Permissions Policy Generator
Generate HTTP Permissions-Policy header to control browser features.
Last reviewed by the Radiatus Cloud team
Permissions Policy Generator
Control which browser features (camera, microphone, geolocation) can be used.
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
Control which browser features a page can use
The Permissions-Policy header lets a site control which powerful browser features its pages may use, and configuring it improves security and privacy. This tool generates a Permissions-Policy header, so you can disable features your site does not need.
Why controlling features matters
Browsers expose powerful features, camera, microphone, geolocation, and by default a page and the third-party content it embeds may attempt to use them. The Permissions-Policy header lets you explicitly allow or deny each feature, so a page that has no need for the camera cannot request it, and embedded content cannot either. This reduces both the attack surface and the privacy risk, since a compromised script or a nosy embed cannot reach a feature you have disabled. Disabling what you do not use is a simple, effective hardening step that costs nothing.
A tool, not legal advice
It runs entirely in your browser, so nothing you enter is uploaded and the generated output is yours to use, which matters when the input or result concerns your own site or organisation.
Related tools
- SOC 2 Evidence Readiness — Interactive checklist to gauge your SOC 2 evidence readiness.
- Privacy Policy Checker — Check if your policy covers standard requirements (GDPR/CCPA basics).
- Compliance Req Finder — Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
- Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Frequently Asked Questions
What does the Permissions-Policy header do?
It controls which powerful browser features, like camera, microphone and geolocation, a page and its embedded content are allowed to use.
Why disable features a site does not use?
Because it reduces attack surface and privacy risk: a compromised script or embedded content cannot reach a feature you have explicitly disabled.
Does it affect embedded content?
Yes. The policy governs what embedded third-party content can request too, so it limits what embeds can do as well as your own scripts.
Is this hard to configure?
No. Disabling features you do not use is a simple, effective hardening step. The generator produces the header for your chosen settings.
Is my input uploaded?
No. The generation runs entirely in your browser.
Privacy & Security
Local generation.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.