Home/SEO, Domain & Network Inspector Tools/Permissions-Policy Header Builder

Permissions-Policy Header Builder

Construct enterprise-grade Permissions-Policy (Feature-Policy) HTTP security headers to lock down camera, microphone, geolocation, and privacy APIs.

Directives Matrix

27 features
CameracameraW3C Recommendation

Controls access to video input devices such as webcams and built-in mobile cameras.

MicrophonemicrophoneW3C Recommendation

Controls access to audio capture hardware and built-in microphone arrays.

GeolocationgeolocationW3C Recommendation

Restricts access to the Geolocation API for device coordinates and GPS positioning.

Speaker Selectionspeaker-selectionW3C Draft

Governs audio output device selection via the Audio Output Devices API.

MIDI DevicesmidiW3C Recommendation

Controls access to Musical Instrument Digital Interface (MIDI) software and hardware.

WebUSBusbW3C Draft

Restricts low-level communication with connected Universal Serial Bus (USB) peripherals.

Web SerialserialW3C Draft

Controls interaction with physical RS-232 serial ports and microcontroller bridges.

Web BluetoothbluetoothExperimental

Restricts scanning and pairing with nearby Bluetooth Low Energy (BLE) peripherals.

WebHID (Human Interface Devices)hidW3C Draft

Restricts communication with uncommon gamepads, pedals, and hardware knobs.

AccelerometeraccelerometerW3C Recommendation

Monitors linear acceleration along three physical spatial dimensions.

GyroscopegyroscopeW3C Recommendation

Measures rates of angular rotation along physical hardware pitch, yaw, and roll axes.

MagnetometermagnetometerW3C Recommendation

Measures ambient magnetic fields and orientation relative to geomagnetic poles.

Ambient Light Sensorambient-light-sensorW3C Draft

Monitors ambient illuminance levels measured by surrounding photodetectors.

Autoplay MediaautoplayW3C Recommendation

Controls whether video or audio streams can initiate audio-rich playback automatically.

Clipboard Readclipboard-readW3C Draft

Restricts asynchronous programmatic retrieval of operating system clipboard contents.

Clipboard Writeclipboard-writeW3C Draft

Controls programmatic copy operations to modify operating system clipboard buffers.

Topics API (Privacy Sandbox)browsing-topicsExperimental

Controls whether third-party trackers can extract browser behavioral interests.

FLoC / Interest Cohort (Legacy)interest-cohortExperimental

Explicitly opts out of federated interest cohort profiling across ad networks.

Run Ad Auction (Protected Audience)run-ad-auctionExperimental

Governs execution of client-side ad bidding scripts via Protected Audience APIs.

Join Ad Interest Groupjoin-ad-interest-groupExperimental

Restricts advertiser scripts from registering the user into remarketing buckets.

Synchronous XHRsync-xhrW3C Recommendation

Controls blocking synchronous XMLHttpRequest calls that freeze the primary browser UI thread.

Screen Wake Lockscreen-wake-lockW3C Recommendation

Governs whether the application can keep the device screen illuminated indefinitely.

Fullscreen DisplayfullscreenW3C Recommendation

Controls whether iframes and elements can transition into full-viewport immersion mode.

Payment Request APIpaymentW3C Recommendation

Controls merchant checkout integration with Apple Pay, Google Pay, and PaymentRequest.

Screen Sharing / Display Capturedisplay-captureW3C Recommendation

Restricts capturing monitor visual surfaces via getDisplayMedia screen recorders.

Picture-in-Picture (PiP)picture-in-pictureW3C Recommendation

Controls whether floating desktop picture-in-picture video viewports can be spawned.

Web Share APIweb-shareW3C Recommendation

Governs invoking native mobile sharing sheets via navigator.share().

Generated Server Output

RFC 8941
camera=(), microphone=(), geolocation=(), speaker-selection=(), midi=(), usb=(), serial=(), bluetooth=(), hid=(), accelerometer=(), gyroscope=(), magnetometer=(), ambient-light-sensor=(), autoplay=(self), clipboard-read=(), clipboard-write=(self), browsing-topics=(), interest-cohort=(), run-ad-auction=(), join-ad-interest-group=(), sync-xhr=(), screen-wake-lock=(self), fullscreen=(self), payment=(self), display-capture=(), picture-in-picture=(self), web-share=(self)
Disabled

20

Self-Only

7

Permissive

0

Privacy Sandbox Recommendation

For maximum visitor privacy, always ensure browsing-topics=() and interest-cohort=() are set to disallow. This prevents ad network trackers from aggregating your users into interest groups across external websites.

100% Client-Side In-Memory Execution: All header string compilations, syntax conversions, and configuration exports are calculated directly in your local browser sandbox. No domain names, origin parameters, or server infrastructure blueprints are ever transmitted to or stored on external servers.

Permissions-Policy Architecture: Granular Hardware & API Governance for Modern Web Applications

The web platform has evolved from static hypertext documents into a sophisticated operating environment capable of interfacing directly with high-definition cameras, microphone arrays, Bluetooth peripherals, USB microcontrollers, and motion sensors. While these capabilities empower web-based applications, they create significant attack vectors when third-party ad networks, social widgets, analytics trackers, or supply-chain script dependencies operate in the same execution context.

The Permissions-Policy HTTP response header provides security engineers with authoritative control over which browser features and hardware interfaces can be invoked by top-level web documents and nested <iframe> frames. By implementing the Principle of Least Privilege (PoLP) at the HTTP layer, you can prevent unauthorized eavesdropping, unauthorized geolocation triangulation, battery drainage from ambient sensors, and intrusive tracking mechanisms.

Subresource Isolation

Even if a malicious advertiser or third-party partner embeds an iframe, the browser denies access to cameras, microphones, or payment APIs if the parent policy does not explicitly delegate access.

Anti-Fingerprinting Defense

Disabling device motion sensors, magnetometers, and ambient light sensors mitigates advanced hardware fingerprinting vectors used by profiling bots to track users across incognito sessions.

Behavioral Privacy Protection

Directives like browsing-topics=() prevent advertising algorithms from silently monitoring domain visits to construct commercial behavioral profiles without express consent.

Standard RFC 8941 Structured Fields Syntax Breakdown

Permissions-Policy replaces the legacy Feature-Policy syntax with standard HTTP Structured Fields. Directives are delimited by commas, and origin parameters are wrapped in parentheses:

# modern RFC 8941 Permissions-Policy Syntax Permissions-Policy: camera=(), microphone=(), geolocation=(self "https://maps.partner.com"), fullscreen=* # Breakdown: # camera=() -> Completely disabled for all frames # microphone=() -> Completely disabled for all frames # geolocation=(self "https://...") -> Allowed on same-origin and explicitly trusted partner # fullscreen=* -> Unrestricted access across all documents and child frames

Comparative Matrix: Permissions-Policy vs. Feature-Policy vs. CSP sandbox

Web security engineers frequently navigate overlapping HTTP header directives. Understanding where Permissions-Policy fits relative to our Content Security Policy (CSP) header generator and legacy Feature-Policy ensures complete defensive coverage without breaking legitimate site functionality. Furthermore, when delegating high-entropy device headers to CDNs, verify your origin headers with the User-Agent client hints inspector to ensure cross-origin privacy delegations remain intact.

SpecificationPrimary Defense ScopeSyntax FormatBrowser StatusHeader Name
Permissions-PolicyHardware, APIs, and Privacy Sandbox APIsRFC 8941 Structured Items: feature=(self)Current W3C StandardPermissions-Policy
Feature-PolicyLegacy hardware restrictionSemicolon-separated: feature 'self'Deprecated (Obsolescent)Feature-Policy
CSP: sandboxForm submission, popups, script executionFlag list: allow-scripts allow-formsActive W3C StandardContent-Security-Policy
Iframe allow attributePer-frame authorization delegationInline string: allow="camera; microphone"Active HTML Standard<iframe allow="...">

Deployment Guide: Server-Level Header Configurations for Production

To guarantee bulletproof protection, the Permissions-Policy header must be emitted as a true HTTP response header directly from your reverse proxy, web server, or CDN edge cache. Here is how leading infrastructure engines implement this header:

Nginx (Reverse Proxy & Ingress)

Add the directive within your primary http { }, server { }, or route location / { } block. The always parameter ensures the header is attached even during 4xx/5xx HTTP error states:

add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always;

Apache HTTP Server (.htaccess)

Verify that mod_headers is enabled inside Apache. Place the rule inside your document root .htaccess file or virtual host configuration:

<IfModule mod_headers.c>
    Header always set Permissions-Policy "camera=(), microphone=(), geolocation=()"
</IfModule>

Caddy Web Server (Caddyfile)

Caddy allows straightforward declarative header definitions directly inside any domain declaration block:

header Permissions-Policy "camera=(), microphone=(), geolocation=()"

Vercel & Next.js Edge Routing

In Next.js App Router applications, declare headers inside next.config.js or define them inside root vercel.json:

// next.config.js
module.exports = {
  async headers() {
    return [{
      source: '/:path*',
      headers: [{
        key: 'Permissions-Policy',
        value: 'camera=(), microphone=(), geolocation=()'
      }]
    }];
  }
};

Frequently Asked Questions (FAQ)

What is the HTTP Permissions-Policy header?

The Permissions-Policy HTTP header (formerly Feature-Policy) gives web developers explicit granular control over browser features, hardware devices, and APIs available to the page and any embedded third-party iframes. It hardens security by disabling sensitive hardware such as cameras, microphones, sensors, and GPS geolocation.

What is the difference between Feature-Policy and Permissions-Policy?

Feature-Policy is the legacy syntax deprecated by the W3C Web Platform Incubator Community Group. Permissions-Policy is the modern standardized replacement utilizing Structured Fields for HTTP (RFC 8941), using parenthesized origin syntax like camera=(self) or geolocation=() instead of whitespace-separated quotes.

How does Permissions-Policy enhance website security?

By enforcing a strict Permissions-Policy, site owners block malicious scripts, third-party advertising SDKs, and compromised nested iframes from turning on microphones, accessing device coordinates, reading the OS clipboard, or executing battery-draining cryptographic coin miners.

Why should I disable the browsing-topics and interest-cohort directives?

Disabling browsing-topics=() and interest-cohort=() prevents your website users from having their cross-site behavioral histories grouped into targeted advertising profiles by automated tracking algorithms like Google's Topics API and legacy FLoC.

Can Permissions-Policy be configured in HTML <meta> tags?

No. Modern browser security models strictly mandate that Permissions-Policy be delivered via genuine HTTP response headers sent directly by the web server or reverse proxy. The browser ignores Permissions-Policy inside standard HTML meta http-equiv tags.

What is the syntax for granting feature access to a trusted third-party domain?

To authorize a specific third-party origin, wrap the directive target in parentheses and enclose the domain in double quotes, such as: payment=(self "https://payments.stripe.com"). Multiple origins can be separated by spaces within the parentheses.

Related & Complementary Utilities

Explore more privacy-first client-side web tools.