Skip to main content

Headers

Permissions-Policy: explicitly disabling browser features your site doesn't use.

Published 2026-05-06 · Last updated 2026-05-06 · Vantyris editorial

Permissions-Policy (the successor to Feature-Policy) is a response header that tells the browser which powerful features your site may use and which it may not. Most sites have no use for the camera, microphone, geolocation, USB access, or interest-cohort tracking (the FLoC successor). But if a compromised third-party script tries to use one of them, the browser allows it unless you've opted out. This header is the opt-out. One line, ten minutes of work.

What this means for your business

How to fix

Add a Permissions-Policy header to every page's response, listing the features to disable. Start by disabling everything you don't actively use.

  1. List the browser APIs your site actually needs. Audit the JavaScript on your site for calls to navigator.geolocation, navigator.mediaDevices.getUserMedia, navigator.usb, navigator.bluetooth, or similar. Most small business sites make none.
  2. Write the Permissions-Policy header. A defensive starting policy: camera=(), microphone=(), geolocation=(), payment=(), usb=(), interest-cohort=(). Each feature followed by =() means 'block everywhere'. To allow a feature on your own origin, use geolocation=(self). For specific third-party origins, use geolocation=(self "https://maps.example.com").
  3. Add the header to your web host or CDN. Apache: Header always set Permissions-Policy "camera=(), microphone=(), geolocation=(), payment=(), usb=(), interest-cohort=()". Nginx: add_header Permissions-Policy "camera=(), microphone=(), geolocation=(), payment=(), usb=(), interest-cohort=()" always;. Next.js: in the headers function in next.config.mjs.
  4. Verify in DevTools. Reload your site, open the Network tab, click any request and look at Response Headers. You should see permissions-policy: camera=(), microphone=(), ....

Owner: Your web host or developer. · Time: 10-15 minutes.

Common gotchas

How to verify the fix

A Vantyris verified scan checks that Permissions-Policy is present and parses the directives. securityheaders.com also grades how much the header covers.

Cyber Essentials alignment

This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):

Vantyris is not a CE certifying body. The mapping above is informational.

Common follow-up questions

Does this affect search engine crawling?

No. Search crawlers don't try to use the camera or microphone, and they ignore Permissions-Policy entirely. A defensive policy doesn't hurt SEO.

What's the FLoC / interest-cohort thing?

Google's Topics API + Federated Learning of Cohorts was an attempt to do interest-based advertising without third-party cookies. Privacy advocates objected, and many sites opt out by setting interest-cohort=(). Vantyris does this by default. We recommend you do too, unless you have a specific reason to take part in the cohort scheme.

Will I notice anything as a site owner if my Permissions-Policy is too strict?

Only if you try to use a blocked feature on your own site. The API call then fails with a Permission denied error, and you fix the policy. Block by default, loosen when you need to. That's the right pattern.

References

Related explainers

Want Vantyris to check your domain for this and 196 other problems?

The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.

Written by Vantyris