Content Security Policy Generator
Build a Content-Security-Policy header directive by directive, with report-only mode and ready-to-paste server snippets.
Add the services your site uses, then adjust the sources. Separate sources with spaces, for example 'self' https://cdn.example.com.
Your policy
Content Security Policy Generator
A Content Security Policy (CSP) tells browsers which sources a page may load scripts, styles, images and other resources from. A good CSP is one of the strongest defences against cross-site scripting (XSS). This generator walks through each directive, warns about unsafe choices like 'unsafe-inline', and outputs the header with snippets for Apache, nginx and an HTML meta tag.
How to use Content Security Policy Generator
- Start from default-src 'self' and add the domains your site loads from (analytics, fonts, CDNs, ads).
- Fill in the directives for scripts, styles, images, fonts, frames and connections.
- Tick Report only to test without blocking anything, and add a report URL if you have one.
- Copy the header or server snippet, deploy it, and watch the browser console for violations before enforcing it.
When it comes in handy
- Adding a first CSP to a website or web app.
- Fixing a "missing Content-Security-Policy" finding from a security scan.
- Tightening an existing policy.
Frequently asked questions
- Why start with report-only?
- A strict policy can block your own scripts, analytics or fonts and break the site. Report-only mode lists what would be blocked without blocking it, so you can fix the policy first.
- Can I use a meta tag instead of a header?
- Yes, for most directives. frame-ancestors, report-uri and sandbox only work in the HTTP header.
- How do I check the result?
- Use the Security Headers Checker on your live site.