Why does an embedded microphone recorder fail when its own page works?
Opening a recorder directly and embedding it on another origin are different permission situations. The parent must permit microphone use by the embedded origin; the user's permission alone does not override a restrictive Permissions Policy.
Separate the three checks
- Context: the recorder and its ancestors must meet secure-context requirements.
- Delegation: inspect the parent's microphone Permissions Policy and the iframe's
allowpolicy. A parent restriction cannot be loosened by a child. - Consent: delegation does not itself grant the user's microphone permission.
The microphone directive defaults to self. For a cross-origin recorder, the embedding configuration therefore matters. A blocked microphone policy can produce NotAllowedError.
If a trusted recorder works directly but fails only when embedded, ask the site maintainer to review the embedding policy before repeatedly resetting your microphone. Do not broadly enable every origin.
Sources and scope
MDN: microphone Permissions Policy; MDN: getUserMedia.
Documentation synthesis reviewed September 28, 2026; no hands-on test or universal browser compatibility claim. This guide does not embed a recorder.