# Install

One line, placed before any other script.

The Install tab in the dashboard shows the exact line for your site. It looks like this:

```html
<script src="https://cdn.flatconsent.com/s/YOUR_SITE_ID.js"></script>
```

This line always loads the current version of the banner, so fixes and new legal requirements reach your site within minutes without you changing anything.

The line must load before any other script, because the banner can only hold back trackers that load after it. Put it first in the `<head>`.

## Where it goes

| Platform | Where |
|---|---|
| Webflow | Site settings > Custom code > Head code. Paste it at the very top, then publish. |
| Framer | Site settings > General > Custom code > "Start of head tag". Then publish. |
| WordPress | Install the [Flat Consent plugin](https://wordpress.org/plugins/flat-consent/) (Plugins > Add New, search "Flat Consent"), then paste your site ID in Settings > Flat Consent. It puts the line first in `<head>` and keeps caching plugins from delaying it. Then clear any page cache. |
| Shopify | Online Store > Themes > Edit code > `layout/theme.liquid`, on the first line after `<head>`. Leave Shopify's own privacy banner switched off. |
| Squarespace | Settings > Advanced > Code injection > Header, at the top. |
| Wix | Settings > Custom code > Add code to Head, set to load once on all pages. |
| Anything else | The template that renders `<head>`, above every other script tag. |

## Pinning a version

If your security policy requires a file that never changes (for example, so you can use Subresource Integrity), load a pinned version instead:

```html
<script src="https://cdn.flatconsent.com/v/0.3.16/cmp.js" data-site="YOUR_SITE_ID"></script>
```

A pinned file stays exactly as it is, so you have to change the version number yourself to get fixes.

## Check it's working

Press **Check my site** on the Install tab. We load your site in a real browser and report on each of these:

- **The line is on your site.** If we can't find it, check that you published the change.
- **It loads before your other scripts**, so nothing can slip past it.
- **The banner is running.** If the line is on the page but not running, a Content Security Policy may be blocking it; see [Troubleshooting](/docs/troubleshooting).
- **Google tags wait for consent**: our line runs before Tag Manager or gtag.
- **Another cookie banner is still installed.** Remove it so visitors see one banner, not two.
- **No "Cookie settings" link in your footer yet.** Add one as shown below. We only mention this when the floating button is off.

## Footer link

Add a "Cookie settings" link to your footer so visitors can change their mind from any page:

```html
<a href="#" data-cmp="settings">Cookie settings</a>
```

When your page has this link, the floating button stays hidden. See [Footer link](/docs/footer-link).
