# Csp Generate — MCP tool `findutils:csp_generate`

Build a Content-Security-Policy header from a preset (strict, typical, google-analytics) and/or your own directives, and get the header line, an equivalent <meta http-equiv> tag, and warnings such as script-src allowing 'unsafe-inline', 'unsafe-eval', * or data:, a missing object-src 'none', base-uri or frame-ancestors. Bare keywords like self are quoted for you; invalid sources are rejected with the directive named. Supports Report-Only with a report-uri. Pure computation: it checks the policy text, not a live site.

- Category: security
- MCP server: https://mcp.findutils.com/ (Streamable HTTP, no API keys, 120 req/min per IP)
- REST endpoint: POST https://api.findutils.com/api/tools/csp-generate/execute (no API keys, 60 req/min per IP)
- Reference page: https://findutils.com/mcp/csp-generate/
- Same tool on the other surface: https://findutils.com/api/csp-generate/

## Connect

```bash
claude mcp add findutils --transport http https://mcp.findutils.com/
```

Claude Desktop (`claude_desktop_config.json`):

```json
{
  "mcpServers": {
    "findutils": {
      "url": "https://mcp.findutils.com/"
    }
  }
}
```

## Call the tool (verified example)

```bash
curl -X POST https://mcp.findutils.com/ \
  -H "Content-Type: application/json" \
  -d '{
    "jsonrpc": "2.0",
    "id": 1,
    "method": "tools/call",
    "params": {
      "name": "csp_generate",
      "arguments": {
        "preset": "typical",
        "directives": {
          "script-src": [
            "self",
            "https://cdn.example.com"
          ]
        }
      }
    }
  }'
```

## Input schema

| Argument | Type | Required | Description |
|---|---|---|---|
| `preset` | string (strict \| typical \| google-analytics) | no | Starting policy: "strict", "typical" or "google-analytics". Your directives replace the preset's for the same directive. |
| `directives` | object | no | Directive name → list of sources (or a space-separated string), e.g. {"script-src": ["self", "https://cdn.example.com"]}. An empty list removes that directive. |
| `upgrade_insecure_requests` | boolean | no | Add upgrade-insecure-requests. Default: true. Default: `true`. |
| `report_only` | boolean | no | Emit Content-Security-Policy-Report-Only instead (reports, does not block). Default: false. Default: `false`. |
| `report_uri` | string | no | Where browsers send violation reports (report-uri). |

Example arguments (verified):

```json
{
  "preset": "typical",
  "directives": {
    "script-src": [
      "self",
      "https://cdn.example.com"
    ]
  }
}
```

## Also a REST endpoint

```bash
curl -X POST https://api.findutils.com/api/tools/csp-generate/execute \
  -H "Content-Type: application/json" \
  -d '{
    "preset": "typical",
    "directives": {
      "script-src": [
        "self",
        "https://cdn.example.com"
      ]
    }
  }'

# Parameter schema
curl https://api.findutils.com/api/tools/csp-generate
```

Full REST reference: https://findutils.com/api/csp-generate/ · OpenAPI 3.1 spec: https://findutils.com/api/openapi.json

---
Full catalog: POST https://mcp.findutils.com/ with method `tools/list` · https://findutils.com/mcp/ · https://findutils.com/llms.txt
