Developer / Security policy
CSP Generator: Build and Analyse Content Security Policies
Create a Content-Security-Policy header with source lists, nonce and hash placeholders, reporting directives and common presets. Review warnings and copy HTTP, meta, nginx, Apache or static _headers output.
CSP Generator: Build and Analyse Content Security Policies: Builds a policy locally and flags unsafe-inline, unsafe-eval, broad sources, duplicate directives and deployment placeholders. The parser preserves unknown directives and uses the first occurrence of a repeated directive. It analyses one policy at a time and does not load the protected page. Runs 100% locally in your browser with zero server file uploads.
- Category
- Developer tools
- Runs
- In your browser
- Cost
- Free · no sign-up
- Availability
- Ready to use
Runs entirely in your browser
Presets replace the current policy. Test with a report-only header first. A nonce placeholder needs server integration; a static header cannot generate a fresh nonce.
script-src · strict-dynamic needs a valid nonce or hash and overrides host allowlists in supporting browsers.
script-src · Replace nonce and hash placeholders before deployment. Generate a fresh unpredictable nonce for each response.
Meta policies cannot enforce frame-ancestors or sandbox, use report-uri, or deliver a report-only policy. Reporting directives are omitted here.
This is a syntax and risk review, not a security audit. Unknown or malformed source expressions need browser testing. Additional policies are enforced together and cannot relax an earlier policy. The generated _headers file is for static responses; dynamic responses need their own header configuration.
Policy syntax and delivery
W3C Content Security Policy Level 3: https://www.w3.org/TR/CSP3/ . Directives are separated by semicolons and values by whitespace. Meta delivery has fewer capabilities than an HTTP response header.
Nonces, hashes and deployment
MDN Content Security Policy guide: https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/CSP . strict-dynamic transfers trust from a nonce- or hash-authorised script to scripts it loads, overriding host allowlists in supporting browsers. Audit trusted script behaviour and test the final policy.
How to use it
- Choose a preset or paste one existing policy.
- Enable directives and edit space-separated values; review warnings.
- Choose an output format, copy it and test it against your site's resources.
Privacy & limitations
Your policy stays in your browser. No website is contacted.
Related tools
Frequently asked questions
Can I use the nonce placeholder as it is?
No. Generate an unpredictable nonce for each response and put the matching value on trusted scripts. A fixed static header cannot generate a nonce. Replace hash placeholders with the actual hash of the intended content.
What cannot a meta policy do?
It cannot enforce frame-ancestors or sandbox, use report-uri, or deliver a report-only policy. The generated meta output omits reporting directives and must appear early in the document head.
Does report-to create a reporting endpoint?
No. It names a group that needs a separate Reporting-Endpoints response header. report-uri is older; browser support varies. This tool does not send reports.
Are the presets guaranteed to work with my website?
No. Start with report-only HTTP delivery and check the resources your site needs. Existing policies combine with the new one; a second policy cannot relax an earlier restriction. Static _headers delivery does not cover dynamically generated responses.
Free tool · runs in your browser · no account required