UTILS.
Private by default
🛡

CSP Header Builder

Build a Content-Security-Policy header by filling in common directives.

Your files stay on this device

Files are processed in your browser, never uploaded. The site downloads code and assets to run the tools. No accounts or trackers.

Use Download to save this tool as one HTML file for offline use.

Privacy →
— output appears here —

About this tool

Assemble a Content-Security-Policy header string from common directives prefilled with 'self'; the header is built entirely in your browser.

Frequently asked questions

What does 'self' mean?
The 'self' keyword allows resources only from your own origin (same scheme, host and port), a safe default for most directives.
How do I deploy the header?
Send the generated string as an HTTP response header from your server or CDN, or place it in a <meta http-equiv> tag for static sites.

More tools