Trusted Server never ships a permission policy. The builder
of a deployment chooses the permissions.yaml baked into their
compiled image, the operator of that image can overlay another, and the
visitor's own signals decide the rest at runtime. This page reads such a
policy document, written in the IAB Tech Lab Privacy Taxonomy's own
vocabulary, and answers the question a policy owner actually has: for a
visitor in a given place, with given consent signals, which Data Uses are
set? Everything runs in this browser tab. Nothing is sent anywhere.
The samples in the repository's config/permissions directory. No policy ever ships with Trusted Server: the builder bakes their chosen file into the image, the operator can overlay another, and choosing is always explicit.
Paste any permissions.yaml. The same
validation the server applies at startup runs here, so a file this page
rejects is a file the server rejects.
Loads a published policy document, for example one hosted by a trade body. The host must allow cross-origin requests, or be the same host serving this page.
To decode a real TC string, or build one purpose by purpose, use the IAB GPP encoder and decoder, which also handles GPP and US state strings, then paste the result here.
Future signal kinds get their own tab here, so the input stays uncluttered as the model grows.
| Data Use (IAB Privacy Taxonomy) | Policy baseline | For this visitor | Why |
|---|