Content Security Policy Generator

Build a Content-Security-Policy header directive by directive, with report-only mode and ready-to-paste server snippets.

Add the services your site uses, then adjust the sources. Separate sources with spaces, for example 'self' https://cdn.example.com.

Your policy


Content Security Policy Generator

A Content Security Policy (CSP) tells browsers which sources a page may load scripts, styles, images and other resources from. A good CSP is one of the strongest defences against cross-site scripting (XSS). This generator walks through each directive, warns about unsafe choices like 'unsafe-inline', and outputs the header with snippets for Apache, nginx and an HTML meta tag.

How to use Content Security Policy Generator

  1. Start from default-src 'self' and add the domains your site loads from (analytics, fonts, CDNs, ads).
  2. Fill in the directives for scripts, styles, images, fonts, frames and connections.
  3. Tick Report only to test without blocking anything, and add a report URL if you have one.
  4. Copy the header or server snippet, deploy it, and watch the browser console for violations before enforcing it.

When it comes in handy

  • Adding a first CSP to a website or web app.
  • Fixing a "missing Content-Security-Policy" finding from a security scan.
  • Tightening an existing policy.

Frequently asked questions

Why start with report-only?
A strict policy can block your own scripts, analytics or fonts and break the site. Report-only mode lists what would be blocked without blocking it, so you can fix the policy first.
Can I use a meta tag instead of a header?
Yes, for most directives. frame-ancestors, report-uri and sandbox only work in the HTTP header.
How do I check the result?
Use the Security Headers Checker on your live site.

Choose which cookies SEOpeck may use. You can change this at any time from "Cookie settings" at the bottom of every page.