Security · browser capabilities
Permissions policy.
Build an allowlist for browser features, then validate the exact header value you plan to send. Everything runs locally; no policy text leaves this browser.
Generate a header
Generated header
Generate a header to see the result.
The validator will flag duplicate features, malformed origins, and unsupported schemes.
Validate an existing policy
Paste only a policy you are authorized to inspect.Your validation result will appear here.
What this checks
- Recognised feature names and duplicate directives
- Structured allowlists such as
()and(self "https://example.com") - HTTP(S) origins, wildcard subdomains, ports, and rejected schemes
- Enforce vs report-only header naming
Standards note: Permissions Policy is still a W3C Working Draft and browser support varies. A valid header here is not proof that a browser, embedded frame, server, or application will behave as intended.