--- name: policystack-init description: Scaffold PolicyStack in a project: run the @policystack/cli installer, then wire the single provider (policy + consent). Use when adding a privacy/cookie policy or a consent banner to a web app. --- # policystack-init Set PolicyStack up in an existing project. PolicyStack generates a privacy policy, a cookie policy, and the consent runtime from **one** typed `defineConfig()` call. It is not legal advice — a lawyer should review the output before publication. ## 1. Run the installer ```sh npx @policystack/cli@latest init ``` `init` detects the package manager and framework from `package.json`, installs `@policystack/sdk` plus the right framework integration, scaffolds a starter `policystack.ts` (`src/policystack.ts` when a `src/` directory exists, else the project root), writes `policystack.llms.txt` next to it, and prints a setup prompt. Useful flags: `--cwd`, `--pm`, `--skip-install`, `--dry-run`, `--yes`, `--out`, `--force`. If `init` cannot run, install by hand: `@policystack/sdk` always, plus `@policystack/vite` and the framework package (`@policystack/react`, …). ## 2. Fill in `policystack.ts` Read the generated `policystack.llms.txt` — it is the type-accurate SDK reference (jurisdiction ids, lawful bases, presets) for this exact version. The canonical, commented reference config is [`examples/tanstack/src/policystack.ts`](https://github.com/jamiedavenport/policystack/blob/v1/examples/tanstack/src/policystack.ts). `jurisdictions` is required and non-empty. Valid ids: `br`, `ca`, `ch`, `eea`, `row`, `uk`, `us`, `us-ak`, `us-al`, `us-ar`, `us-az`, `us-ca`, `us-co`, `us-ct`, `us-de`, `us-fl`, `us-ga`, `us-hi`, `us-ia`, `us-id`, `us-il`, `us-in`, `us-ks`, `us-ky`, `us-la`, `us-ma`, `us-md`, `us-me`, `us-mi`, `us-mn`, `us-mo`, `us-ms`, `us-mt`, `us-nc`, `us-nd`, `us-ne`, `us-nh`, `us-nj`, `us-nm`, `us-nv`, `us-ny`, `us-oh`, `us-ok`, `us-or`, `us-pa`, `us-ri`, `us-sc`, `us-sd`, `us-tn`, `us-tx`, `us-ut`, `us-va`, `us-vt`, `us-wa`, `us-wi`, `us-wv`, `us-wy`. All 50 US states use their ISO `us-` code. Pick the codes that actually apply; `policystack-jurisdiction` explains the posture each implies. ## 3. Wire the provider Wrap the app root **once** with the single provider — it supplies both the policy context and the consent store (derived from the same config): ```tsx import { PolicyStack } from "@policystack/react/provider"; import config from "./policystack"; export function App({ children }: { children: React.ReactNode }) { return {children}; } ``` `` / ``, `useConsent`, and `ConsentGate` all read from it. Components ship unstyled and emit `data-op-*` attributes. For non-React frameworks use that framework's `@policystack/` package. ## 4. Verify Run `policystack-audit` (`policystack validate --json`) and resolve every issue before shipping. Annotate real data flows with `policystack-instrument` so the policy reflects what the code actually does.