Headers
Permissions-Policy: explicitly disabling browser features your site doesn't use.
Published 2026-05-06 · Last updated 2026-05-06 · Vantyris editorial
Permissions-Policy (the successor to Feature-Policy) is a response header that tells the browser which powerful features your site may use and which it may not. Most sites have no use for the camera, microphone, geolocation, USB access, or interest-cohort tracking (the FLoC successor). But if a compromised third-party script tries to use one of them, the browser allows it unless you've opted out. This header is the opt-out. One line, ten minutes of work.
What this means for your business
- Without it, any JavaScript on your page can request access to powerful browser APIs. Most of them (camera, microphone, geolocation) need the user's consent before they switch on, but the request itself is a phishing vector. A malicious script can pop up a permission dialog that looks like it came from your site.
Permissions-Policylets you tell the browser 'this site never uses these features, refuse them outright'. A compromised third-party script then can't even ask. The browser blocks the request before the user ever sees a permission dialog.- Setting
interest-cohort=()in the header also disables interest-cohort tracking (the FLoC successor). It's part of Vantyris's standard defensive header set, and it's what the Vantyris homepage ships.
How to fix
Add a Permissions-Policy header to every page's response, listing the features to disable. Start by disabling everything you don't actively use.
- List the browser APIs your site actually needs. Audit the JavaScript on your site for calls to
navigator.geolocation,navigator.mediaDevices.getUserMedia,navigator.usb,navigator.bluetooth, or similar. Most small business sites make none. - Write the
Permissions-Policyheader. A defensive starting policy:camera=(), microphone=(), geolocation=(), payment=(), usb=(), interest-cohort=(). Each feature followed by=()means 'block everywhere'. To allow a feature on your own origin, usegeolocation=(self). For specific third-party origins, usegeolocation=(self "https://maps.example.com"). - Add the header to your web host or CDN. Apache:
Header always set Permissions-Policy "camera=(), microphone=(), geolocation=(), payment=(), usb=(), interest-cohort=()". Nginx:add_header Permissions-Policy "camera=(), microphone=(), geolocation=(), payment=(), usb=(), interest-cohort=()" always;. Next.js: in the headers function innext.config.mjs. - Verify in DevTools. Reload your site, open the Network tab, click any request and look at Response Headers. You should see
permissions-policy: camera=(), microphone=(), ....
Owner: Your web host or developer. · Time: 10-15 minutes.
Common gotchas
- If you DO use a feature (e.g., a 'show me on the map' button that uses geolocation), don't blanket-disable it. Use
geolocation=(self)to allow your own domain. - Some payment iframes (Stripe, PayPal) need
paymentallowed for specific origins. If you embed Stripe Checkout, setpayment=(self "https://checkout.stripe.com"). - The syntax is finicky. Spaces inside parentheses, no quotes around feature names, exact origin URLs. Use a header checker (securityheaders.com) to validate.
- Older browsers read the now-deprecated
Feature-Policyheader instead. You can send both for belt-and-braces coverage. Most sites send onlyPermissions-Policyand accept that pre-2021 browsers won't enforce it.
How to verify the fix
A Vantyris verified scan checks that Permissions-Policy is present and parses the directives. securityheaders.com also grades how much the header covers.
Cyber Essentials alignment
This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):
- A2. Secure configuration: devices and services hardened against the weaknesses they ship with by default.
Vantyris is not a CE certifying body. The mapping above is informational.
Common follow-up questions
Does this affect search engine crawling?
No. Search crawlers don't try to use the camera or microphone, and they ignore Permissions-Policy entirely. A defensive policy doesn't hurt SEO.
What's the FLoC / interest-cohort thing?
Google's Topics API + Federated Learning of Cohorts was an attempt to do interest-based advertising without third-party cookies. Privacy advocates objected, and many sites opt out by setting interest-cohort=(). Vantyris does this by default. We recommend you do too, unless you have a specific reason to take part in the cohort scheme.
Will I notice anything as a site owner if my Permissions-Policy is too strict?
Only if you try to use a blocked feature on your own site. The API call then fails with a Permission denied error, and you fix the policy. Block by default, loosen when you need to. That's the right pattern.
References
Related explainers
- Content Security Policy: the header that stops most XSS attacks dead.
- X-Frame-Options and frame-ancestors: the anti-clickjacking header.
- HSTS: the security header that locks HTTPS on for good.
Want Vantyris to check your domain for this and 196 other problems?
The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.
Written by Vantyris