Security · browser capabilities

Permissions policy.

Build an allowlist for browser features, then validate the exact header value you plan to send. Everything runs locally; no policy text leaves this browser.

MDN + W3C reviewed 29 September 2026HTTP response header · not a security audit

Advertisement

Generate a header

ScopeEach row becomes one feature directive.

Use none to generate (). For delegated origins, use self "https://maps.example". Keep origins scheme-qualified.

Generated header

Generate a header to see the result.

The validator will flag duplicate features, malformed origins, and unsupported schemes.

Validate an existing policy

Paste only a policy you are authorized to inspect.

Your validation result will appear here.

What this checks

Standards note: Permissions Policy is still a W3C Working Draft and browser support varies. A valid header here is not proof that a browser, embedded frame, server, or application will behave as intended.

MDN Permissions-Policy reference · W3C Permissions Policy

Advertisement
Advertisement
Listening…