---
title: "Version 3.0.0"
url: "https://cookiezest.com/changelog/v3.0.0"
description: "Third-party iframe gating by default, Clarity blocked in safe mode, runtime version and embed API."
---

Zest 3.0 gates third-party embeds before consent. This changes what loads on existing sites, so check your iframes before upgrading from 2.x.

## Breaking changes

-   **Third-party iframe gating is on by default.** Known YouTube, Vimeo, social, music, and video embeds are blocked until their consent category is allowed. An existing `<iframe src>` is swapped to `about:blank` on the first scan and covered with a consent overlay. Sites that already gate embeds can set `intercept: { embeds: false }` or `data-intercept-embeds="false"` on the Zest script. Pin 2.x if you need time to migrate.
-   **Microsoft Clarity is blocked in safe mode.** Previously it was blocked only in strict mode. If you deliberately load it before consent, use `allowedDomains` or disable the relevant interceptor.

## Added

-   **Zero-request embed markup:** set `data-consent-src` instead of `src` on an iframe, optionally with `data-consent-category="marketing"`. The URL never reaches the DOM until consent or a one-time load. [See embed gating](/docs/script-blocking/#embed-gating).
-   **One-time load:** the overlay’s “Load content” button activates a single iframe without storing consent. `Zest.activateEmbed(elementOrIndex)` does the same in both full and headless builds; headless consumers can render their own overlay.
-   **Privacy rewrite:** activated YouTube embed URLs use `youtube-nocookie.com`; Vimeo players get `dnt=1`. Set `privacyRewrite: false` or `data-privacy-rewrite="false"` to opt out.
-   **`zest:embed` event:** `{ phase: 'blocked' | 'activated', element, category, url }` for custom embed interfaces. Overlay text is localized in all 12 languages and customizable via `labels.embed`.
-   **`Zest.version`:** reports the running bundle’s version in full and headless builds.

## Changed

`acceptAll()`, `rejectAll()`, and `updateConsent()` now return `{ current, previous }`, or `null` before initialization, on the full build as they already did in headless. Callers ignoring their return values need no changes.

The full-build TypeScript declarations now include `updateConsent()` and `resolveGeo()` and no longer advertise `showWidget()` / `hideWidget()`, which were never public runtime methods.

```
<script src="https://cdn.jsdelivr.net/npm/@freshjuice/zest@3.0.0/dist/zest.min.js"></script>
```