CSP Header Generator
Create secure Content Security Policy (CSP) headers for your website.
Runs in your browser Your input never leaves your device.
About this tool
Builds a Content-Security-Policy header line from a few common directives. Fill in default-src, script-src, style-src, img-src and connect-src with source lists such as 'self' or https://cdn.example.com, and the tool joins the filled ones with semicolons as you type. Empty fields are left out, and if everything is empty it outputs default-src 'self'. The tool only assembles text: it does not check that your source values are valid, test your site, or tell you whether the policy is strong enough. Test any policy carefully before you enforce it, because a policy that is too strict can break scripts and styles on your pages. Generation happens in your browser.
How to use it
- Leave default-src as 'self' or change it to the sources you trust.
- Add source lists for script-src, style-src, img-src and connect-src where you need different rules.
- Copy the generated Content-Security-Policy line.
- Add it as a response header on your server, then test your pages in the browser console.
Example
Filled directives are joined with semicolons.
default-src: 'self' script-src: 'self' https://cdn.example.com
Content-Security-Policy: default-src 'self'; script-src 'self' https://cdn.example.com
Common problems
- Page breaks after adding the header
- A directive such as script-src replaces default-src for scripts, so list every origin you load scripts from. Check the browser console for blocked resources.
- Keywords are not accepted
- Keywords like 'self' and 'none' must keep their single quotes. Domains and schemes (https:) are written without quotes.
- Other directives are missing
- This tool covers five directives. Add others such as frame-ancestors or object-src by hand to the generated line.