HTML allow Attribute
The HTML allow attribute specifies a Permissions Policy for an embedded <iframe>. It controls which browser features and capabilities the content inside the iframe is permitted to use.
Syntax
The allow attribute is placed in the opening <iframe> tag. Its value contains one or more Permissions Policy directives that identify the features available to the embedded content.
<iframe src="page.html" allow="feature"></iframe>
For example, the following iframe permits its embedded content to use the fullscreen feature:
<iframe src="page.html" allow="fullscreen"></iframe>
Attribute Value
| Value | Description |
|---|---|
permissions-policy |
Specifies one or more Permissions Policy directives that control features available to the iframe and its content. |
A directive begins with the name of a feature and can include an allowlist that determines which origins may use that feature. Multiple directives are separated by semicolons.
Elements That Use the allow Attribute
The allow attribute is currently valid on the <iframe> element.
| Element | Description |
|---|---|
<iframe> |
Specifies a Permissions Policy that controls features available to the iframe and its embedded content. |
Using the allow Attribute
The following example allows the embedded document to use the fullscreen feature:
<iframe src="page.html" allow="fullscreen"></iframe>
The allow attribute does not itself activate the feature. It establishes whether the embedded content is permitted to use that capability when the applicable browser requirements are met.
Allowing Multiple Features
Multiple Permissions Policy directives can be included in the same allow attribute. Separate each directive with a semicolon.
<iframe src="page.html" allow="camera; microphone; fullscreen"></iframe>
In this example, the iframe is given permission to use the camera, microphone, and fullscreen features, subject to the browser's permissions and any other applicable policies.
Permissions Policy
Permissions Policy is a web platform mechanism that controls whether documents and embedded content are allowed to use particular browser features. The allow attribute applies a policy specifically to an individual iframe.
Some features support an allowlist that further limits which origins may use the feature. For example, 'self' refers to the origin of the document containing the iframe, while 'none' prevents the feature from being used.
<iframe src="page.html" allow="camera 'none'; fullscreen 'self'"></iframe>
The features available for Permissions Policy and their browser support can vary, so individual feature directives should be checked before they are relied upon.
allow and allowfullscreen
The allow attribute can grant the fullscreen capability by including the fullscreen directive. The allowfullscreen attribute is a legacy way of allowing an iframe to enter fullscreen mode.
<iframe src="page.html" allow="fullscreen"></iframe>
Modern HTML allows fullscreen permission to be expressed through the allow attribute. The separate allowfullscreen attribute remains available for compatibility and is covered on its own attribute reference page.
Common Mistakes
Do not separate multiple feature directives with commas. Permissions Policy directives in the allow attribute are separated with semicolons.
<!-- Correct -->
<iframe src="page.html" allow="camera; microphone; fullscreen"></iframe>
Do not assume that adding a feature to allow automatically gives the embedded page unrestricted access to that feature. Browser permissions, higher-level policies, the iframe's origin, and other security requirements can still prevent access.
Do not assume every Permissions Policy feature has identical browser support. Support should be checked for the particular feature being used.
Browser Support
Baseline: Widely available indicates a feature has been supported by core browsers for at least 30 months. At this stage, the feature is considered stable and safe for most websites to use without needing to worry about compatibility issues or fallbacks, as it is supported by the vast majority of users' devices and browser versions.
The allow attribute on the <iframe> element is widely supported in current core browsers. Support for individual Permissions Policy directives can differ from support for the allow attribute itself.
Checking Browser Support
For current browser compatibility information, visit Can I Use? . Search for the HTML element or attribute you want to check. You can also narrow your search by entering an element name and attribute name separated by a colon. Search results can include related HTML features, element attributes, input types, APIs, and other technologies, so select the result that most closely matches the feature you are checking.
Try the allow Attribute
The example uses the allow attribute on an iframe. Edit the attribute to see how multiple Permissions Policy directives are written and separated.
Summary
The HTML allow attribute specifies a Permissions Policy for an <iframe>. Its value contains one or more feature directives, which are separated by semicolons. The attribute controls whether embedded content is permitted to use features such as the camera, microphone, or fullscreen capability, but browser permissions and other policies can impose additional restrictions.
