Skip to live checks

Permission Lab

Browser origin permission tester

Current origin

Primary host

Detecting origin…

Secure contextTop-level pageOnline
camerachecking
microphonechecking
geolocationchecking

Live checks

Test this origin

Location
Checking browser state
checking

No position yet

Coordinates plot locally

Location is idle.
May use more battery
Camera
Checking browser state
checking

Camera is idle

Live video appears here

Camera is idle.
Microphone
Checking browser state
checking

Microphone is idle

A local waveform appears here

Microphone is idle.

Combined media request

Ask for camera and microphone in one atomic request. If either track is unavailable or blocked, the whole request normally fails.

Origin isolation
Launch the same lab on real sibling hostnames. Each hostname becomes a separate permission key.
Custom DNS required

Enter the parent hostname served by this deployment

Example: permissions.example.com. The lab will create links for maps.*, camera.*, mic.*, and all.*.

Same-origin control test

This opens another path and query on the current host. It should share the exact same permission record.

Open alternate page
How to activate real subdomains
  1. Use a domain you control and attach the four hostnames to this same deployed site.
  2. Add the DNS and certificate-validation records supplied by the host.
  3. Paste the shared parent hostname above and open each link as a top-level page.

Routes such as /maps and /camera cannot test subdomain isolation because they are still the same origin.

Live context
Signals that help investigate user, document-policy, and platform failures. Some browsers report the same error for more than one cause.
Scheme
Hostname
Port
default
Frame
top-level
Visibility
visible
Run ID
initializing

Permissions Policy

cameranot exposed
microphonenot exposed
geolocationnot exposed

A permission may be granted but idle. A live sensor always appears separately above.

Advanced case

Embedded-origin lab

Same-origin control

Frame setup

With sibling DNS configured, this frame is cross-origin. Without it, the fallback frame is same-origin.

Parent
Detecting origin…
Child target
preparing…

This is a same-origin control. Configure sibling DNS before testing cross-origin delegation.

iframe allow

camera

Detecting origin…/?embed=1&test=camera

Manual coverage

Browser test matrix

0/12 recorded
01

Fresh origin

Clear this site’s stored decisions, then request each permission.

not run
Expected: The browser asks once per undecided permission.
02

Repeat request

Allow or block a permission, then press its request button again.

not run
Expected: The saved decision is applied without an unexpected prompt.
03

Reload persistence

Make a decision, reload this page, and request again.

not run
Expected: The decision persists according to your browser’s policy.
04

Global allow · site block

Allow globally, block this origin in site settings, then request.

not run
Expected: The site override wins if that is your product policy.
05

Global block · site allow

Block globally, allow this origin in site settings, then request.

not run
Expected: The observed result matches the precedence you designed.
06

Sibling subdomains

Allow maps.*, block camera.*, then revisit both origins.

not run
Expected: Each hostname keeps an independent permission record.
07

Combined media

Use the camera + microphone request, then make mixed decisions.

not run
Expected: The atomic request succeeds only when both tracks are available.
08

Change while active

Start a stream, change its site setting, then return to this tab.

not run
Expected: Track and permission-state changes are visible in the log.
09

Same origin, new path

Open the alternate-page link and compare permission behavior.

not run
Expected: Paths and query strings share one origin record.
10

Embedded origin

Toggle iframe delegation and request inside the embedded lab.

not run
Expected: Cross-origin access requires both user consent and delegation.
11

Two tabs

Open a second tab, run the same sensor, then stop one tab.

not run
Expected: Each tab cleans up its own tracks without corrupting site state.
12

OS-level block

Disable device access at OS level, then request it here.

not run
Expected: The error differs from a normal site-level denial when exposed.
Event log
Permission requests, state changes, media lifecycle, device changes, and page context.
run initializing0 events · newest first

No events in this session

Reset means two different things

Reset session stops tracks, clears results, and starts a new report. It cannot revoke a decision stored by your browser.

To test a fresh prompt, use your browser’s site controls to reset camera, microphone, or location for this exact origin.

Private by construction

Camera frames, microphone samples, and coordinates stay in this tab. The lab has no upload, recording, analytics, or database path.