Cookiebees
1Capture: Every visit, on your own domain

Server GTM hosting

Your Tag Manager server container,
run on your own domain.

Paste one value from Google Tag Manager. About a minute later your server container answers on your tracking subdomain, under private names that are yours alone. No Google Cloud project, no second hosting service, and the Tag Manager you already use.

30-day free trialNo card requiredSet up in minutes

Can I run my server container without Stape or Cloud Run?

Why do my GA4 hits get blocked even with a server container?

Server container · track.yourstore.comstarting

Starting. This takes about a minute.

Server container GTM-XXXX · preview mode answering

https://track.yourstore.com

Where each request goes

Cookiebees tag and its eventsCookiebees
Tag Manager scriptYour container
Google tag libraryYour container
Hits from your tagsYour container
Tags not using itGoogle, directly
Google's own image, run on your subdomain. We keep it answering and update it every week.

Which tag ids does my server container need to allow?

How many visits come from ChatGPT and other AI assistants?

What it is worth

One vendor for tracking and your server container

No Cloud Run, no second host

Your container runs on the subdomain you already point at Cookiebees. No Google Cloud project to set up, no other tagging host to sign up with.

Hits that keep arriving

Tag Manager loads with no gtm.js and no GTM- id in the address, and hits go to private paths with the query encoded.

Your Tag Manager, untouched

Tags, triggers and clients stay yours. We keep the container running, restart it when it stops answering, and update it to Google’s current image every week.

Private names

The address a blocker looks for is not the address your site uses.

Your site loads Tag Manager under a private script name instead of /gtm.js?id=GTM-. A short helper added to that script moves the Google tag library and the hits onto private paths, with the query encoded, but only for requests to your own subdomain. The server turns them back before your container sees anything.

  • Your container receives exactly what Google’s own address would carry
  • Requests your tags send straight to Google are never changed
  • A private name per workspace, so there is no shared pattern to list
  • Debug tab: paste an encoded address and read it, decoded in your browser
track.yourstore.com · one purchasein the browser

The Tag Manager script

/gtm.js?id=GTM-XXXX→
/a8k2mqp.js

No gtm.js and no GTM- id in the address. The server knows which container it means.

Google's address for the hit

/g/collect?v=2&tid=G-XXXXXXX&en=purchase&dl=https%3A%2F%2Fyourstore.com%2Fthank-you

What the browser sends instead

/a8k2mqp/c?d=dj0yJnRpZD1HLVhYWFhYWFgmZW49cHVyY2hhc2UmZGw9aHR0cHMlM0ElMkYlMkZ5b3Vyc3RvcmUuY29tJTJGdGhhbmsteW91

What your server container receives

/g/collect?v=2&tid=G-XXXXXXX&en=purchase&dl=https%3A%2F%2Fyourstore.com%2Fthank-you
Only requests to your own subdomain are renamed. A tag that sends straight to Google is never touched.

AI traffic, as headers

Your tags can tell a ChatGPT visitor from a crawler.

Every request your container gets carries three headers. X-User-AI and X-User-AI-Name mark an AI agent or crawler, known by its user agent, or for ChatGPT’s agent by the Signature-Agent header it signs with. X-User-AI-Referrer marks a person who arrived from ChatGPT, Perplexity, Claude, Gemini and others, read from the referrer or the utm_source.

  • Read them with an ordinary Request Header variable
  • The same names Stape uses, so a container moved here keeps its variables
  • A visitor cannot forge them: a header they send is removed
  • The Requests tab counts AI agents and AI referrals, today and over 14 days
Server container · request headers

A shopper who came from ChatGPT

read from the hit: referrer chatgpt.com

X-User-AI-ReferrerChatGPT

ChatGPT's agent, browsing for someone

it signs its requests: Signature-Agent

X-User-AItrueX-User-AI-NameChatGPT-Agent

A crawler

user agent GPTBot

X-User-AItrueX-User-AI-NameGPTBot

A visitor sending X-User-AI: true by hand

removed before your container sees it

The same header names Stape uses, so a Request Header variable you already built keeps working.

Nothing refused in silence

Every request counted, and every refusal named by its tag id.

The Requests tab shows each kind of request your container answered: the script, the library, the hits, preview mode. When the container refuses one, it says which tag id was refused. Bots probing the address for /.env and /wp-login.php are counted apart, so they never read as your container failing.

  • Tag ids your container must serve: read from your live website container
  • Ids that send straight to Google are listed too, so nobody adds them by mistake
  • Requests per day for 14 days, and the share already on private names
  • Check it from the internet: does your container answer on your address?
Connect Tag Manager · tag ids your container must serve1 refused
GTM-XXXXWebsite containerserved
G-XXXXXXXGoogle tag · sends through your subdomainserved
G-YYYYYYYLinked to it · its settings are asked for hererefused
AW-XXXXXXXGoogle tag · goes to Google directlynothing to add

Add G-YYYYYYY in the server container: Clients, Google Tag Manager: Web Container, then publish.

Read from your live website container each time you check. Nothing to work out by hand.

Server GTM hosting, on your own site.

Start a workspace and watch it work on your next order or lead, or let us walk you through it.

Switching it on

Four steps, most of them in Tag Manager

You need a working tracking subdomain first. It takes one DNS record.

  1. 1

    Pick your subdomain

    The tracking subdomain you already point at Cookiebees, for example track.yourstore.com.

  2. 2

    Paste the Container Config

    From Tag Manager: server container, Admin, Container settings, Manually provision. Save and start.

  3. 3

    Point Tag Manager at it

    Set it as the Server container URL, and add server_container_url to each Google tag that should use it.

  4. 4

    Replace the snippet

    Swap the Tag Manager snippet in your site’s head for the one we give you. On Shopify, the custom pixel line too.

Inside the module

What is inside

One page, Server container, with the tabs in the order you set it up.

Settings

Container Config, the subdomain, your website container id, private names on or off

Connect Tag Manager

The three places to change, each with the value to copy, and a check from the internet

Overview

Requests today, pages that loaded it, hits, and the share on private names

Requests

Where each kind of request goes, refusals by tag id, AI traffic, bots counted apart

Debug on your site

What to look for in the Network tab, and a decoder for encoded requests

Preview mode

Tag Manager’s preview works through your own address too

Open the Requests tab after a day: every kind of request your container answered, and every refusal with the tag id that was refused.

Where this sits

One of the four steps an order goes through.

Every feature reads the same identity. Open any of them; each has its own page.

Bring your server container home

Your container.Your domain. One vendor.

Point a subdomain at Cookiebees, paste your Container Config, and change three settings in Tag Manager. We keep it running from there.