Categories

All tools384Text & String Utilities43JSON & Format Converters62Cryptography & Encoding25Color Tools38Developer Utilities35Image Tools17Calculators & Converters65SEO & Metadata Tools22PDF Tools54Keyboard & Typing Tools22Drawing & Creative Tools1

CSP Header Generator

  1. Tools
  2. /Developer Utilities
  3. /CSP Header Generator
Output

Output will appear here

Click in the output to select all text

Related tools

Featured

Nginx Reverse Proxy Config Generator

Generate an Nginx server block for reverse-proxying to a local app, with optional SSL and www redirect.

Nginx config generatorNginx reverse proxy
metaFeatured

SEO Meta Tag Generator

Generate standard HTML meta tags, title, description, canonical, and robots tags.

Meta tagsSeo generator

Canonical URL & Rel Tag Generator

Generate rel="canonical" and rel="alternate" language tags to prevent duplicate content.

Canonical urlRel canonical

This CSP Header Generator builds a Content-Security-Policy value from separate fields for each common directive — default-src, script-src, style-src, img-src, connect-src, font-src, frame-src, and object-src — so you can restrict what a page is allowed to load without hand-assembling the semicolon-separated syntax. Fill in the source lists that apply (e.g. 'self', specific domains, data:), leave the rest blank to skip them, and get both the HTTP header form and the equivalent <meta> tag. A strict CSP is one of the more effective mitigations against XSS, and getting the syntax right the first time avoids a frustrating trial-and-error debugging cycle in the browser console. Everything runs locally in your browser. Scroll down to build your policy.

Features

  • ✓Per-directive source list fields for the most common CSP directives
  • ✓Outputs both the HTTP header and equivalent <meta> tag
  • ✓Skips empty directives automatically
  • ✓One-click copy
  • ✓Runs entirely client-side

Why use this csp header generator?

  • Avoids common CSP syntax mistakes
  • Faster than writing the policy string by hand
  • Fully private — nothing is uploaded
  • Free with unlimited use

Frequently asked questions

What does default-src do?

It's the fallback source list used for any directive you don't set explicitly (like media-src or worker-src), so it's usually the most restrictive baseline, e.g. 'self'.

Why include object-src 'none'?

Disabling <object>, <embed>, and <applet> elements closes off a common legacy vector for loading executable plugin content, and is recommended by most CSP guides even in an otherwise permissive policy.

Can I set this as an HTTP header instead of a meta tag?

Yes, the generated header line can be set directly by your server or reverse proxy (e.g. an Nginx add_header directive) — that's generally preferred over the meta tag, which can't cover frame-ancestors or report-uri.

What does 'unsafe-inline' mean and should I use it?

It allows inline <script>/<style> blocks and attributes to run, which weakens XSS protection — prefer nonces or hashes where possible, but it's commonly needed for style-src on many existing sites.

Does this test my CSP for me?

No, this tool only builds the policy string; test it against your actual site in a browser's console/report-only mode before enforcing it in production.