Cookie Consent Generator
A cookie consent generator builds the banner markup for you instead of leaving you to write it. Set the position, colours, message and cookie lifetime on the left, watch the live preview, then copy the result in one of three formats: a 1,014-character script tag, a self-contained 1,810-character block of inline HTML, or a 1,123-character WordPress snippet for functions.php.
Layout
Colors
Content
Features
Live Preview
Your Website Content
Generated Code
💡 Paste this <script> tag before </body> in your HTML. The widget loads asynchronously.
💡 Self-contained HTML/CSS/JS. No external dependencies. Paste before </body>.
💡 Add this code to your theme's functions.php file or use a code snippets plugin.
GDPR & CCPA Compliance
- ✅ Explicit consent before setting non-essential cookies
- ✅ Option to decline or manage cookie preferences
- ✅ Consent stored locally with configurable expiry
- ✅ Link to your privacy policy
- ✅ No cookies set before user interaction
Cookie Consent Generator
Our free Cookie Consent Banner Generator helps you create a fully customizable, GDPR and CCPA-compliant cookie consent banner. Choose from multiple presets, customize colors, text, position, and features. Generate code as a lightweight script tag, self-contained inline HTML, or a WordPress PHP snippet.
Popular Tools
About Cookie Consent Generator
The left column is the whole configuration. Layout sets the banner to a bottom bar, a top bar or a popup anchored bottom-left or bottom-right, in bar, popup or floating-card style, with a border radius you drag from square to rounded. Colours are separate fields for the background, the text, the accept button and the decline button, so you can match a brand palette rather than pick from a theme. Content holds the banner message, both button labels, the privacy policy URL and the cookie lifetime in days. Four presets - minimal, GDPR full, elegant and colourful - set a dozen of those at once; GDPR full switches to a bottom-right popup with both a decline button and a settings link.
The preview on the right redraws as you type, and the code panel underneath offers three formats. Script tag is the shortest at about a thousand characters: it loads a hosted widget file and passes your settings as data attributes. Inline HTML is self-contained - style block, banner markup and a one-line script, roughly 1,800 characters with no external request. WordPress wraps the script tag in a PHP function hooked to wp_footer, ready to paste into a theme functions file.
The consent itself is stored in a first-party cookie named fwt_consent, set to accepted or declined, with a max-age of your expiry in days times 86,400 - 31,536,000 seconds at the default of a year - and a path of /. On the next page load the banner checks for that cookie and removes itself if it is present, so a visitor is not asked twice.
What this generator does not do matters as much as what it does. It produces a banner; it does not block analytics or advertising scripts until consent is given, it does not keep a record of who consented and when, and it does not scan your site to build a cookie inventory. GDPR Article 7(1) requires a controller to be able to demonstrate that consent was given, and Article 7(3) requires withdrawal to be as easy as giving it - neither is provided by a banner on its own. Treat the output as the visible layer and pair it with the plumbing that actually gates your scripts.
Use Cases
How to use
Press one of the four presets - minimal, GDPR full, elegant or colourful - to start from a sensible layout instead of the defaults.
Set the position and style in the Layout panel and drag the border radius until the preview matches the rest of your site.
Enter your background, text, accept and decline colours in the Colours panel as hex values.
Rewrite the banner message and the button labels in the Content panel, set your privacy policy URL and choose how many days the choice should last.
Pick Script Tag, Inline HTML or WordPress in the code panel and check the preview above it before copying.
Press Copy and paste the block into your template, then make your analytics and advertising tags wait for the fwt_consent cookie before they load.
Pro Tips
- Choose inline HTML if you care about requests. The script-tag and WordPress formats both load a widget file from this site, so the banner depends on an external host staying up; the inline block has no external dependency at all.
- Set the privacy policy URL before you copy. It is written into the generated code as a plain link, and a banner pointing at a missing /privacy-policy/ page is worse than no link at all.
- The expiry field is in days and is multiplied by 86,400 into the cookie max-age. At the default 365 days the generated code contains max-age=31536000; drop it to 30 and the visitor is asked again a month later.
- The Decline button is on by default and the presets disagree about it - minimal turns it off, GDPR full turns it on. Check the toggle after pressing a preset rather than assuming your earlier choice survived.
- Quotes and angle brackets typed into the message or button labels are escaped for you: a label of Accept "all" is written as Accept "all" in the data attribute, so it will not break the tag.
Troubleshooting
The banner never appears on the live site.
The most likely cause is a leftover fwt_consent cookie from your own testing - the banner removes itself whenever that cookie exists. Clear cookies for the domain, or open a private window. If it still does not show and you used the script-tag format, check that the widget file loads: a content blocker or a strict content security policy will stop an external script.
The banner shows on every single page load, even after accepting.
The consent cookie is not being kept. Check that the expiry field is not set to 0, since the max-age is the number of days multiplied by 86,400, and that the visitor is not browsing in a private window where cookies are discarded at the end of the session. The cookie is written with path=/, so it should apply across the whole site.
The generated code breaks the page when pasted.
Paste the inline HTML immediately before the closing body tag, not inside the head, because it contains markup as well as a style block. The WordPress version must go in functions.php or a child theme file, not into a post - it is PHP and will be printed as text anywhere else.
Analytics still runs after a visitor declines.
That is expected: the generated banner records the answer and nothing more. It does not remove or delay any tag. Wrap your analytics and advertising snippets in a check for the fwt_consent cookie so they only run when it reads accepted, or use a consent management platform that does the blocking for you.
The button label looks wrong in the generated code.
Characters that would break an HTML attribute are escaped on purpose. A label typed as Accept "all" appears in the code as Accept "all", and angle brackets become < and >. The browser turns those back into the original characters when the banner renders, so the visitor sees exactly what you typed.
Frequently Asked Questions
It is the visitor's permission to store or read information on their device beyond what the site strictly needs to work. In practice that means a banner asking before analytics, advertising or preference cookies are set, and a record of the answer. This generator produces the banner and stores the answer in a first-party cookie called fwt_consent, set to accepted or declined.
It depends on where your visitors are and what your site stores. Rules in the EU, the UK and several other jurisdictions require consent before non-essential storage, and a purely static site that sets no cookies at all generally does not need a banner. A site running analytics or an advertising tag usually does. This page cannot tell you which applies - check your own obligations or ask a lawyer.
Cookies fall under the GDPR when the data they hold identifies a person, and separately under ePrivacy rules that govern storing or reading anything on a device. That is why analytics identifiers usually need consent while a session cookie that keeps a shopping basket normally does not. The category toggles in this generator - necessary, analytics, marketing, preferences - mirror that split.
The default text in the Content panel is one: "We use cookies to enhance your browsing experience, serve personalized content, and analyze our traffic." Edit it to name what you actually run - "we use Google Analytics to count visits" is clearer and more defensible than a generic sentence. The preview updates as you type so you can see where the text wraps.
Configure the banner here, choose a format, and paste it. Inline HTML goes just before the closing body tag of your template. The script tag goes in the same place or in the head. The WordPress version goes in your child theme functions.php, where it hooks itself to wp_footer. Then do the part this tool cannot: stop your analytics and advertising tags from firing until consent exists.
No, and no banner does on its own. It gives the visitor a choice and remembers it, which is the visible part. GDPR Article 7(1) also requires you to be able to demonstrate that consent was given, and Article 7(3) requires withdrawing consent to be as easy as giving it. This generator keeps no consent log, offers no reopen link once the banner is dismissed, and blocks no scripts before the choice is made.
Script tag is about 1,000 characters and loads a widget file hosted on this site, passing your settings as data attributes. Inline HTML is about 1,800 characters and is entirely self-contained - style block, markup and a one-line script - with no external request. WordPress is about 1,100 characters of PHP that registers the script tag on wp_footer. Inline is the most independent; the other two are the easiest to update.
With the generated banner alone, only by clearing the fwt_consent cookie in their browser, because the banner reappears only when that cookie is absent. GDPR Article 7(3) requires withdrawal to be as easy as giving consent, so if you are relying on consent you will need to add your own link - typically in the footer or the privacy policy - that deletes the cookie and reloads the page.
The banner writes fwt_consent=declined and hides itself for the same number of days as an acceptance. Nothing else happens automatically: the generated code does not switch off any tags. Your own site has to read that cookie and skip loading analytics or advertising when it says declined - which is the piece of work this tool leaves to you.
This page is free and produces code you own outright, with no account and no per-visit quota, but it is a banner generator rather than a consent management platform. A full platform adds the parts listed above - script blocking before consent, a stored record of each choice, a re-open control and a cookie scan. Several offer free tiers with traffic limits; compare those limits with your monthly page views before choosing.