A mechanism to selectively enable and disable browser features and APIs
430
stars
537
commits
Bikeshed
primary language
Jun 18, 2026
updated
A web platform API which gives a website the ability to allow and deny the use of browser features in its own frame, and in iframes that it embeds. Examples of features that could be controlled by permissions policy include:
See also: how to integrate a web platform feature with permissions policy.
The Permissions Policy spec is hosted on this repo, at https://w3c.github.io/webappsec-permissions-policy/
For more explanation, use cases, examples, etc., please refer to the explainer document.
Document Policy, which was previously hosted here, has been moved to WICG; it can be found at https://github.com/WICG/document-policy/.
Questions, suggestions? Please open an issue or send a pull request!
Bikeshed
99.4%
A mechanism to selectively enable and disable browser features and APIs
430
stars
537
commits
Bikeshed
primary language
Jun 18, 2026
updated
A web platform API which gives a website the ability to allow and deny the use of browser features in its own frame, and in iframes that it embeds. Examples of features that could be controlled by permissions policy include:
See also: how to integrate a web platform feature with permissions policy.
The Permissions Policy spec is hosted on this repo, at https://w3c.github.io/webappsec-permissions-policy/
For more explanation, use cases, examples, etc., please refer to the explainer document.
Document Policy, which was previously hosted here, has been moved to WICG; it can be found at https://github.com/WICG/document-policy/.
Questions, suggestions? Please open an issue or send a pull request!
Bikeshed
99.4%