ℹ️ Availability: the Authenticated Scanner is available on the Enterprise plan. See goadopt.io/plans.
What is the Authenticated Scanner
The Authenticated Scanner is the AdOpt feature that reads cookies and local storage in the logged-in areas of your site — pages that only load after a login (checkout, customer dashboard, subscriber area).
In these areas, your site usually fires services that only exist after authentication. Without logging in, the regular Tag Scanner can't see them. The Authenticated Scanner solves this: you teach AdOpt how to log in and scan a specific URL inside the logged-in area, completing the Tag list of your cookie banner.
When to use it
Use it when Tags fire only after login and therefore don't show up in the standard Tag Scanner. For example: a checkout that loads a conversion pixel only for logged-in users, or a dashboard with analytics tools exclusive to the customer area.
Before you start
The logged-in URL you want to scan must already be registered in your Disclaimer's URL Mapping.
Have the login URL and a test user's credentials ready.
Know which fields and buttons make up the login (email, password, sign-in button) — you'll point to each one.
How to configure it
Log in to your AdOpt account.
Select the (1) Organization that holds the Disclaimer with the site to be scanned.
In the left menu, choose the (2) Disclaimer.
Open the (3) Tag scanner step of the Disclaimer.
Click (4) Authenticated Scanner.
Click (5) + Add event to set up your event.
Clicking + Add event opens a window to configure each step of the authentication:
Name the event. E.g.: Checkout.
Enter the URL to be scanned, inside the logged-in area (it must already be registered in the Disclaimer).
Enter the login URL.
Create the events that reproduce the login step by step.
The two event types
You build the login by combining two event types, in the order a person would follow:
Write — fills a text field (for example, email and password). You define what will be written and the field's selector.
Click — triggers a button, link or checkbox (for example, the "Sign in" button). You define only the element's selector.
Events run in the order you configure them — build them in the real login sequence.
How to find the selector
The selector is how you identify, on the page, the field or button the event will use. To copy it:
On your login page, right-click the element and choose Inspect.
In the Elements tab of the developer tools, the element is highlighted.
Right-click the highlighted element and choose Copy > Copy selector.
Paste it into the event's Query selector field.
Tips for a good selector:
It can be an ID, a CSS class, the element name, or a combination.
Make sure the selector is unique to that element, so the scanner doesn't confuse it with another.
📢 Important: repeat the process until every login event is filled in, then click Save. Before running the scanner, review and validate the events — a wrong selector breaks the login and the scan won't happen.
What changes after you set it up
With the Authenticated Scanner configured, Tags that only exist in the logged-in area start being identified and join your Disclaimer's Tag categorization, alongside the others. In practice, your cookie inventory becomes more complete — and a complete inventory is what supports specific and informed consent, as required by the GDPR (and equivalents like the LGPD and CCPA): visitors can only truly decide about the services your cookie banner actually knows and presents.
After scanning, categorize the newly found Tags (Unknown Tags don't appear on the banner until categorized) and save.
Do I have to scan the logged-in area?
It isn't a mandatory step — it's a coverage decision. But it's worth understanding what's at stake: if your site runs services in areas that only load after login and you don't scan them, those Tags stay out of your Disclaimer's inventory — meaning they run without being presented to the visitor.
The cookie banner is usually shown before login — the most common setup. When you use the Authenticated Scanner, the logged-in Tags join that same banner. So, before the visitor even authenticates, the banner presents the full picture — the Tags that run before and after login — and the visitor decides on all of them at once. The consent collected in the pre-login banner then also covers the services that only fire after login, with no need to show the banner again after authentication.
What's the legal basis for logged-in services?
With this strategy — presenting the logged-in Tags in the banner and collecting the visitor's choice — the legal basis for those services is consent: in Europe, GDPR Art. 6(1)(a); in Brazil, LGPD Art. 7º(I). To be valid, consent must be freely given, specific and informed — and it's the complete inventory, including the logged-in Tags, that provides the "informed" part.
Consent, however, isn't the only possible legal basis for processing data in a logged-in area. Depending on the purpose, a service may rely on another basis — for example, performance of a contract (GDPR Art. 6(1)(b); LGPD Art. 7º(V)), when the service is strictly necessary to deliver what the user signed up for. In that case it's common to tie those services to the Terms of Use the user accepts when creating an account or subscribing.
One important caveat: bases like performance of a contract only cover what is strictly necessary for the contracted service. Analytics, marketing or personalization services — even inside the logged-in area — generally still require consent.
📢 Choosing the legal basis for each logged-in service is a decision for you and your legal team/DPO — AdOpt doesn't decide it for you. What AdOpt provides is the technical foundation for either path: the Authenticated Scanner identifies the logged-in Tags; categorization defines how each one is treated (the strictly necessary ones typically don't require consent, while the rest depend on it); and the pre-login banner collects and records the choice when consent is the basis.
Next steps
Categorize the Tags you find: How to categorize your tags in AdOpt.
Keep your inventory up to date automatically with the Scheduled Scanner guide (coming soon).




