The five-minute install, annotated

A line-by-line walkthrough of the Aurora tracking snippet for the engineer who has to approve it: what it loads, what it collects, what it never touches and how it fails safely.

In this post
  1. The snippet, line by line
  2. What it collects
  3. What it never does
  4. Performance budget
  5. Failure modes
  6. Verifying the install

Every “five-minute install” claim deserves skepticism from whoever actually has to approve the change. So here is what the Aurora snippet does, line by line, before it goes anywhere near your production site.

The snippet, line by line#

HTML
<script>
  window.aurora = window.aurora || function () {
    (window.aurora.q = window.aurora.q || []).push(arguments);
  };
</script>
<script async src="https://cdn.aurora.io/v2/aurora.js"
        data-workspace="pk_live_YOUR_WORKSPACE_KEY"></script>
  • Lines 2–4 define a tiny queue. Any aurora(…) calls made before the real script loads — an identify after login, a custom track event — are stored and replayed later, so your code never waits for the tracker.
  • Line 6 loads the tracker asynchronously from our CDN. async means the browser keeps parsing and rendering your page while the script downloads, and runs it whenever it's ready.
  • Line 7 identifies your workspace with its public key. A pk_live_ key can only send events; it can't read any data, so it's safe to ship in page source. Secret sk_live_ keys are for server-side API calls only.

Place it once, just before the closing </body> tag, or deploy it through Google Tag Manager. The installation guide covers every framework we support.

What it collects#

On each page view, the tracker records:

  • The page URL, title and referrer.
  • Active time on page — time the tab was visible and focused, not just open.
  • Coarse device information: browser, operating system and screen size class.
  • A first-party visitor ID in the aur_vid cookie, valid for 13 months, used to connect sessions from the same browser.

IP addresses are used once, at ingestion, to resolve the company and approximate country. They're then truncated and never stored in full.

What it never does#

  • It doesn't read form fields. Visitors are only identified when you explicitly call aurora("identify", …) with values you choose.
  • It doesn't record keystrokes, mouse movement or session replays.
  • It doesn't set third-party cookies, load ad pixels or share data with anyone else.
  • It doesn't fingerprint browsers to get around cookie consent.

If you need consent before tracking, add data-consent="pending" to the script tag. The tracker loads but sends nothing and sets no cookie until you call aurora('consent', 'granted'). See Data & privacy.

Performance budget#

The tracker has a hard budget that is enforced in CI: 8 KB gzipped, and no pull request that grows it gets merged without removing something else. It has no dependencies.

MetricBudgetMeasured (p75)
Script size (gzip)≤ 8 KB7.6 KB
Main-thread time on load≤ 5 ms2.1 ms
Network requests per page view11
Impact on LCP / CLSNoneNot measurable

Events are sent with navigator.sendBeacon where available, so they never delay navigation, and are batched when several happen within a second.

Failure modes#

The most important property of a tracking script is what happens when it breaks. Because Aurora loads asynchronously and nothing on your page depends on it, every failure is silent and harmless:

  • CDN unreachable or blocked by an ad blocker: the script never runs; queued calls are simply discarded.
  • Collection endpoint down: events are retried briefly from memory and then dropped. Your page is unaffected.
  • JavaScript error inside the tracker: all tracker code runs inside a try/catch boundary and never throws into your page.

If you use a Content Security Policy, allow https://cdn.aurora.io in script-src, and https://collect.aurora.io (plus https://collect.eu.aurora.io for EU workspaces) in connect-src.

Verifying the install#

Open your site, then open Settings → Tracking in Aurora. Your visit should appear under Live events within a few seconds. If it doesn't, the troubleshooting guide walks through the usual causes — most often a CSP rule or a tag-manager trigger that never fires.

Naomi Ilić

Naomi owns the Aurora browser tracker and the collection pipeline behind it, and has a standing rule that the script is never allowed to get bigger.

Newsletter

Enjoyed this post?

Get the next one in your inbox. One email every two weeks, no sales follow-up, unsubscribe in one click.

Read by 6,000+ sales and RevOps people. We never share your address.

Put these ideas to work.

Aurora scores every visitor in real time and routes the ready ones to the right rep. Free forever for one seat.

No credit card required · Live in five minutes