Overview
Sanity.io is a headless content management platform that provides structured content through APIs. Its client-side scripts appear on websites only during authenticated content editing sessions — the Visual Editing overlay and live preview functionality connect the editor's browser to the Sanity Content API. Standard visitors browsing the published website do not encounter any Sanity scripts.
What This Script Does
Sanity's browser-side scripts are limited to authenticated editor sessions:
- Visual Editing overlay: When an authenticated content editor accesses a preview URL, Sanity's scripts render a visual editing interface overlaying the page content. This allows editors to click on content elements and edit them in place.
- Live preview: Connects to the Sanity Content API via WebSocket or polling to display real-time draft content changes as editors make them in Sanity Studio.
- Authentication: The preview/editing scripts require authenticated access — typically via a Sanity auth token or cookie. Only users with editor permissions can access these scripts.
- No visitor-facing scripts: On the published, production version of the website, content is delivered as static or server-rendered HTML. Sanity's scripts are not loaded in the visitor's browser.
- No cookies for visitors: Sanity does not set cookies on the production domain for regular site visitors. Authentication cookies are limited to the editing context.
Consent & Compliance
Sanity falls under the functional consent category. Its scripts serve a content editing function used exclusively by authenticated editors.
Under GDPR and ePrivacy, Sanity's scripts are not loaded for regular website visitors, so there is no ePrivacy consent trigger for the general public. The editing cookies are used only by authenticated CMS users in the course of their work, which falls under the site operator's internal tooling.
Under CCPA/CPRA, Sanity does not collect personal information from website visitors. Content editors interact with Sanity as part of their professional duties, governed by the organization's employment or contractor agreements.
Should You Block This Without Consent?
No. Sanity's scripts are loaded only for authenticated content editors during preview sessions, not for regular website visitors. There is nothing to block in the visitor-facing context. The editing tools serve an essential content management function for the site operator's team.
Is Sanity.io GDPR compliant?
Sanity.io typically loads functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Sanity.io can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Sanity.io, not on Sanity.io itself.
Consent Categories
Also Known As
Industries
Tracked Domains (1)
sanity.ioFunctionalsanity.io is a functional domain operated by Sanity.io, used to run site features like chat, video, embeds, and preferences.
Frequently Asked Questions
Related Vendors
Manage consent for Sanity.io
ConsentStack automatically detects and manages Sanity.io trackers so your site stays compliant with global privacy regulations.