field Provisional
Verified 2026-09-18 · registry updated 2026-08-28

Permissions-Policy

Controls which browser features and APIs may be used by a document and its frames.

Disable sensitive or unnecessary features by default and delegate only the origins that need them.

httpsecurityprivacyheader

Reference (http)

Permissions-Policy: camera=(), microphone=(), geolocation=()

Disable sensitive or unnecessary features by default and delegate only the origins that need them.

Editorial status: this registry value is provisional. Review compatibility before deploying it and do not present it as a current default.

Common mistakes

  • Assuming Permissions-Policy replaces user permission prompts or controls server-side access.

IANA registry: http-fields/field-names

Registry reference: Permissions Policy

Permalink: https://merginit.com/reference/http/permissions-policy