CSP Header Builder
Compose Content-Security-Policy headers with guided directives
Build Content-Security-Policy headers with guided directives — preview report-only vs enforce modes locally.
Also known as: csp builder · create csp header · content security policy generator · csp policy tool
100% In-Browser & Private — your data never leaves this device
Loading tool...
How to use the CSP Header Builder
- Add directives: default-src, script-src, style-src, img-src, connect-src, etc.
- Set sources (self, none, nonces, hostnames) using the checklist.
- Copy the Content-Security-Policy or Content-Security-Policy-Report-Only header value.
FAQ
- Should I start with report-only?
- Yes — deploy Content-Security-Policy-Report-Only first, fix violations, then switch to enforcing mode.
- Does this scan my live site?
- No. You compose policy text locally; test on staging with browser DevTools or report-uri endpoints.
Suggest an improvementRequest a feature, report an issue, or propose a new tool
Related tools
More private, in-browser utilities you might need next.
Looking for more? Browse all security tools · All tools