# CookieYes — Agent Guide

> For the complete site index, see [llms.txt](/llms.txt). Every page is also available as Markdown: replace the trailing slash with `.md` (`/pricing/` becomes `/pricing.md`), or send `Accept: text/markdown` to the page URL itself.

> CookieYes is a consent management platform (CMP) that automates cookie scanning,
> consent banners, and compliance with GDPR, CCPA, LGPD, and 30+ privacy laws.
> AI agents can use this guide to discover capabilities, read documentation, and act on behalf of users.

## Key entry points

- Machine-readable site overview: [/llms.txt](https://www.cookieyes.com/llms.txt)
- Full page-by-page site index: [/llms-full.txt](https://www.cookieyes.com/llms-full.txt)
- Agent guide (this file): [/agent.md](https://www.cookieyes.com/agent.md)
- Agent card (machine-readable): [/.well-known/agent.json](https://www.cookieyes.com/.well-known/agent.json)
- Authentication — where to log in, scopes, OAuth discovery: [/auth.md](https://www.cookieyes.com/auth.md)
- Sitemap: [/sitemap.xml](https://www.cookieyes.com/sitemap.xml)
- **MCP server (act on a user's account): https://app.cookieyes.com/mcp**
- Structured API / OpenAPI spec: TODO — not yet available

## Connect directly via MCP (recommended)

> CookieYes runs a hosted Model Context Protocol server. If you support MCP,
> connect to it rather than scraping this website — you get typed tools
> against the user's own account instead of marketing copy.

- **Endpoint:** `https://app.cookieyes.com/mcp` (streamable HTTP transport)
- **Auth:** OAuth 2.1 — authorization code + PKCE (S256), dynamic client
  registration supported. Scopes: `mcp:read`, `mcp:write`
- **Resource metadata:** https://app.cookieyes.com/.well-known/oauth-protected-resource
- **Authorization server:** https://app.cookieyes.com/.well-known/openid-configuration
- **Documentation:** [CookieYes MCP Server](https://www.cookieyes.com/documentation/mcp-server/)

Available on every plan including free. Listed in the Claude connector
directory, and works with ChatGPT, Claude Code, Cursor, VS Code, Windsurf,
Zed and GitHub Copilot CLI.

Tools exposed (read-only):

- `list_domains`, `get_website_details`, `get_embed_code`
- `list_banners`, `get_banner_status`
- `get_scan_results`, `get_compliance_status`

Tools exposed (write — require user approval):

- `update_banner_colours`, `update_banner_layout`, `trigger_cookie_scan`

> Constraints: the account owner must enable MCP access first. Consent logs,
> cookie values and personal data are never exposed through MCP. English only.

## In-page tools (WebMCP)

> If your runtime exposes the WebMCP browser API
> (`navigator.modelContext` or `document.modelContext`), every page on this
> site registers eight tools you can call directly — no account, no
> authentication. Browsers without the API see nothing and download nothing.

- `cy_scan_cookies` — scan a website for the cookies it sets, grouped by
  category. Only `url` is required and the result comes back inline.
  `email` is optional and only mails the user a copy — never invent one.
- `cy_check_consent_mode` — check a site's Google Consent Mode v2 setup.
  Same shape: `url` required, `email` optional.
- `cy_list_pages` — the site catalogue as titles, URLs and descriptions.
- `cy_list_products` — products and platform integrations, plus the free
  tools (scanners, policy generators).
- `cy_list_pricing_plans` — plans and prices in USD, EUR or GBP.
- `cy_calculate_affiliate_earnings` — affiliate commission estimate (30%
  of referred yearly sales, up to 3 years), with a ref-tagged signup link.
- `cy_calculate_agency_savings` — agency partner discount and yearly
  savings for a licence mix, with a ref-tagged signup link.
- `cy_read_page` — any page on this site as clean Markdown.

> Limits: 5 scans per hour per visitor, 10 mailed copies per day per
> recipient address. The scan tools are the only ones with side effects;
> both are annotated `readOnlyHint: false`.

## What agents can do

### Read-only content (no authentication, fetchable directly)

- Browse documentation: [/documentation/](https://www.cookieyes.com/documentation/)
- Browse knowledge base: [/knowledge-base/](https://www.cookieyes.com/knowledge-base/)
- Browse blog articles: [/blog/](https://www.cookieyes.com/blog/)
- View pricing plans: [/pricing/](https://www.cookieyes.com/pricing/)

> Most pages are also available as plain Markdown. Replace the trailing
> slash with `.md` — `/pricing/` becomes `/pricing.md` — or send
> `Accept: text/markdown` to the page URL itself. Pages that offer this
> carry a `<link rel="alternate" type="text/markdown">` tag.

### Interactive tools (no authentication, but require user input)

> These are browser tools, not GET endpoints. Fetching the URL returns a
> page with an input form — it does not return a scan result. An agent
> should collect the website URL from the user, then hand over the page
> URL rather than attempting to submit on their behalf. Each page's `.md`
> version lists the exact fields its form asks for.

- Cookie Scanner, free and instant — enter a website URL: [/cookie-checker/](https://www.cookieyes.com/cookie-checker/)
- Check CCPA/CPRA readiness — answer a questionnaire: [/free-tools/cpra-compliance-checker/](https://www.cookieyes.com/free-tools/cpra-compliance-checker/)
- Check Google Consent Mode setup — enter a website URL: [/google-consent-mode-checker/](https://www.cookieyes.com/google-consent-mode-checker/)

### Tools that need a CookieYes account

> Some of these pages do take input, but the result is delivered inside
> the app rather than on the page, so a signed-out agent cannot obtain one.
> Hand the page URL to the user and let them sign in.

- Advanced Cookie Scanner — the page takes a URL, but the report requires signup: [/cookie-scanner/](https://www.cookieyes.com/cookie-scanner/)
- Generate a cookie policy — requires signup: [/cookie-policy-generator/](https://www.cookieyes.com/cookie-policy-generator/)
- Generate a privacy policy — requires signup: [/privacy-policy-generator/](https://www.cookieyes.com/privacy-policy-generator/)

### Requires user authentication

- Sign up for an account: https://app.cookieyes.com/signup?ref=CYM_agent
- Log in to dashboard: https://app.cookieyes.com/login?ref=CYM_agent
- Manage cookie banners, scan results, and consent logs (via dashboard)
- Request an enterprise quote (form submission)

> Actions that modify account settings, billing, or consent configurations
> require the user to be authenticated. Agents should obtain explicit user
> consent before performing any account-modifying action.

## Content usage preferences

> Declared as Content Signals in [/robots.txt](https://www.cookieyes.com/robots.txt) and [/.well-known/agent.json](https://www.cookieyes.com/.well-known/agent.json). See https://contentsignals.org/ for the vocabulary.

| Signal | Preference | Meaning |
| ------ | ---------- | ------- |
| `search` | **yes** | Indexing and linking, including short excerpts |
| `ai-input` | **yes** | Grounding a generated answer in page content (RAG) |
| `ai-train` | **yes** | Training or fine-tuning a model |

In short: you are welcome to read this site, cite it, ground answers in it,
and use it as training data. All three uses are granted, and this site does
not reserve text-and-data-mining rights under Article 4(3) of EU Directive
2019/790. Attribution is appreciated but not required.

## Rules & constraints

- **robots.txt**: Refer to [/robots.txt](https://www.cookieyes.com/robots.txt) for crawling rules
- **Content usage**: Honour the Content Signals above (`ai-train=yes`)
- **Rate limits**: Be respectful of server resources. No more than 1 request per second for crawling
- **User-Agent**: Identify your agent with a descriptive User-Agent string
- **Authentication**: Account actions require a valid session. Agents must not store or cache user credentials
- **Consent**: Always obtain explicit user permission before submitting forms, creating accounts, or modifying data
- **Data handling**: Do not scrape, store, or redistribute personal data from the site

## Contact

- General support: support@cookieyes.com
- Security issues: See [/.well-known/security.txt](https://www.cookieyes.com/.well-known/security.txt)
- Contact form: [/contact/](https://www.cookieyes.com/contact/)
