In this post
Every “five-minute install” claim deserves skepticism from whoever actually has to approve the change. So here is what the Aurora snippet does, line by line, before it goes anywhere near your production site.
The snippet, line by line#
<script>
window.aurora = window.aurora || function () {
(window.aurora.q = window.aurora.q || []).push(arguments);
};
</script>
<script async src="https://cdn.aurora.io/v2/aurora.js"
data-workspace="pk_live_YOUR_WORKSPACE_KEY"></script>- Lines 2–4 define a tiny queue. Any
aurora(…)calls made before the real script loads — anidentifyafter login, a customtrackevent — are stored and replayed later, so your code never waits for the tracker. - Line 6 loads the tracker asynchronously from our CDN.
asyncmeans the browser keeps parsing and rendering your page while the script downloads, and runs it whenever it's ready. - Line 7 identifies your workspace with its public key. A
pk_live_key can only send events; it can't read any data, so it's safe to ship in page source. Secretsk_live_keys are for server-side API calls only.
Place it once, just before the closing </body> tag, or deploy it through Google Tag Manager. The installation guide covers every framework we support.
What it collects#
On each page view, the tracker records:
- The page URL, title and referrer.
- Active time on page — time the tab was visible and focused, not just open.
- Coarse device information: browser, operating system and screen size class.
- A first-party visitor ID in the
aur_vidcookie, valid for 13 months, used to connect sessions from the same browser.
IP addresses are used once, at ingestion, to resolve the company and approximate country. They're then truncated and never stored in full.
What it never does#
- It doesn't read form fields. Visitors are only identified when you explicitly call
aurora("identify", …)with values you choose. - It doesn't record keystrokes, mouse movement or session replays.
- It doesn't set third-party cookies, load ad pixels or share data with anyone else.
- It doesn't fingerprint browsers to get around cookie consent.
If you need consent before tracking, add data-consent="pending" to the script tag. The tracker loads but sends nothing and sets no cookie until you call aurora('consent', 'granted'). See Data & privacy.
Performance budget#
The tracker has a hard budget that is enforced in CI: 8 KB gzipped, and no pull request that grows it gets merged without removing something else. It has no dependencies.
| Metric | Budget | Measured (p75) |
|---|---|---|
| Script size (gzip) | ≤ 8 KB | 7.6 KB |
| Main-thread time on load | ≤ 5 ms | 2.1 ms |
| Network requests per page view | 1 | 1 |
| Impact on LCP / CLS | None | Not measurable |
Events are sent with navigator.sendBeacon where available, so they never delay navigation, and are batched when several happen within a second.
Failure modes#
The most important property of a tracking script is what happens when it breaks. Because Aurora loads asynchronously and nothing on your page depends on it, every failure is silent and harmless:
- CDN unreachable or blocked by an ad blocker: the script never runs; queued calls are simply discarded.
- Collection endpoint down: events are retried briefly from memory and then dropped. Your page is unaffected.
- JavaScript error inside the tracker: all tracker code runs inside a try/catch boundary and never throws into your page.
If you use a Content Security Policy, allow https://cdn.aurora.io in script-src, and https://collect.aurora.io (plus https://collect.eu.aurora.io for EU workspaces) in connect-src.
Verifying the install#
Open your site, then open Settings → Tracking in Aurora. Your visit should appear under Live events within a few seconds. If it doesn't, the troubleshooting guide walks through the usual causes — most often a CSP rule or a tag-manager trigger that never fires.