Developer / Security policy

CSP Generator: Build and Analyse Content Security Policies

Create a Content-Security-Policy header with source lists, nonce and hash placeholders, reporting directives and common presets. Review warnings and copy HTTP, meta, nginx, Apache or static _headers output.

CSP Generator: Build and Analyse Content Security Policies: Builds a policy locally and flags unsafe-inline, unsafe-eval, broad sources, duplicate directives and deployment placeholders. The parser preserves unknown directives and uses the first occurrence of a repeated directive. It analyses one policy at a time and does not load the protected page. Runs 100% locally in your browser with zero server file uploads.

Runs
In your browser
Cost
Free · no sign-up
Availability
Ready to use
Content security policy benchLocal processing

Runs entirely in your browser

Presets replace the current policy. Test with a report-only header first. A nonce placeholder needs server integration; a static header cannot generate a fresh nonce.

Script source tokens

script-src · strict-dynamic needs a valid nonce or hash and overrides host allowlists in supporting browsers.

script-src · Replace nonce and hash placeholders before deployment. Generate a fresh unpredictable nonce for each response.

Meta policies cannot enforce frame-ancestors or sandbox, use report-uri, or deliver a report-only policy. Reporting directives are omitted here.

This is a syntax and risk review, not a security audit. Unknown or malformed source expressions need browser testing. Additional policies are enforced together and cannot relax an earlier policy. The generated _headers file is for static responses; dynamic responses need their own header configuration.

Policy syntax and delivery

W3C Content Security Policy Level 3: https://www.w3.org/TR/CSP3/ . Directives are separated by semicolons and values by whitespace. Meta delivery has fewer capabilities than an HTTP response header.

Nonces, hashes and deployment

MDN Content Security Policy guide: https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/CSP . strict-dynamic transfers trust from a nonce- or hash-authorised script to scripts it loads, overriding host allowlists in supporting browsers. Audit trusted script behaviour and test the final policy.

How to use it

  1. Choose a preset or paste one existing policy.
  2. Enable directives and edit space-separated values; review warnings.
  3. Choose an output format, copy it and test it against your site's resources.

Privacy & limitations

Your policy stays in your browser. No website is contacted.

Related tools

Frequently asked questions

Can I use the nonce placeholder as it is?

No. Generate an unpredictable nonce for each response and put the matching value on trusted scripts. A fixed static header cannot generate a nonce. Replace hash placeholders with the actual hash of the intended content.

What cannot a meta policy do?

It cannot enforce frame-ancestors or sandbox, use report-uri, or deliver a report-only policy. The generated meta output omits reporting directives and must appear early in the document head.

Does report-to create a reporting endpoint?

No. It names a group that needs a separate Reporting-Endpoints response header. report-uri is older; browser support varies. This tool does not send reports.

Are the presets guaranteed to work with my website?

No. Start with report-only HTTP delivery and check the resources your site needs. Existing policies combine with the new one; a second policy cannot relax an earlier restriction. Static _headers delivery does not cover dynamically generated responses.

Free tool · runs in your browser · no account required