Where the TCF consent string actually travels in header bidding
October 1, 2026 · CookieCitadel
The TCF consent string has a specific journey: the CMP writes it, the page exposes it, the prebid wrapper picks it up, and each bidder adapter forwards it to its endpoint. Every handoff is a place where the string can be dropped, truncated, or never requested. When bid requests arrive without a usable consent signal, bidders treat the inventory as non-consented and the publisher eats the revenue difference. Verifying the string end to end, at each handoff, is a routine every publisher running header bidding should run.
The intended journey
Start with the intended path, because debugging means comparing reality against it. The CMP generates the TC string after the visitor makes a choice and exposes it through the standard APIs. The page, usually through the prebid wrapper's consent management module, reads the string and attaches it to each auction. Each bidder adapter includes the string in its request to the bidder's endpoint. The bidder then applies the purposes and vendor consents it finds there.
Note what this chain assumes: that the CMP has finished before the auction starts, that the wrapper is configured to wait for it, and that every adapter actually forwards the string. Each assumption fails in real deployments, and each failure is silent from the publisher's side. The auction still runs. The bids just come back lower, or not at all.
Drop point 1: the CMP to page handoff
The first failure is timing. If the auction starts before the CMP has written the string, the wrapper reads nothing and the auction proceeds without consent data. This happens when the wrapper is not configured to wait for the CMP, or when the CMP loads slowly and the auction timeout fires first. The symptom is intermittent: some pageviews carry the string, some do not, depending on a race.
Check the CMP's API directly on a test page: call the standard function and confirm the string exists before any auction code runs. Then check the wrapper's configuration for the consent module settings that control waiting. If the wrapper fires auctions on a timer that does not account for the CMP, the string will lose the race on slow connections and slow devices, which is exactly the traffic you least want to misprice.
Drop point 2: the wrapper configuration
The wrapper has to be told to collect the string and pass it along. A consent management module that is installed but misconfigured, wrong CMP ID, wrong timeout values, or the module simply not enabled for a given ad unit, produces auctions that look normal but carry no signal. Audit the wrapper config against the CMP you actually run, not the one you ran last year.
Also check what happens on the reject path. Some configurations only attach the string when the visitor accepts; on reject, the auction goes out with no string rather than with a string recording the rejection. Bidders cannot distinguish no signal from no consent, and they price accordingly. The reject path needs the same verification as the accept path.
Drop point 3: bidder adapters
Not every adapter forwards the string, and not every adapter forwards it correctly. Older adapter versions predate current TCF versions. Some adapters read the string from the wrong location. A few document consent support they do not fully implement. When a specific bidder's win rate or CPM looks wrong, check whether its requests actually contain the string before assuming it is a demand problem.
Keep a list of which bidders receive the string in your actual bid requests, verified from the network log, not from documentation. Update it when you upgrade the wrapper or add a bidder. Documentation describes intent; the network log describes reality.
How to verify end to end
The verification routine: load a test page, accept all, and confirm the string exists via the CMP API. Trigger an auction and inspect the outgoing bid requests for the consent parameter. Decode the string and confirm it reflects the choice you made. Then repeat with reject all and with necessary-only. Three consent states, each checked at the CMP, the wrapper, and the bid request. Anything missing at any stage is a finding with a known location.
Run this after every wrapper upgrade, CMP change, or new bidder onboarding. The string's journey crosses three systems owned by three different parties, and any of them can break it without telling the others.