CSP Header Generator
BetaBuild a Content-Security-Policy header from presets and per-directive source lists, with a matching meta tag and warnings for unsafe sources.
- Free, no sign-up
- REST + MCP
- Updated
- Reviewed by Olgun Ozoktas
Runs in your browser · nothing is uploaded
Directives
0 of 12 onStart with a preset, or switch on a directive and pick its sources.
default-srcFallback for fetch directives that are not setscript-srcJavaScript sourcesstyle-srcStylesheet sourcesimg-srcImage sourcesfont-srcFont sourcesconnect-srcfetch, XHR, WebSocket and EventSourceframe-srcPages this page may load in framesframe-ancestorsWho may embed this page in a frameobject-src<object> and <embed> contentbase-uriURLs allowed in <base>form-actionWhere forms may submitupgrade-insecure-requestsLoad http:// subresources over https://Report-Only mode
Sends Content-Security-Policy-Report-Only: violations are reported, nothing is blocked.
An https:// URL or a path starting with /. Browsers POST a JSON report there for each violation.
HTTP header
Nothing to copy yet. Pick a preset or switch on a directive.
<meta> tag
The equivalent <meta http-equiv> tag appears here.
frame-ancestors, report-uri and sandbox are ignored in a <meta> tag.
Warnings
Warnings show here as you build the policy.
How to Generate a Content-Security-Policy
-
Start from a preset
Pick Strict, Typical site or With Google Analytics. Each one switches on a set of directives with sources you can edit. You can also start from nothing and switch directives on one at a time. -
Set the sources for each directive
Use the 'self', 'none', https: and data: buttons, or type a host such as cdn.example.com or https://*.example.com and press Add. A source that is not valid CSP syntax is refused with the reason, and it never reaches the header. -
Decide on reporting
Turn on Report-Only mode to send Content-Security-Policy-Report-Only, which reports violations without blocking anything. Add a report-uri URL if you collect those reports. -
Read the warnings and copy the result
Check the warnings list, then copy the HTTP header for your server or CDN config. Copy the <meta> tag only if you cannot set headers; it leaves out the directives a <meta> tag cannot carry.
Common Use Cases
Adding a first CSP to an existing site
Allowing Google Analytics or Tag Manager
Blocking clickjacking
Reviewing a policy someone else wrote
Why Use a CSP Header Generator?
The CSP Header Generator builds a Content-Security-Policy from a list of directives and sources and gives you three things: the HTTP header line, an equivalent <meta http-equiv> tag, and a list of warnings about the policy. Keywords such as 'self' and 'none' are quoted for you, directives come out in a fixed order, and a source that is not valid CSP syntax (a URL with a missing colon, a host with a space, a quote or an angle bracket) is refused before it can reach the header. The policy is built in your browser and nothing you enter is uploaded.
The warnings check what the policy text itself says: 'unsafe-inline', 'unsafe-eval', *, data: or a bare https: in the script sources; 'none' mixed with other sources; plain http:// hosts; and a missing default-src, object-src 'none', base-uri or frame-ancestors. It does not fetch your site, so to see the header a server really sends, use the Security Headers Analyzer. For cookies set by the same response, the Cookie Analyzer checks the Secure, HttpOnly and SameSite flags.
A CSP is one layer of defence against cross-site scripting, not a replacement for escaping output. It pairs well with checking the links you publish in the URL Safety Checker and with the other head tags a page needs, which the Meta Tag Generator writes.
How it compares
You can write a CSP by hand in a text editor, and for a two-directive policy that is often quickest. The trouble starts with the details the browser is strict about: keywords need single quotes, 'none' is ignored as soon as anything else shares its list, and frame-ancestors, report-uri and sandbox are silently ignored in a <meta> tag. A typo in a handwritten policy is not an error message, it is a source that quietly does not match. This generator checks the syntax of every source as you add it and writes the <meta> variant without the directives it cannot carry.
Browser developer tools are the right place for the next step: once a policy is live, the console lists every blocked resource with the directive that blocked it. Framework and server middleware that inject a per-request nonce are the right answer for inline scripts on dynamic sites, because a nonce must change on every response, which no static generator can do for you. Use this page to design and sanity-check the policy, then let your server send it.
Tips for a Working CSP
- Deploy in Report-Only mode first. An enforced policy that misses one CDN host will break that part of the site for every visitor.
- Set object-src 'none' and base-uri 'self' (or 'none') explicitly. object-src would otherwise inherit a looser default-src, and base-uri does not inherit from default-src at all.
- default-src only covers fetch directives. frame-ancestors, form-action and base-uri do not fall back to it, so set them explicitly.
- Prefer nonces or hashes to 'unsafe-inline' for scripts. In CSP Level 2 and later, a browser ignores 'unsafe-inline' when a nonce or hash is present in the same directive.
- After you deploy, test the live response with the Security Headers Analyzer to confirm the header your server really sends.