Output will appear here
Click in the output to select all text
Output will appear here
Click in the output to select all text
Generate an Nginx server block for reverse-proxying to a local app, with optional SSL and www redirect.
Generate standard HTML meta tags, title, description, canonical, and robots tags.
Generate rel="canonical" and rel="alternate" language tags to prevent duplicate content.
This CSP Header Generator builds a Content-Security-Policy value from separate fields for each common directive — default-src, script-src, style-src, img-src, connect-src, font-src, frame-src, and object-src — so you can restrict what a page is allowed to load without hand-assembling the semicolon-separated syntax. Fill in the source lists that apply (e.g. 'self', specific domains, data:), leave the rest blank to skip them, and get both the HTTP header form and the equivalent <meta> tag. A strict CSP is one of the more effective mitigations against XSS, and getting the syntax right the first time avoids a frustrating trial-and-error debugging cycle in the browser console. Everything runs locally in your browser. Scroll down to build your policy.
It's the fallback source list used for any directive you don't set explicitly (like media-src or worker-src), so it's usually the most restrictive baseline, e.g. 'self'.
Disabling <object>, <embed>, and <applet> elements closes off a common legacy vector for loading executable plugin content, and is recommended by most CSP guides even in an otherwise permissive policy.
Yes, the generated header line can be set directly by your server or reverse proxy (e.g. an Nginx add_header directive) — that's generally preferred over the meta tag, which can't cover frame-ancestors or report-uri.
It allows inline <script>/<style> blocks and attributes to run, which weakens XSS protection — prefer nonces or hashes where possible, but it's commonly needed for style-src on many existing sites.
No, this tool only builds the policy string; test it against your actual site in a browser's console/report-only mode before enforcing it in production.