← All headersResponse header

What is a Permissions-Policy header?

Allows or disables the use of browser features and APIs (camera, geolocation, etc.) in the page and its iframes.

Permissions-Policy (the successor to the older Feature-Policy header) lets a website explicitly control which powerful browser APIs - camera, microphone, geolocation, and more - the page and any embedded iframes are allowed to use. It's a genuinely useful defence-in-depth tool: even if a third-party script embedded on the page gets compromised, a tight Permissions-Policy can stop it from ever accessing the camera or location data in the first place.

Common use case

A site embedding third-party ad iframes sets Permissions-Policy to block those iframes from ever requesting camera or microphone access, regardless of what the ad script itself tries to do.

Example

Permissions-Policy: camera=(), microphone=(), geolocation=(self)

History

Standardised as the direct successor to the earlier Feature-Policy header, formalised by the W3C starting around 2020.

Deprecated / legacy status

Replaced Feature-Policy, which is itself now deprecated - browsers still accept Feature-Policy for backwards compatibility, but new implementations should use Permissions-Policy going forward.

Did you know?

Its syntax deliberately borrowed heavily from Content-Security-Policy's allowlist style, making the two headers feel like a consistent family even though they were standardised through somewhat different processes.