An iframe allow attribute declares a permissions policy for selected features in the embedded document.
HTML iframe allow: grant an embedded page only needed capabilities
Use it in a concrete workflow
A trusted local scanning tool is embedded in a parcel intake page and needs camera access. The parent permits that capability for the frame. The browser may still ask the user for permission, and the framed page must be served by a route the team controls. The allow list is not a guarantee that camera capture works, nor a replacement for server authorization of uploaded scans.
<iframe src="/tools/parcel-scan" title="Parcel barcode scanner" width="480" height="360"
allow="camera"></iframe>
<p>If the scanner is unavailable, enter the parcel code in the intake form.</p>Behavior and ownership
This example assumes the scanner is a trusted part of the same application. An untrusted scanner needs a separate origin and a carefully designed sandbox and permissions policy. Review the exact trust boundary before embedding one.
Performance and maintenance
Camera access and embedded scripts have device and memory costs. Defer loading when scanning is optional, and measure the framed tool separately from the parent page.
Common Mistakes
- Do not treat allow as automatic user consent.
- Do not embed untrusted code at a trusted application route.
- Do not make the camera the only way to enter a parcel code.
Connected lessons
- HTML iframe sandbox: isolate an embedded preview and name its purpose
- HTML iframe srcdoc: isolate a small preview deliberately
- HTML labels: bind each control to a durable accessible name
Continue with HTML iframe referrerpolicy: limit parent-page details sent to an embed.
