Introduction
Permito is a consent toolkit for websites built with React. It shows a banner, lets visitors choose categories and individual services, stores that decision, and makes sure third-party code only runs once it is allowed.
Packages
Section titled “Packages”| Package | Use it for |
|---|---|
@permito/react |
React and Next.js apps. Includes everything from the core. |
@permito/core |
Any other stack, or your own UI. Framework-agnostic, no dependencies. |
Principles
Section titled “Principles”- Opt-in by default. Only categories you mark as
requiredare active before a decision. Opt-out exists, but only if you configure it. - Equal choices. “Accept all” and “Reject all” are always shown together and styled identically.
- Data minimisation. The stored decision contains categories, services, versions, a timestamp and the source of the decision. No IP address, no user agent, no identifier.
- No external communication. The open-source packages never call a server.
- Accessibility. Keyboard operable, focus management, labelled controls,
prefers-reduced-motionand dark mode support, tested with axe-core.
What Permito is not
Section titled “What Permito is not”Permito is technical infrastructure, not legal advice. It does not tell you which services need consent, it does not scan your site and it cannot guarantee compliance with the GDPR, the Swiss revDSG or any other law. See Legal notes.
Installation
Section titled “Installation”pnpm add @permito/react# or: npm install @permito/reactContinue with the guide for your stack: Next.js, React with Vite or without React.