Permissions-Policy Delegation Simulator

Model selected feature delegation for one iframe using top-page policy, its allow attribute and child restrictions.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Model delegation controls

The origin of the page that embeds the frame. It decides which requests count as the same origin.

Up to 4,000 characters. Use the header form: comma between features and parentheses around the origins. Features that are absent fall back to their default allowlist.

The URL in the src attribute. Its origin is the declared origin used by the allow attribute.

Leave blank when the frame stays on its src origin. Enter an origin such as https://other.example when the frame redirects, because the rules are checked against the loaded origin.

Up to 4,000 characters. Use the attribute form: semicolon between features, and self, src, none or a quoted origin in each list. An empty list means src.

Optional. A frame can restrict a feature further in its own response. Leave blank when the frame sends none.

Processed in your browser. Your inputs stay on this device.

Showing a generated example. Generate again for a new result.

How to use Permissions-Policy Delegation Simulator

  1. Supply the top page origin and permissions-policy response header of the top page using the supported input described beside the controls.
  2. Review the selected options and the declared scope, then run the permissions policy simulator.
  3. Read the result and unresolved findings before downloading or sharing a report. The original input is not changed.

Example: Permissions-Policy Delegation Simulator

Evaluate a declared top-page/iframe policy and allow attribute for selected features. This example uses synthetic public data.

You add
Top page origin: https://app.example.com Permissions-Policy response header of the top page: geolocation=(self "https://maps.embed.example"), camera=(self), microphone=() iframe src (declared URL): https://maps.embed.example/view?place=dhaka iframe allow attribute: geolocation 'src'; camera 'none'; fullscreen 'self'
You get
1 of 4 features reach the frame. camera | blocked | The page header does not allow https://maps.embed.example for this feature. microphone | blocked | The page header switches the feature off for the page itself, so no frame can be granted it. geolocation | allowed | Allowed because the page header allows the frame origin, the allow attribute passes the feature on, the frame does not restrict it in its own response header.

Options

Origins and iframe source
Keep the declared iframe source and actual navigated origin distinct. A src token refers to its defined source convention, not every future navigation.
Intersecting restrictions
Top-page policy, iframe delegation and child restrictions all matter. A broader child declaration cannot recover permission denied by its ancestor.

Supported inputs and limits

One-iframe model for the listed features and supported syntax only. No device APIs, browser permission prompts, live testing or complete policy parser.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Policy eligibility is separate from permission

A modeled feature can be eligible under the supplied policy while a real browser still refuses it because of user permission, document state or platform support. The supported one-iframe scenario does not model an entire frame tree. Unsupported features or structures remain outside the result.

Questions about Permissions-Policy Delegation Simulator

Does eligible mean the camera will work?

No. User permission, browser support and document conditions are separate.

Can a child override an ancestor denial?

No. The modeled restrictions are intersected.

Can it model nested frames?

No. This page covers its explicitly declared one-iframe scenario.

Project manager: Tony Hines · Content updated 4 October 2026 · Report a problem