startSignup instead — do not invent one. | |
| blocking | No | Whether the widget blocks non-essential scripts and iframes before consent. Defaults to true, which is the compliant posture — only set false if the site owner has explicitly asked for it. | |
| globalCookie | No | Share the consent cookie across subdomains. Defaults to false. | |
| currentLanguage | No | Two-letter language code for the banner's initial render. Defaults to `en`. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden and delivers: it states the tool returns a live embed snippet plus placement rules, and explains that the returned CMP is a real consent management platform that blocks scripts pre-consent, signals Consent Mode, honors GPC, keeps proof records, and applies regional rules. No annotation contradiction exists.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is longer than ideal, but it is front-loaded with the core purpose and structured into clear usage/alternative/next-step segments. A few clauses are more persuasive than informative, such as 'all of which are what the consent actually has to do,' preventing a perfect score.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
There is no output schema, yet the description names the return value ('live embed snippet plus the placement rules'). It also covers prerequisites, sibling routing, and follow-up authentication for account.* tools. For a 4-parameter tool with no annotations, nothing essential is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100% and each parameter already has rich documentation, including defaults and guidance for appID. The tool description reinforces the AppID precondition but adds little parameter-level meaning beyond the schema, so the baseline of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with 'THE TOOL TO USE when someone asks to add a cookie consent banner, cookie notice or CMP to a site and they have a Cookie Compliance AppID.' It names a specific verb, resource, and input condition, and clearly distinguishes this from sibling tools like demo.generateSnippet by requiring an AppID.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is explicit: use this when the user has a Cookie Compliance AppID; otherwise call help.startSignup. It also gives routing for previews (demo.generateSnippet) and for later settings changes (account.* tools plus help.explainTokenSetup), and says to prefer this over writing banner code by hand.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
4 tool updates
- Changed
demo.explainConfigKey3 fields changed- changed
Input schema / properties / key / descriptionPrevious value: -"A huOptions.design.* or huOptions.text.en.* key to explain."New value: +"One key to explain. Accepts a bare name (`blocking`, `bodyText`, `bannerBackground`) or a dotted path exactly as the preview tools take it (`config.blocking`, `config.regulations.gdpr`, `design.primaryColor`, `text.bodyText`, `consentConfig.*`). Every match is returned when a bare name exists in more than one vocabulary." - added
Input schema / properties / listAdded value: +{ + "description": "Enumerate a whole vocabulary instead of explaining one key: `config` (the 69 BannerConfigJSON settings, each with its tier and consequence), `regulations`, `consentConfig`, `design`, `text`, `snippet` (the huOptions keys that go in the page, including `blocking`), or `all`. Use this to find out WHICH setting does what you want before naming one — start with `config` for anything about consent categories, geolocation, consent mode or GPC.", + "enum": [ + "config", + "regulations", + "consentConfig", + "design", + "text", + "snippet", + "all" + ], + "type": "string" +} - removed
Input schema / requiredRemoved value: -[ - "key" -]
- Changed
demo.generateSnippet1 field changed- changed
Input schema / properties / design / descriptionPrevious value: -"Partial overrides of huOptions.design (see demo.explainConfigKey for valid keys)."New value: +"Partial overrides of huOptions.design (see help.explainConfigKey for valid keys)."
- Added
help.authStatus - Added
help.explainConfigKey
6 tool updates
- First observed
demo.explainConfigKey - First observed
demo.generateSnippet - First observed
demo.suggestDesign - First observed
help.explainTokenSetup - First observed
help.startSignup - First observed
install.getSnippet
Related MCP Connectors
Cookie consent for GDPR/CCPA: scan sites for trackers, configure consent banners, get install code.
Set up GDPR and CCPA cookie consent: create a site, publish a banner, scan and categorize trackers.
GDPR/CCPA cookie consent: scan sites for cookies, track consent rates, generate privacy policies.
Cookie consent scanner: GDPR, CCPA, GCMv2. PASS/FAIL compliance checklists with fix recommendations.
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceEnables AI agents to install GDPR-compliant cookie consent banners on websites with a single command, handling domain registration, template assignment, and script injection.27 npm-
- AlicenseNot gradedqualityCmaintenanceEnables AI coding agents to generate LGPD-compliant cookie banners by detecting trackers in local projects, and to scan published sites for privacy violations, returning actionable results.Apache 2.0
- AlicenseAqualityAmaintenanceOne-step legal compliance for vibe-coded apps: scans project, generates privacy policies/TOS, installs cookie consent banner, and checks EU AI Act risk.1044 npmMIT

pageguard-mcpofficial
AlicenseAqualityFmaintenanceScan any project or website for privacy compliance issues directly in your AI coding tool. Detects tracking tech, cookies, and third-party data collection. Works in Claude Code, Cursor, and Windsurf.329 npm1MIT
Glama MCP Gateway
Add one secure layer between your agents and this server.