Cookie Consent Management at Coinbase
2025The cookie banner on the Coinbase and Base web domains runs on client-side consent libraries I wrote.
Codebases across Coinbase are in React and Next, so we built the package with React and TypeScript and made sure it is bulletproof (opens in a new tab). It has no other external dependencies, which keeps it lightweight.
The problem
Privacy law in the EU and UK requires opt-in consent before any non-essential tracking. In the US and most other regions it is opt-out. A consent banner has to reflect that difference and remember what the user chose.
Our old banner had not been maintained for five years, so we needed a new consent system for every domain across Coinbase.
What I built
A shared consent library, used across every Coinbase and Base domain:
- A region-aware banner and preferences center. Opt-in where the law requires it, opt-out everywhere else.
- Blocking of tracking scripts before they execute.
- Removal of cookies the user has not agreed to.
- Consent that persists across sessions, and across devices once someone signs in.
- A vanilla JavaScript version of the library for non-React codebases, like our external documentation (opens in a new tab) on Mintlify.
- Instrumentation, alerting, a runbook, and an incident severity model.
- A launch behind a kill switch, with exposure raised step by step: 1%, 5%, 20%, 50%, 80%, 100%.
Where it shipped
The banner runs on Coinbase.com for both signed-in and logged-out users, with consent following the account across devices. It also runs on the Help Center, the developer platform portal and its documentation site, and the Base domains: base.org, base.app, base.dev, account.base.app, join.base.app, and the wallet.
Our documentation sites are powered by Mintlify. We could not share our React package with them because it lives in our internal registry, so we built a vanilla JavaScript version. They inject one script and the banner runs.
Outcome
Consent is now enforced across the Coinbase and Base domains, and the system meets the consent requirements of the GDPR and ePrivacy Directive in the EU, and the UK GDPR and PECR in the UK. One shared library replaced the separate, tightly coupled implementations that each application carried before.