What is a Permissions-Policy header?
Allows or disables the use of browser features and APIs (camera, geolocation, etc.) in the page and its iframes.
Permissions-Policy (the successor to the older Feature-Policy header) lets a website explicitly control which powerful browser APIs - camera, microphone, geolocation, and more - the page and any embedded iframes are allowed to use. It's a genuinely useful defence-in-depth tool: even if a third-party script embedded on the page gets compromised, a tight Permissions-Policy can stop it from ever accessing the camera or location data in the first place.
Common use case
A site embedding third-party ad iframes sets Permissions-Policy to block those iframes from ever requesting camera or microphone access, regardless of what the ad script itself tries to do.
Example
Permissions-Policy: camera=(), microphone=(), geolocation=(self)History
Standardised as the direct successor to the earlier Feature-Policy header, formalised by the W3C starting around 2020.
Deprecated / legacy status
Replaced Feature-Policy, which is itself now deprecated - browsers still accept Feature-Policy for backwards compatibility, but new implementations should use Permissions-Policy going forward.
Did you know?
Its syntax deliberately borrowed heavily from Content-Security-Policy's allowlist style, making the two headers feel like a consistent family even though they were standardised through somewhat different processes.