Firefox Tomorrow

http permissions policy directive

Permissions-Policy: publickey-credentials-create directive

View on MDN ↗

Limited availability

The HTTP Permissions-Policy header publickey-credentials-create directive controls whether the current document is allowed to use the Web Authentication API to create new WebAuthn credentials, i.e., via navigator.credentials.create({publicKey}).

Specifically, where a defined policy blocks use of this feature, the Promise returned by navigator.credentials.create({publicKey}) will reject with a NotAllowedError DOMException. If the method is called cross-origin, the Promise will also reject with a NotAllowedError if the feature is granted by allow= on an iframe and the frame does not also have Transient activation.

Syntax

Permissions-Policy: publickey-credentials-create=<allowlist>;
  • <allowlist>

Default policy

The default allowlist for publickey-credentials-create is self.

Specifications

SpecificationsStandards references are available on the canonical MDN page.

Browser compatibility

Browser compatibilityCompatibility data is available on the canonical MDN page.

See also