Compliance

Permissions Policy Generator

Generate HTTP Permissions-Policy header to control browser features.

Last reviewed by the Radiatus Cloud team

Permissions Policy Generator

Control which browser features (camera, microphone, geolocation) can be used.

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

Control which browser features a page can use

The Permissions-Policy header lets a site control which powerful browser features its pages may use, and configuring it improves security and privacy. This tool generates a Permissions-Policy header, so you can disable features your site does not need.

Why controlling features matters

Browsers expose powerful features, camera, microphone, geolocation, and by default a page and the third-party content it embeds may attempt to use them. The Permissions-Policy header lets you explicitly allow or deny each feature, so a page that has no need for the camera cannot request it, and embedded content cannot either. This reduces both the attack surface and the privacy risk, since a compromised script or a nosy embed cannot reach a feature you have disabled. Disabling what you do not use is a simple, effective hardening step that costs nothing.

A tool, not legal advice

It runs entirely in your browser, so nothing you enter is uploaded and the generated output is yours to use, which matters when the input or result concerns your own site or organisation.

Related tools

Frequently Asked Questions

What does the Permissions-Policy header do?

It controls which powerful browser features, like camera, microphone and geolocation, a page and its embedded content are allowed to use.

Why disable features a site does not use?

Because it reduces attack surface and privacy risk: a compromised script or embedded content cannot reach a feature you have explicitly disabled.

Does it affect embedded content?

Yes. The policy governs what embedded third-party content can request too, so it limits what embeds can do as well as your own scripts.

Is this hard to configure?

No. Disabling features you do not use is a simple, effective hardening step. The generator produces the header for your chosen settings.

Is my input uploaded?

No. The generation runs entirely in your browser.

Privacy & Security

Local generation.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.