CSP Generator
Choose which CSP directives to include, set their source expressions, and create an HTTP response header draft locally. Start with Report-Only and compare the policy against resources your site actually needs.
CSP directives
Enable directives and enter space-separated source expressions. Sources are not checked against the resources your site actually uses.
Examples: 'self' https://cdn.example.com
Examples: 'self' https://cdn.example.com
Examples: 'self' https://cdn.example.com
Examples: 'self' https://cdn.example.com
Examples: 'self' https://cdn.example.com
Examples: 'self' https://cdn.example.com
Examples: 'self' https://cdn.example.com
Examples: 'self' https://cdn.example.com
Examples: 'self' https://cdn.example.com
Examples: 'self' https://cdn.example.com
Examples: 'self' https://cdn.example.com
Examples: 'self' https://cdn.example.com
Avoid 'unsafe-inline' and 'unsafe-eval' when possible. This creates a header draft; it does not inspect your site or guarantee protection. Test with Report-Only before enforcement.
Enable directives and enter space-separated source expressions. Sources are not checked against the resources your site actually uses.
A QUICK WALKTHROUGH
How to use this tool
- Enable the directives you need and edit their space-separated source expressions.
- Choose Report-Only while testing, then select Generate header.
- Review the single-line header and test it on your own site before using enforcement.
Twelve common CSP directives
Configure default-src, script-src, style-src, img-src, font-src, connect-src, media-src, object-src, frame-src, frame-ancestors, base-uri, and form-action. Each directive has an editable source list and can be omitted.
Accepted source expressions
The tool accepts common quoted keywords such as 'self', 'none', 'unsafe-inline', and 'unsafe-eval', nonce and hash expressions, scheme sources such as https: and data:, and host sources. It formats the text but is not a full CSP parser or policy analyzer.
Review before enforcement
The defaults are a starting draft, not a guarantee of a secure or working configuration. Compare sources with the scripts, styles, images, embeds, and network requests your site needs. Test with Content-Security-Policy-Report-Only first; avoid unsafe-inline and unsafe-eval unless you understand the tradeoffs. This tool does not apply headers or upload site data.
GOOD TO KNOW
Common questions
Does this install the policy on my website?
No. It creates a text response-header draft for you to review and add to your own server or hosting configuration.
What is Report-Only for?
The Content-Security-Policy-Report-Only header lets browsers report policy violations without blocking the matching resources. Check browser reports and site behavior before switching to enforcement.
Does it check every CSP rule?
No. It checks the shape of the entered source expressions and prevents directive separators inside them, but it does not implement the full CSP grammar, inspect your site, or test browser behavior.
Are the defaults safe for every site?
No. A policy that is too strict can break required features, while a permissive policy can provide little protection. Review actual site resources and test in Report-Only mode.