Permissions-Policy Builder
Turn on, off or origin-scope a browser feature per directive, then copy the header.
Set at least one directive above.
How it works
Pick a setting for each browser feature that matters: None blocks it for every origin including your own page, Self allows only your own origin, All allows any origin including embedded iframes, and Origins scopes it to a specific list of origins typed into the text field. A directive left Unset is omitted from the header entirely.
Only directives current browsers enforce
The full W3C Permissions Policy draft names dozens more directives than are offered here — this list is limited to the set Chromium and Firefox actually enforce today, so the generated header does not carry entries no browser reads.
Example
Blocking camera and microphone everywhere except your own page, while allowing a payment origin for the
payment feature, produces:
camera=(self), microphone=(self), payment=("https://pay.example.com").
Frequently asked questions
What does an empty allowlist, (), actually mean?
No origin at all may use that feature, including your own page. It is the strictest setting — use (self) instead if your own page needs the feature but embedded content should not get it.
Why scope a feature to specific origins instead of just self or *?
A page embedding a third-party checkout or video widget can grant that one origin camera or fullscreen access without opening it to every other iframe on the page — the origin list is exactly for that case.
Does this header stop a feature from being used at all?
It stops it in the browser, for the origins not allowlisted — a blocked getUserMedia() call rejects instead of prompting. It has no effect on native app or server-side use of a device.
Related tools
CSP Generator
Build a Content-Security-Policy header directive by directive, not by editing a string.
LocalSecurity Headers Analyzer
Review a set of pasted HTTP response headers against current guidance.
LocalCSP Analyzer
Break a Content-Security-Policy into its directives and flag the weak ones.
LocalX.509 Certificate Decoder
Paste a PEM certificate to read its subject, issuer, validity, key and extensions.
LocalCSR Decoder
Paste a PKCS#10 CSR to read its requested subject, key and Subject Alternative Names.
LocalCertificate Fingerprint Calculator
Paste a PEM certificate, get its SHA-1 and SHA-256 fingerprint.
Local