CSP Header Builder

Compose Content-Security-Policy headers with guided directives

Build Content-Security-Policy headers with guided directives — preview report-only vs enforce modes locally.

Also known as: csp builder · create csp header · content security policy generator · csp policy tool

100% In-Browser & Private — your data never leaves this device
Loading tool...

How to use the CSP Header Builder

  1. Add directives: default-src, script-src, style-src, img-src, connect-src, etc.
  2. Set sources (self, none, nonces, hostnames) using the checklist.
  3. Copy the Content-Security-Policy or Content-Security-Policy-Report-Only header value.

FAQ

Should I start with report-only?
Yes — deploy Content-Security-Policy-Report-Only first, fix violations, then switch to enforcing mode.
Does this scan my live site?
No. You compose policy text locally; test on staging with browser DevTools or report-uri endpoints.
Suggest an improvementRequest a feature, report an issue, or propose a new tool

Your tool inputs stay private in your browser. Only this message is sent to PeachTools — no account required.

What would you like to share?

0/500 · minimum 20 characters

Rate limited to keep spam out — thanks for understanding.

Related tools

More private, in-browser utilities you might need next.

Looking for more? Browse all security tools · All tools