CSP Header Generator
Create a Content-Security-Policy without memorising directives. Start from Google's recommended strict policy (nonces plus 'strict-dynamic') or an allowlist of hosts, add the domains for your images, fonts, APIs and embeds, and copy the header for Nginx, Apache, Next.js or a meta tag — evaluated live for weaknesses.
Pick strict (recommended) or allowlist mode, list the third-party hosts you use for styles, images, fonts, APIs and frames, and set framing and upgrade options. The generator outputs a complete policy with object-src 'none', base-uri and form-action locked down, in the format for your server. Deploy it as Report-Only first.
Your server adds a fresh random nonce to every response and to each <script nonce="…">. Replace {RANDOM_NONCE} per request.
Your policy
Content-Security-Policy-Report-Only: default-src 'self'; script-src 'nonce-{RANDOM_NONCE}' 'strict-dynamic' https: 'unsafe-inline'; style-src 'self'; img-src 'self' data:; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; upgrade-insecure-requestsStrict CSP (nonces/hashes + 'strict-dynamic')
This is the approach Google recommends; host allowlists are ignored by modern browsers.
Deploy in Report-Only mode first, watch the browser console (or your report endpoint) for violations, then switch to enforcing. A <meta> CSP can't use frame-ancestors or reporting.
Zero Server Uploads
Files process in local RAM
Instant WASM Speed
No waiting queues or lags
Unlimited Batching
Convert files without limits
Suggest a Feature or Improvement for CSP Header Generator
Need custom options, higher limits, or extra format support? Let our engineering team know!
How to use CSP Header Generator
- 1Choose strict (nonce) or allowlist mode.
- 2Add the external hosts your site loads from.
- 3Choose who may frame your site.
- 4Copy the header for your server — start in Report-Only mode.
Strict CSP vs allowlists
Research by Google found that most allowlist policies can be bypassed because allowed CDNs host JSONP endpoints or old libraries. A strict CSP instead gives each legitimate script a random nonce; 'strict-dynamic' lets those scripts load their dependencies, and hosts are ignored by modern browsers.
The https: and 'unsafe-inline' in the strict template are fallbacks for very old browsers — modern ones ignore them when a nonce is present.
Rolling it out
Send it as Content-Security-Policy-Report-Only first, watch the console and reports for violations, adjust, then enforce. Your server must generate a fresh random nonce per response. Check any policy with the CSP Evaluator and the overall header grade with the Security Headers Checker.
Frequently Asked Questions
Can I set CSP in a meta tag?
Yes, but frame-ancestors, report-uri and sandbox don't work there. An HTTP header is better.
Do I need 'unsafe-inline' for styles?
Many sites do, because frameworks inject inline styles. It's far less risky for styles than for scripts.
Is my data sent to your server?
No. This tool runs entirely in your browser using the Web Crypto API and JavaScript. Nothing you type or generate is uploaded, logged or stored.
Guides & Tutorials
Related Tools
CSP Evaluator
Analyse a Content-Security-Policy for bypasses and weaknesses — paste it or fetch it from a URL.
Security Headers Checker
Scan any website's HTTP security headers and get an A+ to F grade with fixes.
HTTP Header Checker
View every HTTP response header a URL returns, with explanations and the redirect chain.