go-supertools
Security & Privacy Tools

CSP Header Generator

Create secure Content Security Policy (CSP) headers for your website.

Runs in your browser Your input never leaves your device.

About this tool

Builds a Content-Security-Policy header line from a few common directives. Fill in default-src, script-src, style-src, img-src and connect-src with source lists such as 'self' or https://cdn.example.com, and the tool joins the filled ones with semicolons as you type. Empty fields are left out, and if everything is empty it outputs default-src 'self'. The tool only assembles text: it does not check that your source values are valid, test your site, or tell you whether the policy is strong enough. Test any policy carefully before you enforce it, because a policy that is too strict can break scripts and styles on your pages. Generation happens in your browser.

How to use it

  1. Leave default-src as 'self' or change it to the sources you trust.
  2. Add source lists for script-src, style-src, img-src and connect-src where you need different rules.
  3. Copy the generated Content-Security-Policy line.
  4. Add it as a response header on your server, then test your pages in the browser console.

Example

Filled directives are joined with semicolons.

Input
default-src: 'self'
script-src: 'self' https://cdn.example.com
Result
Content-Security-Policy: default-src 'self'; script-src 'self' https://cdn.example.com

Common problems

Page breaks after adding the header
A directive such as script-src replaces default-src for scripts, so list every origin you load scripts from. Check the browser console for blocked resources.
Keywords are not accepted
Keywords like 'self' and 'none' must keep their single quotes. Domains and schemes (https:) are written without quotes.
Other directives are missing
This tool covers five directives. Add others such as frame-ancestors or object-src by hand to the generated line.