Private, browser-local utility
Content Security Policy Generator
Build a bounded defensive CSP header from explicit directives without scanning or changing a site.
Loading local tool…
Warnings
Selected directives
Defensive scope and source policy
V1 supports default, script, style, image, font, connection, frame, object, base URI, form action, and frame-ancestor directives plus upgrade-insecure-requests. Source fields accept a bounded set of keywords and schemes or explicit HTTPS origins. Duplicate values are removed. 'none' cannot be mixed.
Wildcard, unsafe-inline, and unsafe-eval values receive explicit warnings. CRLF and controls are rejected. Runtime nonces are not generated because secure nonce values generally need unique server-side generation per response; static nonce/hash generation is outside this tool. Nothing is scanned, requested, executed, reported, deployed, or presented as a security guarantee.