---
title: "CSP Header Generator"
description: "Build a Content-Security-Policy header from presets and per-directive source lists, with a matching meta tag and warnings for unsafe sources."
url: https://findutils.com/security/csp-header-generator/
category: security
---

# CSP Header Generator

Build a Content-Security-Policy header from presets and per-directive source lists, with a matching meta tag and warnings for unsafe sources.

**Use this tool:** [CSP Header Generator](https://findutils.com/security/csp-header-generator/)

## Programmatic access

- REST id `csp-generate`: POST https://api.findutils.com/api/tools/csp-generate/execute (reference: https://findutils.com/api/csp-generate/)
- MCP tool `csp_generate` on https://mcp.findutils.com (reference: https://findutils.com/mcp/csp-generate/)

## Why Use a CSP Header Generator?

A Content-Security-Policy tells the browser which origins may supply scripts, styles, images, frames and connections for a page, so an injected script from an unlisted source is refused. Writing one by hand is error-prone: keywords must be single-quoted, 'none' cannot share a list, and some directives do nothing in a &lt;meta&gt; tag. This generator builds the policy from switches and source lists, quotes keywords for you, rejects malformed sources before they reach the header, and flags the choices that weaken the policy.

## Tips for a Working CSP

- Deploy in Report-Only mode first. An enforced policy that misses one CDN host will break that part of the site for every visitor.
- Set object-src 'none' and base-uri 'self' (or 'none') explicitly. object-src would otherwise inherit a looser default-src, and base-uri does not inherit from default-src at all.
- default-src only covers fetch directives. frame-ancestors, form-action and base-uri do not fall back to it, so set them explicitly.
- Prefer nonces or hashes to 'unsafe-inline' for scripts. In CSP Level 2 and later, a browser ignores 'unsafe-inline' when a nonce or hash is present in the same directive.
- After you deploy, test the live response with the Security Headers Analyzer to confirm the header your server really sends.

## Frequently Asked Questions

### What does a CSP header generator do?

It turns a set of directives (default-src, script-src, img-src and so on) and their allowed sources into a valid Content-Security-Policy header line. This one also writes the matching <meta http-equiv> tag, quotes keywords such as 'self' for you, refuses sources that are not valid CSP syntax, and lists warnings for choices that weaken the policy, such as 'unsafe-inline' in script-src.

### Should I use the HTTP header or the <meta> tag?

Use the HTTP header whenever you can set one. A policy delivered in a <meta http-equiv="Content-Security-Policy"> tag ignores frame-ancestors, report-uri and sandbox, cannot be Report-Only, and only applies to content that loads after the tag is parsed. The generator leaves those directives out of the <meta> tag and says which ones it dropped.

### Why does frame-ancestors not appear in the meta tag?

The CSP specification says browsers must ignore frame-ancestors in a policy delivered by a <meta> element. It only takes effect in the Content-Security-Policy HTTP header, which is why the generator keeps it in the header and removes it from the tag.

### Is 'unsafe-inline' always dangerous?

In script-src it allows any inline script to run, including one an attacker injects, which removes most of what a CSP protects against. In CSP Level 2 and later, a browser ignores 'unsafe-inline' when the same directive also contains a nonce or a hash, which lets you keep it as a fallback for older browsers; the generator does not warn in that case. In style-src the risk is lower, and many sites allow it there.

### What is Report-Only mode?

It sends the policy as Content-Security-Policy-Report-Only instead of Content-Security-Policy. The browser checks every resource against the policy and reports violations, but blocks nothing. It is the safe way to trial a policy on a live site. It only works as a header, and browsers ignore upgrade-insecure-requests in it, so the generator leaves that directive out.

### Should I use report-uri or report-to?

CSP Level 3 deprecates report-uri in favour of report-to, which names an endpoint declared in a separate Reporting-Endpoints header. Browser support for report-to has differed, so many sites send both. This generator writes report-uri, which browsers still honour; if you also use report-to, add it and its Reporting-Endpoints header yourself.

### What does each preset contain?

Strict sets default-src 'none', allows scripts, styles, images, fonts and connections only from your own origin, and sets object-src 'none', base-uri 'none', form-action 'self' and frame-ancestors 'none'. Typical site starts from default-src 'self', allows inline styles, images from any https: host or data: URLs, fonts from data: URLs, and lets your own origin frame the page. With Google Analytics adds Google's Tag Manager and Analytics host patterns to the Typical policy.

### Why was my source rejected?

Each source must be a keyword ('self', 'none', 'unsafe-inline' and so on), a nonce or hash, a scheme such as https: or data:, or a host with an optional scheme, a leading *. wildcard, a port and a path. The most common mistakes are a missing colon (https//), a space inside a host, and quotes, commas, semicolons or angle brackets, all of which are refused. A rejected source is never added to the header.

### Does this tool check my live website?

No. It checks the policy you build, not a server. To see the Content-Security-Policy header a site actually sends, along with its other security headers, use the Security Headers Analyzer.

### Is anything I enter sent anywhere?

Not from this page. The policy is built by code running in your browser and nothing you type is uploaded. The same generator is also available through the FindUtils REST API and as the csp_generate MCP tool; a call there sends your directives to FindUtils over TLS to build the policy, and they are not stored or logged.

## Related Tools

- [Security Headers Analyzer](https://findutils.com/network/security-headers-analyzer/)
- [Cookie Analyzer](https://findutils.com/security/cookie-analyzer/)
- [URL Safety Checker](https://findutils.com/security/url-safety-checker/)
- [Data Sanitizer](https://findutils.com/security/data-sanitizer/)
- [Password Generator](https://findutils.com/security/password-generator/)
