How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Permissions-Policy

Security Policy IANA provisional reached by regulation

A reference entry. The registry facts and catalog measurements below are complete; the written guidance for this header has not been authored yet.

The Permissions-Policy HTTP header — security policy, not observed in the catalog.

Permissions-Policy is security policy — Response headers instructing the client to constrain itself — transport security, framing, script sources, sniffing, referrer leakage.

The registry

Listed in the IANA HTTP Field Name Registry as a provisional entry — registered, but not through a standards-track document. Defined in Permissions Policy.

In the catalog

Registered with IANA and declared by not one of the 26,641 providers in the API Evangelist catalog. A registered field with no observed use is still part of the vocabulary — it just is not part of the practice.

Reached by regulation

No law names this header. It is evidentiary — the deployed control for an obligation that regulation does impose. It is observable at the edge: an unauthenticated request is enough to see whether a provider sends it.

Reached by these regulations

Catalogued at regulations.apievangelist.com, with the basis of each connection recorded rather than implied.

Governed by these rules

Machine-enforceable governance rules from rules.apievangelist.com that apply to this header when it appears in an OpenAPI.

OpenAPI Components Headers Error error

Utilizing the headers object in the centralized OpenAPI components library helps make headers reusable across API requests and responses

Guidance: Rate Limits →
OpenAPI Components Headers Info info

Utilizing the headers object in the centralized OpenAPI components library helps make headers reusable across API requests and responses

Guidance: Rate Limits →
OpenAPI Headers Hyphenated Pascal Case error

HTTP headers should follow Hyphenated-Pascal-Case naming convention for consistency and readability, such as Content-Type, X-Request-Id, or Accept-Language.

Guidance: Naming →