Private, browser-local utility

Permissions Policy Generator

Build a bounded Permissions-Policy HTTP header from structured browser-feature allowlists.

Your input and result stay in this browser tab. Nothing is uploaded, fetched, executed, logged, or stored.

Loading local tool…

Policy scope and safety

V1 supports twelve stable feature identifiers and structured allowlists: none, all, self, explicit HTTP(S) origins, or self plus origins. Origins cannot include credentials, paths, queries, fragments, quotes, backslashes, or control characters. Duplicate directives and origins are rejected.

The tool generates header text only. It does not scan, configure, or secure a server. Browser support and application requirements vary; test a policy carefully before enforcing it. No legacy Feature-Policy syntax is emitted.