field Provisional
Verified 2026-09-18 · registry updated
2026-08-28Permissions-Policy
Controls which browser features and APIs may be used by a document and its frames.
Disable sensitive or unnecessary features by default and delegate only the origins that need them.
httpsecurityprivacyheader
Reference (http)
Permissions-Policy: camera=(), microphone=(), geolocation=()
Disable sensitive or unnecessary features by default and delegate only the origins that need them.
Editorial status: this registry value is provisional. Review compatibility before deploying it and do not present it as a current default.
Common mistakes
- Assuming Permissions-Policy replaces user permission prompts or controls server-side access.
IANA registry: http-fields/field-names
Registry reference: Permissions Policy