WordPress Plugin
The Contentpass WordPress Plugin integrates Contentpass with your WordPress site and supports multiple Consent Management Platforms (you can find the full list here). It includes a built-in script and iframe blocker to prevent third-party resources from loading before consent.
1. Create a Contentpass account and property
Go to publisher.contentpass.net and create your publisher account. The wizard will guide you through the steps of creating a publisher profile as well as the first property. The property's status page will present the required steps for a successful Contentpass integration. This document contains further details that should help you with the process.
You will need your Property ID and Base URL for the plugin configuration. These can be found in your property's settings in the Publisher Dashboard.
2. Install the plugin
- In WordPress Admin, go to Plugins → Add Plugin.
- Search for Contentpass Integration and install it from the WordPress plugin directory.
- Activate the plugin.
- After activation, the Contentpass menu appears in the WordPress admin sidebar with three items:
- Integration – CMP and Contentpass configuration
- Blocking Rules – Third-party script blocking
- Request Contract – Link to contact form
3. Configure CNAME
Since 3rd-party cookies don't work reliably anymore in most browsers, Contentpass subscribers must be identified using a 1st-party session.
To simplify handling of these 1st-party sessions, Contentpass provides an endpoint that must be configured behind a CNAME subdomain of the publisher's first-party domain.
In the following example we assume that the publisher's website is: https://www.example.com and the propertyId is 1234abcd. You can find your propertyId in the settings of your property. Can't find it? Get in touch with us to obtain your propertyId.
A CNAME must be set up as follows:
cp.example.com. 300 IN CNAME 1234abcd.12.with.contentpass.net.
Once the CNAME has been set up, Contentpass will automatically provision the required SSL certificates.
The plugin automatically checks if the CNAME is set up. As soon as it's found, the plugin will display the full Integration settings form and you can continue integration.
DNS propagation can take up to 24 hours. If the CNAME has just been configured, please try again later or use the "Check again" button on the Integration page.
4. Fill out the Integration page
Once the CNAME is configured and verified, the full Integration form will be available under Contentpass → Integration.
CMP integration mode
Choose how the plugin handles your CMP:
- CMP already integrated on my site – The plugin loads only the Contentpass stub for the selected CMP; it does not load the CMP script.
- Plugin should also load the CMP (default for new setups) – The plugin loads the CMP and Contentpass.
Click Save after changing the mode. CMP credential fields only appear when Plugin should also load the CMP is selected.
Common fields (all CMPs)
| Field | Description |
|---|---|
| Base URL | The CNAME subdomain for your property (e.g. cp.example.com). Usually pre-filled from your site domain. |
| Property ID | Your Property ID from the Publisher Dashboard (e.g. abc123). When you open a property in the dashboard, it also appears as the last segment of the URL in your browser's address bar (e.g. the abc123 in .../properties/view/abc123). |
| CMP | Select your Consent Management Platform. After choosing and saving, CMP-specific fields will appear (only when Plugin should also load the CMP is selected). If the CMP is already on your site, choose CMP already integrated on my site under CMP integration mode instead. |
| Debug URL password | Password required for debug URL query parameters (see Debug URLs below). Logged-in WordPress administrators (manage_options) may omit the password. |
| Code to load after consent | Optional custom <script> or <style> blocks that load after consent. Only <script> and <style> tags are allowed. |
Where to find CMP-specific IDs
Depending on the CMP you select, additional fields will appear. Use the tabs below to find each value in your CMP's dashboard:
- Consentmanager
- Didomi
- CCM19
- OneTrust
- Usercentrics V2/V3
- Sourcepoint
When Plugin should also load the CMP and Consentmanager is selected, paste
the external semi-automatic <script> snippet from Consentmanager →
Get Code into the textarea in the plugin settings. Use the semi-automatic
snippet, not the automatic-blocking snippet (typical src:
https://cdn.consentmanager.net/delivery/js/semiautomatic.min.js).
The plugin validates the snippet (allowed hosts and allowlisted data-cmp-*
attributes only).
Consentmanager ID (cmID)
Go to your Consentmanager client and select your CMP.
The ID is shown in the script snippet or in the CMP settings (e.g. in the URL or under "CMP ID").
It is a numeric value like
12345or an alphanumeric identifier.
Didomi API Key (didomiapi)
Log in to the Didomi dashboard.
Go to Settings → API keys.
Use the API key for your app (not the SDK key).
- The key is a UUID or alphanumeric string.
CCM19 API Key and Domain ID
Log in to the CCM19 dashboard.
Go to Settings or Developer section.
API Key: Found under API or Developer settings.
Domain ID: Found in the domain/site configuration or in the CCM19 script snippet for your domain.
OneTrust data-domain-script ID (scriptId)
Log in to MyOneTrust.
- Open your Cookie Compliance property.
The script ID is the value of the
data-domain-scriptattribute in your OneTrust script tag.It is typically a UUID such as
xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx.
Usercentrics Settings ID (settingsId)
Log in to the Usercentrics dashboard.
- Select your application/settings.
The Settings ID is shown in the integration code snippet (e.g.
data-id="abc123def456") or in the application settings.- Use the correct version (V2 or V3) that matches your Usercentrics setup.
Sourcepoint ID (sourcepointID)
Log in to the Sourcepoint dashboard.
- Open your property.
The Account ID or Property ID is in the script snippet (
accountIdor similar) or in the property settings.- It is typically a numeric value.
Property URL must match the URL configured for your property in Sourcepoint.
CMP-specific steps
By default, the plugin runs in staging mode until your Contentpass property is live. While staging is active, anonymous visitors see no Contentpass, no CMP (from the plugin), and no script blocking or placeholders; only logged-in Editors and Administrators see the full integration. Staging is forced when Contentpass config.json has isApproved=false or isLive=false — you cannot disable it in WordPress until the property is live.
Debug URLs
Set a Debug URL password under Contentpass → Integration, then append these query parameters to any front-end URL:
?cpdebug=settings&cpdebug_key=PASSWORD— logs front-end plugin config to the browser console only; does not load Contentpass.?cpdebug=staging&cpdebug_key=PASSWORD— loads the full integration (Contentpass + CMP + blocking) for that request, even for anonymous visitors.
Without a saved password, debug URLs have no effect for anonymous visitors. Logged-in WordPress administrators (manage_options) may omit cpdebug_key. Full-page cache or CDN may serve stale HTML — purge cache or test with a fresh query string after changes.
- any not mentioned
- CCM19
- OneTrust
- Sourcepoint
There are no specific steps for other CMPs aside from those in the tabs above.
This guide assumes you are visiting the English language version of the CCM19 dashboard.
Before integrating your CMP with contentpass, you must configure specific settings for your site on the CCM19 dashboard.
4.1. Enable IAB TCF API
First of all you must ensure that the IAB framework TCF support option is activated. All you need to do is visit the "IAB Framework (TCFv2)" page on your domain dashboard and make sure the "Activate now" option in the "IAB framework support" section is enabled (it is usually enabled by default).

4.2. Enable Ad- and Tracking-Free Network (complete this step last!)
IMPORTANT: Activating this setting will disable the CMP from displaying the first layer (CCM19's widget). This is because the CMP will assume that the consent layer is being handled by the ad- and tracking-free network i.e contentpass. This is the desired behaviour. Please only activate this option when all other onboarding steps are complete and your property is ready to go live.
Instructions: In order for our SDK to connect with CCM19's code you must enable the "My website is part of an ad- and tracking-free network" option in the Developer settings/Frontend behavior section for your domain.
Find Your Domain Dashboard
First you will need to visit the dashboard page for your site aka domain.

Locate The Developer Settings
At the very bottom of the left-side navbar (you might need to scroll) there is an option for Developer Settings (Developer-Einstellungen in German), click this.

Turn On Required Frontend Setting and save
At the top of this page there is a section of settings called "Frontend Behaviour" ("Frontend-Verhalten" in German). The setting required to integrate CCM19 with contentpass is called " My website is part of an ad and tracking-free network" ("Meine Website ist Teil eines werbe- und trackingfreien Netzwerks" in German). This option is turned off by default. This must be switched to on. Then click the "Save" button at the bottom of the screen to save this setting and you are done!

Once this setting is turned on you can now integrate your CMP with contentpass. Please double-check that IAB Framework Support is turned on.
Set up OneTrust
We assume a valid TCFv2 configuration including TCFv2 Geolocation Rule, Vendorlist, etc. Based on this setup, the following changes need to be done to have the best contentpass experience.
Configure privacy center buttons
First, open the privacy center tab of your TCF2-based template:

Open "Content" on the left and click on the edit icon next to "Button Set". Configure the settings according to the screenshot below. The most important ones are:
- Show Allow All button
- Show Reject All button
- Show Close Button
- Show Close Button (X)

Make sure to apply these changes to all languages supported in your template.
Disable banner from being shown automatically
When publishing your changes, make sure you enable the "Prevent Fetching Banner" toggle.

Add contentpass snippet
Please add the following script below the OneTrust script. The plugin uses your
scriptId (data-domain-script), cpBaseUrl and
cpPropertyId from the Integration form. Reference snippets (for non-WordPress
setups):
In addition to your existing sp.config the isSPA flag must be
set to true; This allows us to control the timing of the Sourcepoint scenario
execution in the callback of cp('authenticate'). We use a Sourcepoint
targeting parameter to distinguish contentpass users from visitors that have not consented
yet. The key acps is used throughout this documentation to refer to that
parameter.
Sourcepoint first layer
You can start by using the contentpass template from Sourcepoint's global template library. If you prefer to build upon your existing message, you can also include the contentpass functionality the following way:
Add a signup for contentpass button to include the "Action" "Custom Javascript" with the value:
cp('signup')Add a login with contentpass link to include the "Choice option" "Custom Javascript" with the value
cp('login')
In all cases, please make sure to include the contentpass logo on the signup button (with the same color as the corresponding button text) and all text regarding contentpass is the same as in the global template.
Sourcepoint scenario
The base setup usually consists of two steps containing the "Consent Gate" conditions "No Action" and "Rejected to Any" to surface the consent layer for visitors with insufficient consent status. Please include an
additional condition in all your current and future scenario steps of all active scenarios
to prevent messaging from being shown to contentpass users. Click the
Add Condition button and then select Key Value Pair Targeting.
Please make sure this condition is anywhere before the message delivery setting. This Key
Value Pair has to be set up the following way:
Pages:
exclude(selecting exclude negates the key value pair)Key:
acps(key of our custom targeting parameter)Value:
match(we only want exact matches)String:
true(value of our custom targeting parameter)

We strongly recommend, that you also add a "Page URL Match" condition to keep legal pages like your privacy policy accessible.
5. Block third-party resources ("Blocking Rules")
To comply with Contentpass requirements, third-party resources (scripts, iframes) must not load before the user has given consent. The plugin includes a script and iframe blocker for this purpose. Script blocking follows the same staging rules as Contentpass and the CMP: in staging, only the preview audience (Editors/Administrators) is affected; in production, all visitors.
Visit our docs on Third Party Resources for more information on how to block third parties and the technical details on why this is important.
Using the Blocking Rules page
Go to Contentpass → Blocking Rules in the WordPress admin.
Block List (Scripts to Block)
Add URL patterns that should be blocked until consent is given. Any script or iframe whose src contains the pattern will be blocked and replaced with a placeholder (or hidden, if configured via the checkbox).
| Column | Description |
|---|---|
| URL / Script Source | A substring of the URL to block (e.g. facebook.com, youtu.be, googletagmanager). It does not have to be a full URL. |
| Vendor name | When set, it will overwrite the automatically detected vendor name in the placeholder. |
| Privacy Link | Optional, but highly recommended to be set URL to the service's privacy policy. Shown below the placeholder button. |
| Hide Placeholder | When enabled, the content is blocked without showing a visible placeholder (stealth mode). |
Examples of useful patterns: doubleclick, analytics, facebook, youtube, googletagmanager, hotjar.com.
Please check the findings on the Publisher Dashboard for your site to identify third-party resources to block.
6. Mention Contentpass in your Privacy Policy
While we do not process any data of non-subscribers, we receive the IP addresses of your visitors for technical reasons. Please inform your visitors about this data processing and link to our privacy policy by including the following snippet on your privacy policy page:
- plain text
- html
Contentpass
Auf unserer Website bieten wir Ihnen einen Service zum werbe- und tracking-freien Zugang mit Contentpass an. Dies ist ein Angebot der Content Pass GmbH, Wolfswerder 58, 14532 Kleinmachnow, Deutschland. Beim Abschluss des Service wird Contentpass Ihr Vertragspartner.
Um Ihnen diesen Service auf unserer Website anzuzeigen und damit anbieten zu können, verarbeitet Contentpass, in unserem Auftrag, mit dem Besuch unserer Website Ihre IP-Adresse. Für die Registrierung sowie die Vertragsabwicklung des Contentpass und die damit einhergehende Datenverarbeitung ist Contentpass Verantwortlicher im Sinne der DSGVO. Wir sind ausschließlich Verantwortlicher für die Verarbeitung Ihrer IP-Adresse.
Grundlage für die Datenverarbeitung der IP-Adresse, im Rahmen unserer Auftragsverarbeitung mit Contentpass, ist unser berechtigtes Interesse Ihnen die Möglichkeit zu bieten, unsere Website werbe- und tracking-frei aufrufen zu können und Ihr Interesse an der Nutzung unserer Website praktisch ohne Werbung und Tracking [Art. 6 Abs. 1 lit. f) DSGVO]. Zudem erfüllen wir hiermit die rechtliche Verpflichtung, eine rechtskonforme Einwilligung in einwilligungsbedürftige Datenverarbeitungen einzuholen [Art. 6 Abs. 1 lit. c) DSGVO].
Bitte klicken Sie auf die folgenden Links, um mehr zum Datenschutz bei Contentpass zu erfahren, sich in Ihr Contentpass-Konto einzuloggen, oder sich für Contentpass zu registrieren.
<h3>Contentpass</h3>
<p>Auf unserer Website bieten wir Ihnen einen Service zum <a href="https://contentpass.net">werbe- und tracking-freien Zugang mit Contentpass</a> an. Dies ist ein Angebot der Content Pass GmbH, Wolfswerder 58, 14532 Kleinmachnow, Deutschland. Beim Abschluss des Service wird Contentpass Ihr Vertragspartner.</p>
<p>Um Ihnen diesen Service auf unserer Website anzuzeigen und damit anbieten zu können, verarbeitet Contentpass, in unserem Auftrag, mit dem Besuch unserer Website Ihre IP-Adresse. Für die Registrierung sowie die Vertragsabwicklung des Contentpass und die damit einhergehende Datenverarbeitung ist Contentpass Verantwortlicher im Sinne der DSGVO. Wir sind ausschließlich Verantwortlicher für die Verarbeitung Ihrer IP-Adresse. </p>
<p>Grundlage für die Datenverarbeitung der IP-Adresse, im Rahmen unserer Auftragsverarbeitung mit Contentpass, ist unser berechtigtes Interesse Ihnen die Möglichkeit zu bieten, unsere Website werbe- und tracking-frei aufrufen zu können und Ihr Interesse an der Nutzung unserer Website praktisch ohne Werbung und Tracking [Art. 6 Abs. 1 lit. f) DSGVO]. Zudem erfüllen wir hiermit die rechtliche Verpflichtung, eine rechtskonforme Einwilligung in einwilligungsbedürftige Datenverarbeitungen einzuholen [Art. 6 Abs. 1 lit. c) DSGVO].</p>
<p>Bitte klicken Sie auf die folgenden Links, um <a href="https://www.contentpass.net/privacy">mehr zum Datenschutz bei Contentpass</a> zu erfahren, sich <a href="https://www.contentpass.net/login/" onclick="cp('login'); return false;" target="_top" >in Ihr Contentpass-Konto einzuloggen</a>, oder sich <a href="https://www.contentpass.net/register/" onclick="cp('signup'); return false;" target="_top" >für Contentpass zu registrieren</a>. </p>
Note:
Link target for login:
javascript: cp('login');
Link target for signup:
javascript: cp('signup');
Since these are not quite ordinary links, it may happen that your CMS does not support them. In that case, you can simply link to https://www.contentpass.net/login and https://www.contentpass.net/signup instead.
7. Using the cpauthenticated CSS class
While the stealth mode hides the placeholder, it does not automatically hide its parent container, to not interfere with your website and possibly hide other elements within this container you wish to not hide.
To improve the experience for Contentpass subscribers (e.g. hiding ad slots), the Contentpass script adds the class cpauthenticated to the <body> when the user is logged in and has a valid subscription.
You can use this in your CSS to adjust layout for subscribers:
/* Hide ad containers for Contentpass subscribers */
body.cpauthenticated .ad-container {
display: none;
}
Apply this CSS as early as possible to avoid layout shifts—e.g. in the first CSS file loaded or as high as possible in the <head>.
We do not recommend relying on this as a robust method for recognizing Contentpass users for business logic. CSS classes can be easily manipulated by the user or any other javascript running on the page. Additionally there is no guarantee that the CSS styles are applied before your javascript runs.
For more examples of styling with cpauthenticated, refer to the Web SDK documentation and the Contentpass integration guides for your CMP.
8. Placeholder CSS settings in Block Scripts
The Blocking Rules page includes a Placeholder Styling section to customize the appearance of blocked content placeholders.
A live preview (desktop, tablet, mobile) shows how the placeholder will look with your current settings.
Button text and privacy link text must be customized per language. The provided languages are configured in the settings in our Publisher Dashboard.
| Setting | Description |
|---|---|
| Border Color | Color of the placeholder box border (default: #212121). |
| Border Width | Border width (e.g. 2px). |
| Padding | Internal spacing of the box (e.g. 20px). |
| Background Color | Background color of the placeholder (default: #f5faff). |
| Background Image | Optional background image URL. |
| Text Color | Color of the placeholder text. |
| Border Radius | Corner roundness (e.g. 8px). |
| Button Background | Background color of the "Load" button. |
| Button Text Color | Text color of the button. |
| Content Alignment | Text alignment inside the box (left, center, right). |
| Placeholder Text | HTML template. Use {name} for the automated script/iframe name and {type} for script or iframe. |
| Button Text | Template for the button label (supports {name}). |
| Privacy Link Text | Template for the privacy link. Use [priv]…[/priv] to mark the clickable part (e.g. Read more [priv]here[/priv]). This is a dummy for the privacy link provided in the block list. There is no link needed here and only text must be provided. |
| Additional CSS | Extra CSS rules for the placeholder box (e.g. box-shadow, font-size). |