Capabilities
Published
Capabilities are the device and platform APIs that let a PWA do what native apps do — read and write local files, share content, reach hardware, accelerate graphics, and take payments. Most are gated behind a secure context, a user gesture, and an explicit permission, and support varies by engine.
Each entry explains what an API does, its permission and security model, where it is supported, and the fallback when it is not.
In this section
Section titled “In this section”File System Access APIshowOpenFilePicker / showSaveFilePicker / showDirectoryPicker, file handles, permissions, and the Safari/Firefox fallback.
Web Share APIInvoke the native OS share sheet with navigator.share() to share URLs, text, and files.
Payment Request APIBrowser-mediated checkout: native payment sheet, digital wallets, and the canMakePayment() check.
Geolocation APIAccess the user's position with explicit permission. getCurrentPosition, watchPosition, and the permission model.
Async Clipboard APIRead and write the system clipboard. Permission model, rich content, and the execCommand fallback.
Web Bluetooth APIConnect to BLE devices via a browser device picker. WICG spec, Chromium-only, GATT service model.
Screen Wake Lock APIPrevent the screen from dimming. Automatic release on page hide and the re-acquire pattern.
WebCodecsLow-level, hardware-accelerated encoding and decoding with VideoEncoder, VideoDecoder, AudioEncoder, and AudioDecoder.
WebRTCRTCPeerConnection, MediaStreamTrack, and RTCDataChannel for peer-to-peer audio, video, and data — plus getUserMedia and signaling.
Idle Detection APIIdleDetector reports user and screen idle state. Permission model, 60-second threshold floor, and why Firefox/Safari don't implement it.
Contact Picker API: letting users share selected contacts, not the whole address bookHow the Contact Picker API's navigator.contacts.select() lets a user pick specific contacts and choose which fields to share with a site, why it requires a secure context and a user gesture, and why MDN marks it experimental and not Baseline.
Credential Management APInavigator.credentials lets a site create, store, and retrieve sign-in credentials: the four credential types, the mediation modes, and the browser gaps.
Digital Goods API (Play Billing in TWAs)The Digital Goods API lets a PWA running in a Trusted Web Activity query SKUs and purchases through Google Play Billing, alongside the Payment Request API.
Document Picture-in-Picture: always-on-top windowHow the Document Picture-in-Picture API opens an always-on-top HTML window, its requestWindow() options, feature detection, and Chrome/Firefox browser support.
EyeDropper API: sampling on-screen colorsHow the EyeDropper() constructor and open() method let a page sample a pixel's color anywhere on screen for a custom color picker, why open() requires a user gesture, and the desktop-only, Chromium-only support starting at Chrome and Edge 95.
Local Font Access API: enumerating the fonts installed on a deviceHow window.queryLocalFonts() lets a page enumerate locally installed fonts as FontData objects, the local-fonts permission it requires, why it does not need to return every font, and where it ships.
Local Network Access: a local-request promptHow Chrome shows a Local Network Access permission prompt before a public page can reach a device on the local network, replacing silent preflight-only checks.
Media Session APIHow navigator.mediaSession sets metadata and action handlers for OS-level media controls, with Chrome, Firefox, and Safari support versions.
Navigation APIHow window.navigation and the navigate event let single-page apps intercept and control browser navigations, with Chrome, Firefox, and Safari support versions.
Manifest protocol_handlers: registering a PWA for custom URL schemesHow the manifest's protocol_handlers member registers an installed PWA to handle clicks on a given URL scheme, the web+ naming rule for custom schemes, and the %s placeholder that carries the clicked URL into your app.
Screen Capture API (getDisplayMedia)getDisplayMedia() lets a page prompt the user to capture a screen, window, or tab as a MediaStream, for recording locally or sending over WebRTC.
Generic Sensor APIThe Generic Sensor API exposes device sensors like Accelerometer and Gyroscope through common interfaces, behind a secure-context and Permissions API check.
Storage Buckets API: named partitionsHow navigator.storageBuckets creates separately named storage buckets, how Chrome exposes IndexedDB inside them, and the history of the durability option.
VirtualKeyboard APIHow the VirtualKeyboard API lets a page opt out of automatic viewport resizing and read the on-screen keyboard's geometry, with Chrome/Firefox/Safari support.
WebHID API: navigator.hid device access from the webPair a HID device with navigator.hid.requestDevice(), handle connect and disconnect events, and meet the secure-context and activation rules.
Web Locks API: exclusive and shared named locksHow navigator.locks.request() grants exclusive or shared named locks to coordinate work, its storage-bucket scoping, and its secure-context restriction.
Web NFC: reading and writing NFC tags from the webHow NDEFReader.scan() and write() exchange NDEF messages with NFC tags, the spec's secure-context and visible-top-level-document requirements, the "nfc" permission prompt, and the current non-Baseline browser support starting at Chrome for Android 89.
Web Serial API: navigator.serial device accessHow navigator.serial.requestPort() and getPorts() grant page access to a serial port, which browsers support it, and how to feature-detect it with a fallback.
WebUSB API: connecting to non-standard USB devices from the webHow navigator.usb.requestDevice() pairs with USB devices outside the standard device classes, the transient-activation and secure-context requirements, the permission/chooser model, and the optional landing-page mechanism.
WebAuthn and passkeysHow the Web Authentication API and passkeys give a PWA phishing-resistant, passwordless sign-in — credential creation and assertion, discoverable credentials, platform vs roaming authenticators, and cross-device sync.
WebGPU: GPU rendering and compute in the browserHow navigator.gpu.requestAdapter()/requestDevice() expose the GPU for rendering and compute via WGSL, current Chrome/Firefox/Safari support, and the WebGL2 fallback path.
WebTransport: HTTP/3 streams and datagramsSend data over HTTP/3 with reliable streams and unreliable datagrams, how to detect support, and where Chrome, Edge, Firefox and Safari stand.
Window Management API: placing windows across multiple screensHow window.screen.isExtended and Window.getScreenDetails() expose multi-screen layout details, the window-management permission prompt, the secure-context requirement, and today's Chromium-only support per MDN.
← Back to the Reference overview.