CLItrail Docs

Add CLItrail to Astro

Where the CLItrail tag goes in Astro, in its own idiom, with the consent, CSP and client-side routing details and how to check it works.

Written for Astro 7 (the same code works in 4 to 6)

#Where the tag goes

Edit src/layouts/Layout.astro (the layout every page uses). Put the tag on every page that shows your install command; site-wide is best, after your existing analytics tags.

---
const { title } = Astro.props;
---
<html lang="en">
  <head>
    <meta charset="utf-8" />
    <title>{title}</title>
    <script is:inline defer src="https://YOUR_SERVICE/browser.js" data-website="YOUR_WEBSITE_ID"></script>
  </head>
  <body>
    <slot />
  </body>
</html>

Use the loader in place of the tag: nothing from CLItrail loads until startClitrail() runs. Load the loader before your consent manager's script and call startClitrail() from the manager's accept callback (most managers also run it on later visits once a choice is stored; check yours). Use the marketing category when installs go to Google Ads, Meta, TikTok or X Ads, and the analytics category when they only reach GA4 or your webhooks.

Consent loader

// Loads CLItrail only after the visitor agrees. Call startClitrail() from your
// consent manager's "accepted" callback; nothing is fetched or stored before that.
window.startClitrail = () => {
  if (document.getElementById('clitrail')) return;
  const tag = document.createElement('script');
  tag.id = 'clitrail';
  tag.src = 'https://YOUR_SERVICE/browser.js';
  tag.dataset.website = 'YOUR_WEBSITE_ID';
  document.head.append(tag);
};
<script is:inline defer src="/clitrail-consent.js"></script>

#Client-side routing

Without <ClientRouter /> every page loads in full and the tag is enough. With it, pages change without a reload: astro:page-load fires on the first load and after every navigation. A head script that is on both pages stays and does not run again.

Route helper

// Records a visit when client-side navigation opens a new page path. The tag records
// the page the browser loaded, so that page is never recorded twice; before the SDK has
// started (for example, before consent) it records nothing.
declare global {
  interface Window {
    InstallAttribution?: { init(options: { service: string; project: string }): Promise<unknown>; ready?: Promise<unknown> };
  }
}

let recorded: string | undefined;

export function recordVisit(): void {
  if (typeof window === 'undefined') return;
  recorded ??= new URL(performance.getEntriesByType('navigation')[0]?.name ?? location.href).pathname;
  const sdk = window.InstallAttribution;
  if (!sdk?.ready || location.pathname === recorded) return;
  recorded = location.pathname;
  sdk.ready = sdk.init({ service: 'https://YOUR_SERVICE', project: 'YOUR_WEBSITE_ID' });
}
<script>
  import { recordVisit } from '../lib/clitrail';

  document.addEventListener('astro:page-load', recordVisit);
</script>

#Content Security Policy

Your host's headers or a <meta http-equiv> in the layout (if you use Astro's own CSP option, add the origin to its script and connect sources): add https://YOUR_SERVICE to script-src and connect-src, and blob: to worker-src (only Safari before 26 needs that one).

script-src 'self' https://YOUR_SERVICE;
connect-src 'self' https://YOUR_SERVICE;
worker-src 'self' blob:;

#Verify it works

  1. Run npm run dev (http://localhost:4321) or deploy.
  2. Open a page with the tag in Chrome or Firefox (accept analytics first if you gate CLItrail on consent), open the developer console and run await InstallAttribution.ready. It resolves to { ok: true, urlId, hasAnalyticsContext, expiresAt }.
  3. In the CLItrail dashboard, open Visits & identities: the visit is listed.
  4. Anything else names the cause: disabled (no consent yet, or data-enabled="false"), opfs_unavailable (the page is not served over https or from localhost), Error (the service refused the visit: add the page's origin, including a development origin such as http://localhost:3000, under Settings → Additional domains). If InstallAttribution is undefined, the tag did not load: check the Network tab and your Content-Security-Policy.

Then run your installer on the same computer and check Install events, or run the hook with --doctor.

#Notes

  • is:inline keeps Astro from processing the tag, so it stays a plain <script src> with its data-website attribute. Astro also leaves alone any script with an attribute other than src; is:inline makes that explicit.
  • The route script is processed and bundled by Astro, so it runs once and keeps listening.

Astro documentation: docs.astro.build/en/guides/client-side-scripts

Using other install paths or destinations? The setup generator puts this snippet together with your hooks and destination checklist.