CSP Builder

Generate a Content-Security-Policy header from a JSON directive map.

Processing stays in your browser. This builds syntax rather than proving the policy is secure or compatible. Test with Report-Only first; nonces must be generated per response by your server.

How to use the csp builder

Generate a Content-Security-Policy header from a JSON directive map. Complete the csp directives json object fields above, or upload a UTF-8 text file for the first field. Choose Run tool, review the output, then copy or download the result.

Example

default-src with self becomes default-src 'self'.

Good to know

This builds syntax rather than proving the policy is secure or compatible. Test with Report-Only first; nonces must be generated per response by your server.