Both options promise first-party tracking, and both come from the same part of Google's toolkit, so they're easy to confuse. They solve different problems.

Google tag gateway changes where Google's tags load from. Server-side Google Tag Manager changes where your data goes, and lets you decide what happens to it on the way. This guide explains each, compares them side by side, and ends with a plain way to decide.

What Google tag gateway is.

Google tag gateway (sometimes called Google tag gateway for advertisers, and discussed earlier under the name "first-party mode") launched in 2025. It lets your site serve Google's tags, the gtag.js library or your GTM container, from a path on your own domain instead of from Google's domains.

The measurement requests those tags send also go through your domain. Your CDN or load balancer passes them on to Google behind the scenes. From the browser's point of view, everything is first-party.

You set it up in the infrastructure in front of your site, not in a separate server. Cloudflare offers it as a simple setting. Google Cloud supports it through its load balancer, Akamai has announced support, and other CDNs can be configured to do the same job. There's no server container to build, host or patch.

What the gateway does and doesn't do.

What it gives you:

  • First-party serving. Requests to your own domain are less likely to be blocked by some ad blockers and browser privacy features that target Google's domains, so more consented data reaches GA4 and Google Ads.
  • Little upkeep. Once the CDN setting is on and tested, there's not much to look after.

What it doesn't do:

  • No control over the data. Requests pass through unchanged. You can't remove fields, hash personal data, add first-party data or filter events before they reach Google.
  • Google tags only. It covers GA4, Google Ads and Floodlight tags. The Meta pixel, TikTok, LinkedIn and other vendors still load from their own domains.
  • No change to consent. Your banner and Consent Mode still decide whether tags run and what they send.

What server-side GTM is.

Server-side Google Tag Manager adds a second container that runs on a server rather than in the browser. It's usually hosted on Google Cloud Run or with a managed host that specialises in it, and reached through a subdomain of your site.

The browser sends events to that server. The server container then forwards them to GA4, Google Ads, the Meta Conversions API and other platforms, each through its own tag.

Because the data passes through a container you control, you can change it on the way:

  • Strip or hash personal data before any vendor sees it.
  • Add first-party data, such as margin or customer status, from your own systems.
  • Send one stream of events to many vendors, instead of loading each vendor's script in the page.
  • Set cookies from your server rather than from a script, which browsers generally treat more kindly.

The trade-off is cost and care. There's a setup project, a monthly hosting bill from the provider that grows with traffic, and a container that needs monitoring and updating like any other system. A badly configured server container can drop or double-count key events without anyone noticing.

Side by side.

QuestionGoogle tag gatewayServer-side GTM
Where it runsYour CDN or load balancerA server container you host, or a managed host runs for you
Which platformsGoogle tags onlyGoogle, Meta, TikTok and others, through server tags
First-party requestsYesYes, through your own subdomain
Change or filter dataNoYes
Add first-party dataNoYes
Setup effortLow, often a setting plus testingA proper project: container, hosting, DNS, tags and testing
Running costDepends on your CDN planHosting billed monthly, rising with traffic
UpkeepMinimalOngoing monitoring and updates
Replaces consentNoNo

Which do you need.

Google tag gateway

Choose it if: you only use Google tags (GA4, Google Ads, perhaps Floodlight), your site already sits behind a supported CDN, and you want better data collection without a new system to run. For many small and mid-sized sites that's the whole requirement.

It won't help if: your main measurement problem is Meta or TikTok under-reporting, you need to control what personal data leaves your site, or your tracking is already broken. Moving a broken tag to your own domain just gives you broken data more reliably.

Server-side GTM

Choose it if: you send conversions to platforms outside Google, particularly the Meta Conversions API; you want to enrich events with data from your own systems; you want one stream feeding several vendors; or you work under privacy requirements about exactly what leaves your infrastructure.

It won't help if: nobody on the team is comfortable with GTM, the hosting cost doesn't make sense at your traffic, or basic GA4 tracking isn't working yet. Fix the basics first.

Both

They aren't mutually exclusive. Server-side GTM on your own subdomain already gives first-party collection, but some setups combine them, for example using first-party serving for Google's tags alongside a server container that handles other vendors. If you're considering this, map out which requests go where before building anything, so the same event isn't sent twice.

Both options make consented measurement more reliable. Neither changes what you're allowed to collect. If a visitor declines, tags should respect that whether they load from Google's domain, your CDN or your server.

Consent Mode v2 still needs to be set up and tested either way. The Consent Mode v2 testing guide shows how to check it's working, and it's worth doing before and after any change like this.

How to check what you have now.

Before choosing, find out what your site currently does.

How to diagnose it: open your site in Chrome, open developer tools and go to the Network tab. Accept cookies, reload, and filter for collect. Look at the domain each GA4 request goes to.

  • If requests go to a Google domain, you're using standard client-side tags.
  • If they go to a path on your main domain, a tag gateway or similar first-party serving is already in place.
  • If they go to a subdomain of yours, such as one set up for tracking, you probably have a server container.

Then list every platform you send conversions to. If the list is only Google products, the gateway is the obvious first step. If it includes Meta or others, weigh up server-side GTM.

Setting up the gateway safely.

How to fix it: treat the switch like any other tracking change.

  1. Check that GA4 and Google Ads tracking are correct before you start, including key events and consent.
  2. Turn on the gateway in your CDN, following Google's and your provider's current instructions, and confirm your tags load from your own domain.
  3. Walk through key journeys in DebugView and GTM Preview, checking every key event still fires exactly once.
  4. Test consent again: decline, then check that no tags send data they shouldn't.
  5. Compare GA4 and Google Ads figures for the weeks before and after, so you can see what changed.

If you go server-side instead, the server-side GTM service page explains what a full build involves, from hosting to switching off the old tags.

Summary.

Google tag gateway is the lightweight option: first-party serving for Google's tags, set up at the CDN, with almost nothing to maintain. Server-side GTM is the heavier one: a container you host that gives you control over the data and reaches platforms beyond Google.

Neither fixes broken tracking or replaces consent. Get the basics right, then pick the one that matches the platforms you use and the control you need.

If you'd rather have your current setup checked before deciding, the GA4 mini audit covers your tags, key events and consent, and shows which of these options makes sense for your site.