What stape.io takes over
A server-side GTM container is a Node process that accepts requests, processes events and forwards them. Someone has to run it. Provisioning, SSL, scaling under load spikes, container updates when Google ships a new version, monitoring so an outage doesn't surface in the weekly report.
That list is what you buy from stape. What remains is the work nobody can automate anyway: event design, consent mapping, PII rules, QA.
Why server-side is the 2026 default at all is covered in the server-side tracking guide. This is about the product itself.
How we scored it
Four axes, the same ones every tool in our catalogue gets. No tool scores fives across the board here, because that reads as advertising to readers and to Google alike.
EU data sovereignty 4.0. The EU region and a data processing agreement are in place. The container still runs at the vendor, not at you. That is the one thing a self-run Cloud Run container does better.
Data quality 4.5. The first-party endpoint is the real technical win. Events survive ITP and common blocklists far more reliably than the client-side path, and cookie lifetime goes from seven days to up to 400.
Value for money 4.5. Measured against the alternative, not against the list price. $83 a month for 5M requests undercuts any calculation that includes half a DevOps role.
Ease of use 5.0. Create a container, connect a subdomain, paste the GTM container ID. Done. Templates for Meta CAPI, TikTok and consent forwarding ship with it.
Pricing 2026
As of 15 August 2026, read directly off stape.io/price. Monthly figures are the annual price divided by twelve; paying monthly costs 20 percent more.
| Plan | Price | Requests / month | What matters |
|---|---|---|---|
| Free | $0 | 10,000 | one container, no card required |
| Pro | $17 / month ($200 / year) | 500,000 | 3-day logs, Cookie Keeper, bot detection |
| Business | $83 / month ($1,000 / year) | 5M | multi-zone, 10-day logs, up to 20 domains |
| Enterprise | $167 / month ($2,000 / year) | 20M | account manager, up to 50 domains, S3/GCS export |
| Custom | on request | unlimited | own DPA, HIPAA BAA, dedicated IP, private cluster |
The column everything hinges on is the third. Billing counts server requests, not sessions, users or conversions. One page view easily triggers five to ten requests: page_view, scroll events, a view_item, the consent update ping, the forward to Meta CAPI. Bots count too, unless detection filters them first. So do prefetches.
Anyone sizing a plan from GA4 sessions lands one tier too low, reliably. Use the event volume from your blueprint instead.
What does server-side hosting cost in 2026?
Move the slider, the recommendation updates live. Stape tiers are the publicly known 2026 plans; the GCP estimate combines Cloud Run compute with a min-instance so no event is lost to cold-starts.
€50/ per month
Pro
€28/ per month
baseline + 3.00 per million
Recommendation
GCP Cloud Run
Above ~5M requests/month GCP Cloud Run is mathematically cheaper. If you need data sovereignty (own cloud tenant), the switch happens earlier.
Pure compute comparison. Stape also ships managed updates, EU DPA, tag templates and support, that feeds into TCO, not just the server bill.
What holds up in production
Time to the first clean event. A container exists in minutes, the first-party subdomain hangs off one DNS record. The difference to a self-built Cloud Run setup isn't the technology, it's the days between the decision and tracking that actually works.
Cookie Keeper. Sets cookies server-side as HttpOnly, so Safari stops binning them after seven days. For cross-session recognition that is the difference between "works" and "works everywhere except Safari".
The templates. Meta CAPI, TikTok Events API, Snapchat, consent forwarding, GEO headers. All there, none of it custom code. What is an afternoon on a self-built server is a form here.
Support that knows the subject. Answers come from people who run sGTM themselves rather than from a ticket script. In this category that is not a given.
Where it hurts
Request billing surprises people. A campaign launches, volume jumps, the plan no longer covers it. Auto-scaling absorbs that technically, the invoice follows. Without monitoring, you find out from accounting.
Three-day logs on Pro. That's tight for debugging. An attribution problem someone reports a week later can no longer be reconstructed. Business fixes it with ten days.
One container per account. Anyone managing many clients manages a matching number of subscriptions. Administration, not a technical problem, but it costs time.
Anything contractual beyond the standard sits in the Custom plan. Your own DPA wording, HIPAA BAA, dedicated IP, private cluster. If procurement hands you hard requirements, you end up in a conversation instead of self-service.
stape.io vs JENTIS vs your own Cloud Run: which fits when?
- If you are under 5M requests and have no DevOps capacity for your own container, then → stape.io. The standard case, and the reason it is our default entry point.
- If compliance requires the tagging server inside your own tenant, then → Cloud Run or your own server. The cost picture changes, and the requirement is still legitimate.
- If you process well beyond 20M requests, then → run the numbers on your own infrastructure. At that size operating cost per request drops below the licence, provided somebody actually operates it.
- If the requirement is data minimisation at field level, meaning pseudonymisation and server-side data retention as a product promise, then → look at JENTIS. Different price bracket, but a compliance concept rather than pure hosting.
- If you run Shopify, then → stape plus a custom pixel, in the order set out in the Shopify guide. The sandbox does things there that no host solves for you.
The full cost comparison against Cloud Run, calculator included, sits in the server-side tracking guide.
Disclosure
stape.io has been our declared server-side tagging partner since 2024 and is listed as such in our imprint. It is also the tool we build most of our server-side projects on. The partner status gives us access to roadmap calls and occasional promo codes for discovery clients, but no commission for referred licences.
So the verdict above is not a neutral lab result. It is the assessment of a team that works with the product daily. That cuts both ways: we know the weak spots better than any review portal, and we have an interest in the product looking good. Which is why the limits above are as detailed as the strengths, and why we recommend Cloud Run and self-hosted servers where they fit better.
What to decide it on
- How many server requests per month? Not sessions. Take the events from your measurement blueprint times expected sessions, then add a margin for bots and consent pings.
- Does the container have to run in your own tenant? Marketing doesn't answer that one, your DPO does. If the answer is yes, stape is out, however well the rest fits.
- How far back must an event stay reconstructable? Three days covers a go-live. For ongoing operation with attribution questions from sales, ten days is the floor.
