Code tool

Security HTTP Response Header Generator

Enter your own HSTS, CSP, X-Frame-Options, Referrer-Policy and Permissions-Policy values. Fields start empty; only populated fields are included.

In-browser processingNo account requiredPrivacy details ↗

Enter your own HSTS, CSP, X-Frame-Options, Referrer-Policy and Permissions-Policy values. Fields start empty; only populated fields are included.

Leave a field empty to omit that header. Enter a single line per field.

Enter values to build header text.

The builder trims surrounding spaces and joins each header name with your value. It does not choose directives, assess security or compliance, or configure a server.

A QUICK WALKTHROUGH

How to use this tool

  1. Enter your chosen directives or value for each header.
  2. Generate and review the header text.
  3. Copy the text for your own review.

User-configured text

The builder trims surrounding spaces and joins each header name with your value. It does not choose directives, assess security or compliance, or configure a server.

GOOD TO KNOW

Common questions

Does it provide a recommended policy?

No. All values are entered by you; the tool does not supply a default policy.

Where are values processed?

Values stay in this browser. No request or deployment is performed.