---
title: "systhema cookies"
description: "Scan, classify and seed cookies for the consent banner."
url: https://docs.systhema.app/cli/cookies
version: unreleased (main)
docs_index: https://docs.systhema.app/llms.txt
---

Cookie-consent helpers for projects that have the banner enabled. All three are proxied to `systhema-core cookies <sub>`.

```bash
systhema cookies scan              # walk src/**, classify cookies, write .systhema/cookies.discovered.json
systhema cookies seed              # push discovered cookies into the Payload general-settings global (additive)
systhema cookies update-db         # refresh the project-local Open Cookie Database cache
systhema cookies scan --dry-run    # plan only
```

`scan` and `seed` together replace the manual cookie audit that GDPR-compliant sites usually do once a quarter. `seed` is additive — editor-curated entries in admin are never touched. For cookies set by third-party scripts at runtime that the static scanner can't see (chat widgets, ad networks, embeds), pair with the [`systhema:discovering-runtime-cookies`](https://docs.systhema.app/cli/skills.md) skill.

Cookie-consent helpers. Run inside a project that has `cookieConsent` configured in `systhema.config.ts`.

## Subcommands

- `scan` — walks `src/**/*.{ts,tsx,js,jsx}` (configurable via `cookieConsent.scanner.include`), looks each cookie up in the bundled [Open Cookie Database](https://github.com/jkwakman/Open-Cookie-Database) snapshot, classifies it into one of the five Systhema categories (`necessary`, `functional`, `analytics`, `performance`, `advertisement`), and writes the result to `.systhema/cookies.discovered.json`. Idempotent — safe to re-run. Pass `--dry-run` to plan without writing.
- `seed` — reads `.systhema/cookies.discovered.json` and pushes new entries into the Payload `general-settings` global. **Additive only**: editor-curated entries in admin are never modified, even if the OCDB classification changes. Requires `@systhemaui/payload` installed and a Payload config at the project root (override with `--payload-config <path>`).
- `update-db` — fetches the latest OCDB snapshot from upstream and caches it at `.systhema/cache/open-cookie-database.json`. The scanner uses the cache when present; otherwise it falls back to the version bundled with `@systhemaui/core`.

## Options

<!-- generated:cli-flags cookies -->

### systhema cookies scan

| Flag               | Description                      | Default |
| ------------------ | -------------------------------- | ------- |
| `--config <value>` | Path to a Systhema config.       |         |
| `--db <value>`     | Open Cookie Database URL.        |         |
| `--dry-run`        | Preview changes without writing. | `false` |

### systhema cookies update-db

| Flag            | Description                        | Default                                                                                            |
| --------------- | ---------------------------------- | -------------------------------------------------------------------------------------------------- |
| `--url <value>` | Open Cookie Database download URL. | `https://raw.githubusercontent.com/jkwakman/Open-Cookie-Database/master/open-cookie-database.json` |

### systhema cookies seed

| Flag                       | Description                      | Default |
| -------------------------- | -------------------------------- | ------- |
| `--dry-run`                | Preview changes without writing. | `false` |
| `--payload-config <value>` | Path to the Payload config.      |         |

<!-- /generated -->

See [Cookie scanner](https://docs.systhema.app/guides/cookie-consent/scanner.md) for details on classification, OCDB freshness, and the auth/session whitelist.

For runtime cookies the static scanner can't see (third-party scripts, ad networks, embeds), pair with the `systhema:discovering-runtime-cookies` skill — see [Agent skills](https://docs.systhema.app/cli/skills.md).
