Csp Generate API
https://api.findutils.com/api/tools/csp-generate/execute Build a Content-Security-Policy header from a preset (strict, typical, google-analytics) and/or your own directives, and get the header line, an equivalent <meta http-equiv> tag, and warnings such as script-src allowing 'unsafe-inline', 'unsafe-eval', * or data:, a missing object-src 'none', base-uri or frame-ancestors. Bare keywords like self are quoted for you; invalid sources are rejected with the directive named. Supports Report-Only with a report-uri. Pure computation: it checks the policy text, not a live site.
Request body
application/json-
preset
string optional
Starting policy: "strict", "typical" or "google-analytics". Your directives replace the preset's for the same directive. One of
strict · typical · google-analytics. -
directives
object optional
Directive name → list of sources (or a space-separated string), e.g. {"script-src": ["self", "https://cdn.example.com"]}. An empty list removes that directive.
-
upgrade_insecure_requests
boolean optional
Add upgrade-insecure-requests. Default: true. Default
true. -
report_only
boolean optional
Emit Content-Security-Policy-Report-Only instead (reports, does not block). Default: false. Default
false. -
report_uri
string optional
Where browsers send violation reports (report-uri).
Example arguments
Verified{
"preset": "typical",
"directives": {
"script-src": [
"self",
"https://cdn.example.com"
]
}
} More Security tools
- Base32 Encode Encode UTF-8 text to RFC 4648 base32 (uppercase, "=" padding).
- Data Sanitizer Sanitize untrusted text and return the cleaned output, a list of changes made, and a risk level.
- Dnpm Configurator Returns the five files of a hardened Docker-based npm wrapper (the ./dnpm bash script, .dnpm/Dockerfile, docker-compose.node.yml…
- Email Header Analyzer Return a structured analysis of raw email headers: sender, recipient, subject, date, message id, the Received hop chain with per-hop…
- Hash Comparison Tool Hash text with MD5, SHA-1, SHA-256, SHA-384, or SHA-512 and compare the hex digest with an expected hash.
- Password Breach Checker Return whether a password appears in known data breaches and how many times, using the Have I Been Pwned k-anonymity range API.