
How to find which script sets a cookie in Chrome
A cookie's domain tells you where it belongs. It does not tell you which line of JavaScript created it. First determine whether the cookie came from an HTTP response or a browser script. Then follow the response or call path. Searching a tag-manager container before making that distinction can send you to the wrong part of the stack.
You need access to the browser, not necessarily the site's source repository, to start this investigation. Source maps, tag-manager preview access and a staging environment make the final attribution much easier. Where those are unavailable, keep the conclusion narrower: a request origin is useful evidence, but it is not always the exact caller.
Record the cookie identity before searching for it
Write down the name, domain and path. Include a partition key if the browser shows one, along with Secure, HttpOnly and SameSite attributes. Record whether the cookie existed before the page loaded. Avoid pasting its value into a public issue; an apparently random string may be a session credential or a persistent identifier.
Reproduce the event with DevTools open before navigation. Keep a baseline without banner interaction, then note the exact action that produces the cookie. If you only opened DevTools after the cookie appeared, start again rather than treating a missing request as proof that JavaScript created it.
If the cookie comes from a response, follow the request
- Search the recorded network traffic for the cookie name and inspect candidate response headers for Set-Cookie.
- Record the response URL and status. Check redirects as well as the final document; an earlier response may be responsible.
- Check whether Chrome accepted the cookie or blocked it. An attempted Set-Cookie header and a stored cookie are different observations.
- Inspect the request initiator to understand why the browser made that request. If a JavaScript stack is available, follow it into the relevant source.
- If a first-party endpoint sets the cookie, investigate the application or middleware serving that endpoint. Do not assume a third-party hostname is required for tracking.
Chrome's Network reference documents the Initiator column and the available request stack trace. These help explain a request. They do not, by themselves, identify every JavaScript cookie write on the page.
If JavaScript writes it, narrow the caller
Search loaded sources for the cookie name and the vendor's initialization code. Look for cookie helpers as well as direct document.cookie assignments. Names can be assembled dynamically, so a failed text search is not decisive. Use a source breakpoint on the candidate write or helper, reload, and inspect the call stack when execution pauses.
When source maps are available, work from the original modules instead of guessing from a minified bundle name. On staging, temporarily disable one suspected integration at a time and repeat the same action. A disappearing cookie narrows the cause, but check that the experiment did not also prevent unrelated parts of the page from loading.
| Evidence | Useful conclusion | What it does not prove |
|---|---|---|
| Set-Cookie on a captured response | That response attempted to write the cookie | That the browser accepted the write |
| Paused execution at a cookie assignment | This execution path attempts the write | That it is the only writer of that cookie |
| JavaScript stack for a network request | This stack caused that request | That the same stack wrote a cookie separately |
| Browser-provided initiator origin | The originating document or frame is known | The exact script file, function or GTM tag |
| Cookie disappears when a tag is disabled | The tag is a candidate dependency | A complete causal chain without further checks |
Where ConsentScope helps, and where Chrome is still needed
The ConsentScope DevTools panel brings captured events and their consent timing together. Its Initiator Trace displays available browser-provided origin and frame information for third-party requests. That can point you toward an embedded player, a document or another origin worth investigating.
Initiator Trace is not a full JavaScript debugger. It does not promise a source line for every cookie, and an origin-only trace cannot identify a specific tag inside a GTM container. Use Chrome's stack and source tools, or the container's preview mode, when you need that level of attribution. Keep both pieces of evidence in the same ticket.
Inspect the request in its consent context
Extension Pro includes the DevTools panel, Initiator Trace and Debug Snapshot. Use them to organize captured evidence while Chrome handles source-level debugging.
Add Pro diagnostics to your browserA worked investigation, without invented audit results
Consider this hypothetical staging problem: a marketing cookie appears after Reject all. A developer finds the vendor tag in GTM and disables it, but the cookie still appears. The next capture shows a second installation loaded by a site plugin. The practical lesson is to test the actual writer rather than stopping when you find the first familiar vendor name.
A useful ticket would include the exact reproduction path, cookie identity, request or breakpoint evidence, the suspected second installation, and a retest after its removal. The example is an investigation pattern, not a claim about a real website or a finding produced by ConsentScope.
Avoid three attribution traps
The cookie is first-party, so our application must have written it
A third-party library executing on your page can create a cookie scoped to your domain. The storage domain alone does not identify the library owner. Keep the distinction between the domain storing the cookie and the code responsible for the write.
The initiator says Other, so there is no source
It means that this view did not give you a useful script attribution. Recheck document responses, redirects, frame activity and whether recording began early enough. If the evidence still stops at the request, report that boundary honestly.
The export is redacted, so it is safe to publish
Inspect URLs, request payloads and screenshots before sharing. Redacting cookie values does not remove every possible identifier. Use a private developer ticket for sensitive evidence, and follow the client report template for a summary that does not expose raw session data.
ConsentScope Team
Verified authorConsentScope product team
We build ConsentScope and write practical guides to inspecting browser storage, consent signals and network activity. Our examples distinguish recorded observations from test scenarios.
Related articles
Third-Party Scripts & GDPR: What Developers Need to Know
Learn how third-party scripts impact GDPR compliance. Technical guide for developers on detecting, blocking and auditing external scripts before user consent.
Cookies still set after "Reject all"? How to find the cause
Separate old cookies from new writes, trace the request or script responsible, and retest rejection, reloads and consent withdrawal in your browser.
Cookie audit report for clients: template and worked example
Build a client cookie audit report with scope, evidence, findings and retest criteria. Download an editable template and view a clearly labeled sample PDF.