Content Security Policy Generator
Build a CSP header from common presets, with each directive explained.
To generate a Content Security Policy, choose a preset and each directive is explained alongside the header. Report-only mode is on by default because an enforced CSP that blocks your own scripts takes a site down immediately — deploy in report-only, check the console, then enforce.
Runs in your browser- Privacy
- Runs entirely in your browser — nothing is uploaded
- Cost
- Free, unlimited, no sign-up
Frequently asked questions
Why avoid unsafe-inline for scripts?
What is frame-ancestors for?
How to use the content security policy generator
- 1Choose the policy preset.
- 2Turn "Report-only mode" on or off as needed.
- 3The result appears immediately — copy or download it.
Embed this tool
Put the working content security policy generator on your own site. It runs in your visitors' browsers exactly as it does here — free, no account, nothing uploaded.
Share this tool
Related tools
HTTP Security Header AnalyserPaste response headers and get a security grade, with what is missing and why it matters.MIME Type LookupFind the correct MIME type for any file extension, and vice versa.HTML Entity Encoder & DecoderConvert characters to HTML entities and back — escape markup safely for display.HTTP Header CheckerFollow every redirect, grade the security headers and read the cookie and caching settings.HTTP Status Code ReferenceLook up what any HTTP status code means and when to use it.URL ParserBreak a URL into protocol, host, path, query parameters and fragment.
Last updated
More developer tools