X-Permitted-Cross-Domain-Policies

Response headers

Controls whether legacy plug-ins may load data from this origin.

On the wireX-Permitted-Cross-Domain-Policies: …
CategoryResponse headers

Headers the server attaches when it answers.

How to read this

  • The first digit of a status code carries the meaning: 4 means the request, 5 means the server.
  • 404 means "not there"; 403 means "there, but not for you". Swapping them makes debugging slower.
  • Header names are case-insensitive — Content-Type and content-type are the same header.
  • Caching and CORS problems usually come down to one header line, visible in the browser’s network tab.

Frequently asked questions

Q. What does HTTP X-Permitted-Cross-Domain-Policies mean?

Controls whether legacy plug-ins may load data from this origin.

Q. What does X-Permitted-Cross-Domain-Policies look like on the wire?

It travels as X-Permitted-Cross-Domain-Policies: …

Q. Where does X-Permitted-Cross-Domain-Policies appear?

In response headers.

Q. What group does X-Permitted-Cross-Domain-Policies belong to?

The response headers group; the rest of that group is listed further down.

Same group

Reference docs