2 operations. Call each with POST https://app.chirply.io/api/v1/actions/<name> and a bearer token; the response is { "data": { "action", "summary", "result" } }. A read badge means the operation changes nothing; write requires the credential’s write scope.
Cookie consent settings for a site
consent.get_policyread
Reports the cookie-consent banner settings for one tracked website or hosted-page set — whether a banner is shown and to whom, what happens before a visitor chooses, the wording, the link to the account's privacy policy, which categories a visitor can pick, and how long a choice is remembered. Use it to audit whether consent is switched on across an account's sites. Read-only.
Also answers to is the cookie banner on, cookie consent settings, GDPR banner settings, check consent for this site.
Parameters
Field
Type
Required
Description
site_id
string (uuid)
required
The tracking site to read. Use tracking.list_sites to find it; the account's Chirply-hosted funnels, stores and checkout pages are one of these sites too.
Over MCP the same operation is the tool consent_get_policy at https://app.chirply.io/api/mcp, same bearer token, same input.
Change cookie consent for a site
consent.set_policywriteconfirmadmin only
Turns the cookie-consent banner on or off for one tracked website or hosted-page set, and sets its wording, privacy-policy link, categories and how long a choice is remembered. Switching it on has a REAL EFFECT ON VISITORS AND ON DATA: with mode 'eu' or 'all' and prior 'block', affected visitors see a banner and NOTHING is collected about them — no page views, no heat maps, no session recordings — until they accept, so analytics for those regions will drop. Switching it off stops asking and resumes collecting immediately, which may be unlawful in the EEA and UK. The banner always offers Reject as prominently as Accept and never pre-ticks a category; that is not configurable.
Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.
Also answers to turn on the cookie banner, enable cookie consent, GDPR banner, add a cookie notice to my site.
Parameters
Field
Type
Required
Description
site_id
string (uuid)
required
The tracking site to change. Use tracking.list_sites to find it.
mode
"off" | "eu" | "all"
required
Who sees the banner. 'off' means no banner at all and is the default. 'eu' shows it only to visitors the network places in the EEA, the UK or Switzerland — the usual choice. 'all' shows it to everyone, everywhere.
prior
"block" | "notice_only"
optional
What happens before the visitor chooses. 'block' (the default) collects nothing until they accept, and is the only lawful option in Europe. 'notice_only' shows the banner but keeps collecting while they decide — do not use it for European visitors.
title
string
optional
Banner heading. Leave unset to use Chirply's default wording, which is written to read plainly and to survive a regulator's reading.
message
string
optional
Banner body text. Leave unset for the default wording.
policy_url
string
optional
Link to the account's own privacy or cookie policy, shown in the banner. Must be an http(s) URL or a site-relative path; anything else is dropped.
categories
array of ("analytics" | "marketing")
optional
Which choices the visitor is offered: 'analytics' covers Chirply's own visitor tracking, heat maps and session recordings; 'marketing' covers retargeting pixels attached to the site. Defaults to both.
remember_days
integer
optional
How many days a visitor's choice is honoured before they are asked again. European guidance says no more than a year, so the maximum is 365 and the default is 182.