v149 · Permissions Policy · Security
Header Builder
Build the exact Permissions-Policy HTTP header and the corresponding iframe allow attribute for focus-without-user-activation. Choose an allowlist mode, add specific origins, and get copy-pasteable output for your server and your embed tags.
Allowlist mode
Allowed origins
HTTP response header
iframe allow attribute
nginx / Apache config snippet
see also
- Focus Hijack Guard — live focus-stealing demo
- Autofocus Lockdown — autofocus attribute interaction
- Focus Timeline — event log of focus attempts and policy decisions
implementation reference
Need the exact API surface, compatibility boundaries, errors, lifecycle, and source links? Read the matching gendn reference ↗