Back to Content

Permissions-Policy: publickey-credentials-get directive

files/en-us/web/http/reference/headers/permissions-policy/publickey-credentials-get/index.md

latest1.3 KB
Original Source

{{SeeCompatTable}}

The HTTP {{HTTPHeader("Permissions-Policy")}} header publickey-credentials-get directive controls whether the current document is allowed to access the Web Authentication API to retrieve public-key credentials, i.e., via {{domxref("CredentialsContainer.get","navigator.credentials.get({publicKey})")}}.

Specifically, where a defined policy blocks the use of this feature, the {{jsxref("Promise")}} returned by navigator.credentials.get({publicKey}) will reject with a NotAllowedError {{domxref("DOMException")}}.

Syntax

http
Permissions-Policy: publickey-credentials-get=<allowlist>;
  • <allowlist>

Default policy

The default allowlist for publickey-credentials-get is self.

Specifications

{{Specifications}}

Browser compatibility

{{Compat}}

See also