security / security headers / permissions-policy
Security headers

Permissions-Policy

Permissions-Policy lets you control which browser features — like camera, microphone and location — your site and its embedded content are allowed to use.

Severity if missing
Low
Category
Security headers
Standard
W3C Permissions Policy

What it is

Modern browsers expose powerful features to websites: camera, microphone, geolocation, and more. The Permissions-Policy header lets you explicitly allow or deny each of these, both for your own site and for any third-party content embedded in it.

By default, many of these features are available unless you turn them off. This header lets you disable the ones you don't need.

Why it matters

If your site includes third-party scripts or embeds, they may be able to request access to sensitive features on your behalf. A Permissions-Policy shuts the door on features you don't use, reducing what a compromised or malicious embed could attempt.

The risk
Without a Permissions-Policy, embedded third-party content may access browser features like camera or location that your site never intended to expose.

How Pentrawl checks it

Pentrawl checks your response headers for a Permissions-Policy header. Its presence passes the check; its absence is reported as a low-severity issue.

How to fix it

Add a Permissions-Policy header to your server, disabling the features your site doesn't use. The example below blocks camera, microphone and geolocation entirely.

Example
Permissions-Policy: camera=(), microphone=(), geolocation=()
Check your domain's Permissions-Policy in seconds
Pentrawl scans this and 20+ other security checks in one automated pass.
Scan your website →