Installation

Aurora collects behavior through a single asynchronous script. This page covers every supported install method, how to verify it, and the configuration options for single-page apps, Content Security Policy and multi-domain sites.

5 min read Updated Aug 19, 2026
On this page
  1. Choose an install method
  2. Direct snippet
  3. What the snippet does
  4. Framework examples
  5. Google Tag Manager
  6. Segment
  7. Verify the installation
  8. Configuration options
  9. Single-page applications
  10. Content Security Policy
  11. Cross-domain and subdomain tracking
  12. Excluding internal traffic

Choose an install method#

All three methods load the same tracker and produce identical data. Pick the one that matches how your team already ships changes to the site.

MethodBest forNeeds a deploy?Backfill
Direct snippetSites where you control the HTML templatesYes, onceFrom install onward
Google Tag ManagerMarketing-owned sites already running GTMNo — publish in GTM30 days, if GA4 is linked
SegmentTeams already sending events through SegmentNo — enable a destination30 days of Segment history

Direct snippet#

Copy the snippet from Settings → Tracking and paste it immediately before </body> in the layout shared by every page. The first <script> block creates a small command queue so calls such as aurora('identify', …) made before the tracker finishes loading are never lost.

HTML
="t-c"><!-- Aurora tracking snippet — paste once, right before </body> -->
<script>
  window.aurora = window.aurora || function () {
    (window.aurora.q = window.aurora.q || []).push(arguments);
  };
</script>
<script async src="https://cdn.aurora.io/v2/aurora.js"
        data-workspace="pk_live_YOUR_WORKSPACE_KEY"></script>

What the snippet does#

  • Sets one first-party cookie, aur_vid, to recognize the visitor across sessions. No third-party cookies are read or written.
  • Records the page URL, title, referrer, UTM parameters, viewport size, language and a coarse device and browser category.
  • Sends events with navigator.sendBeacon where available, so tracking never delays navigation or page unload.
  • Does not record keystrokes, form field contents, mouse movement or session video. Form data is only captured for forms you explicitly connect.

Framework examples#

In frameworks with a shared document or layout component, add the snippet there. For Next.js with the App Router, use the built-in Script component in your root layout:

app/layout.jsx
import Script from "next/script";

export default function RootLayout({ children }) {
  return (
    <html lang="en">
      <body>
        {children}
        <Script id="aurora-queue" strategy="afterInteractive">
          {`window.aurora=window.aurora||function(){(window.aurora.q=window.aurora.q||[]).push(arguments)}`}
        </Script>
        <Script src="https://cdn.aurora.io/v2/aurora.js"
                data-workspace={process.env.NEXT_PUBLIC_AURORA_KEY}
                strategy="afterInteractive" />
      </body>
    </html>
  );
}

For WordPress, paste the snippet into your theme's footer through a header-and-footer plugin, or add it to footer.php just before wp_footer(). For Webflow, use Project settings → Custom code → Footer code.

Google Tag Manager#

  1. Add the templateIn your GTM container, go to Templates → Search gallery, find Aurora Tracker and choose Add to workspace.
  2. Create the tagCreate a new tag from the template and paste your public workspace key (pk_live_…).
  3. Set the triggerUse the built-in All Pages trigger. For single-page apps, also add a History Change trigger — see Single-page applications.
  4. Preview and publishUse GTM's Preview mode to confirm the tag fires once per page, then publish the container version.

If your GTM container waits for a consent management platform, map the Aurora tag to your analytics consent category. See Consent and cookies.

Segment#

In Segment, open Connections → Destinations → Add destination, search for Aurora, choose your website source and paste your public workspace key. Segment's page, identify and track calls map directly to Aurora's methods, so there's nothing else to install.

After you enable the destination, Aurora requests the last 30 days of events for that source through Segment's replay API. Depending on volume, the backfill completes within a few minutes to an hour; progress is shown in Settings → Tracking.

Verify the installation#

Open your site in a normal browser window (not one with an ad blocker) and load a few pages. Then check any of the following:

  • Dashboard: Settings → Tracking shows a green status and your page views in the Live events panel.
  • Browser console: run aurora('debug', true) and reload. Every event the tracker sends is logged with its payload.
  • Network tab: filter for collect.aurora.io. Each page view produces one request with status 204.

Configuration options#

Options are set with data- attributes on the script tag or with aurora('config', {…}) before the first page view.

AttributeDefaultDescription
data-workspace—Required. Your public workspace key.
data-auto-pagetrueSend a page view automatically on load. Set to false to call aurora('page') yourself.
data-spafalseListen for History API changes and send a page view on each route change.
data-includeall pathsComma-separated path prefixes to track, for example /pricing,/docs.
data-excludenoneComma-separated path prefixes to ignore, for example /admin,/checkout.
data-cookie-domaincurrent hostSet to your root domain (for example .example.com) to share identity across subdomains.
data-consentgrantedSet to pending to wait for an explicit aurora('consent', 'granted') call.
data-regionworkspace defaulteu or us. Only needed when self-hosting the script.

Single-page applications#

In React, Vue, Svelte or Angular apps, route changes don't reload the page, so the tracker can't see them automatically. Either add data-spa="true" to the script tag, or call aurora('page') from your router after each navigation:

JavaScript
// Vue Router
router.afterEach((to) => {
  aurora("page", { path: to.fullPath, title: document.title });
});

Don't use both approaches at once — each route change would be counted twice.

Content Security Policy#

If your site sends a Content-Security-Policy header, allow the tracker's script and collection endpoints:

HTTP
Content-Security-Policy:
  script-src  'self' https://cdn.aurora.io;
  connect-src 'self' https://collect.aurora.io https://collect.eu.aurora.io;

The inline queue stub needs either 'unsafe-inline' or a nonce. To avoid inline script entirely, move the stub into your own bundled JavaScript file.

Cross-domain and subdomain tracking#

To follow one visitor from www.example.com to app.example.com, set data-cookie-domain=".example.com" on both. For separate domains (for example a marketing site and a docs site on different domains), add both under Settings → Tracking → Domains; Aurora appends a short-lived _aur parameter to links between them so the identity carries over.

Excluding internal traffic#

Your own team's visits inflate scores. Exclude them under Settings → Tracking → Filters by IP range, by email domain for identified visitors, or by a cookie your admin tools set. Excluded traffic is dropped at collection time and never counts toward any score.

Last updated Aug 19, 2026 Report an issue with this page

Ready to try it on your own site?

Install the snippet in five minutes and see your first scored visitors today. Starter is free forever for one seat.

No credit card required · Setup help from real engineers