Skip to content

HTTP security configuration

What is Permissions-Policy?

Whether responses set a Permissions-Policy header that switches off powerful browser features the site does not use.

Part of the External Security Check. Free during the preview.

What it checks

Whether responses set a Permissions-Policy header that switches off powerful browser features the site does not use.

A pass means: A Permissions-Policy limits powerful browser features.

Possible findings

No Permissions-Policy

Severity: InformationConfidence: ConfirmedKind: Recommended hardening

What we found

Responses do not set a Permissions-Policy header.

Why it matters

A Permissions-Policy switches off browser features (camera, microphone, geolocation) your site does not use, limiting what injected or third-party code could do.

How to fix it

Add a policy that disables features you do not use, for example Permissions-Policy: camera=(), microphone=(), geolocation=().

References