What does the validator check?
It checks directive syntax, feature names, origin formatting, duplicate entries and potentially broad allowlists.
Security
Validate Permissions-Policy header syntax, directives, origins and allowlists.
Validate Permissions-Policy header syntax, directives, origins and allowlists.
This tool runs in your browser. Your input is processed locally and is not uploaded.
Use this Permissions Policy validator to inspect an existing header before deployment. The tool checks feature names, allowlists, origin syntax, duplicate directives and overly broad permissions locally in your browser.
It checks directive syntax, feature names, origin formatting, duplicate entries and potentially broad allowlists.
No. A policy may be syntactically valid but still allow more browser capabilities than the application requires.
Yes. A browser-side rule list can flag known deprecated or unsupported feature directives without contacting a server.