CSP Generator
Build a Content-Security-Policy HTTP header or meta tag. Choose a strict or relaxed preset, toggle the directives you need, and copy a ready-to-use policy.
Category: Security & Privacy
About this tool
What Is CSP Generator? The CSP Generator builds a Content-Security-Policy header or meta tag that tells browsers which sources your page may load. Start from a strict or a relaxed preset, toggle the directives you need, and copy a syntactically valid policy. How It Works Each directive — default-src, script-src, style-src, img-src, connect-src, font-src, frame-src, object-src, base-uri, form-action — collects the sources you choose (grounded on 'self, plus optional nonce/hash for inline scripts), and the generator joins directives with semicolons into a valid policy, exposed as a header value or meta tag. Worked Example The Strict preset produces a policy like default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline' when inline script and style sources are enabled — the exact list depends on the directives you activate. Common Use Cases harden sites against XSS and data-injection attacks meet OWASP CSP recommendations during design build a report-only policy before enforcing Important Notes nonce or hash require server-side templating to stay safe test in report-only mode before enforcing CSP complements, and does not replace, HTTPS and sanitization Related Tools Meta Tag Generator — build SEO meta tags. Open Graph Generator — generate Open Graph tags. Robots.txt Generator — create robots.txt rules. Sitemap Generator — generate XML sitemaps. Redir