Private, browser-local utility

Content Security Policy Generator

Build a bounded defensive CSP header from explicit directives without scanning or changing a site.

CSP is one defensive control. Incorrect enforcement can break a site. Start with Report-Only, review violations, and test before deployment.

Header mode

Loading local tool…

Defensive scope and source policy

V1 supports default, script, style, image, font, connection, frame, object, base URI, form action, and frame-ancestor directives plus upgrade-insecure-requests. Source fields accept a bounded set of keywords and schemes or explicit HTTPS origins. Duplicate values are removed. 'none' cannot be mixed.

Wildcard, unsafe-inline, and unsafe-eval values receive explicit warnings. CRLF and controls are rejected. Runtime nonces are not generated because secure nonce values generally need unique server-side generation per response; static nonce/hash generation is outside this tool. Nothing is scanned, requested, executed, reported, deployed, or presented as a security guarantee.