Skip to content
FlexibleToolsAI
Security Toolkit · 100% Client-Side Private

CSP Header Generator

Create a Content-Security-Policy without memorising directives. Start from Google's recommended strict policy (nonces plus 'strict-dynamic') or an allowlist of hosts, add the domains for your images, fonts, APIs and embeds, and copy the header for Nginx, Apache, Next.js or a meta tag — evaluated live for weaknesses.

Pick strict (recommended) or allowlist mode, list the third-party hosts you use for styles, images, fonts, APIs and frames, and set framing and upgrade options. The generator outputs a complete policy with object-src 'none', base-uri and form-action locked down, in the format for your server. Deploy it as Report-Only first.

Your server adds a fresh random nonce to every response and to each <script nonce="…">. Replace {RANDOM_NONCE} per request.

space or comma separated
space or comma separated
space or comma separated
space or comma separated
space or comma separated
optional

Your policy

Content-Security-Policy-Report-Only: default-src 'self'; script-src 'nonce-{RANDOM_NONCE}' 'strict-dynamic' https: 'unsafe-inline'; style-src 'self'; img-src 'self' data:; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; upgrade-insecure-requests
  • Strict CSP (nonces/hashes + 'strict-dynamic')

    This is the approach Google recommends; host allowlists are ignored by modern browsers.

Deploy in Report-Only mode first, watch the browser console (or your report endpoint) for violations, then switch to enforcing. A <meta> CSP can't use frame-ancestors or reporting.

Zero Server Uploads

Files process in local RAM

Instant WASM Speed

No waiting queues or lags

Unlimited Batching

Convert files without limits

Suggest a Feature or Improvement for CSP Header Generator

Need custom options, higher limits, or extra format support? Let our engineering team know!

How to use CSP Header Generator

  1. 1Choose strict (nonce) or allowlist mode.
  2. 2Add the external hosts your site loads from.
  3. 3Choose who may frame your site.
  4. 4Copy the header for your server — start in Report-Only mode.

Strict CSP vs allowlists

Research by Google found that most allowlist policies can be bypassed because allowed CDNs host JSONP endpoints or old libraries. A strict CSP instead gives each legitimate script a random nonce; 'strict-dynamic' lets those scripts load their dependencies, and hosts are ignored by modern browsers.

The https: and 'unsafe-inline' in the strict template are fallbacks for very old browsers — modern ones ignore them when a nonce is present.

Rolling it out

Send it as Content-Security-Policy-Report-Only first, watch the console and reports for violations, adjust, then enforce. Your server must generate a fresh random nonce per response. Check any policy with the CSP Evaluator and the overall header grade with the Security Headers Checker.

Frequently Asked Questions

Can I set CSP in a meta tag?

Yes, but frame-ancestors, report-uri and sandbox don't work there. An HTTP header is better.

Do I need 'unsafe-inline' for styles?

Many sites do, because frameworks inject inline styles. It's far less risky for styles than for scripts.

Is my data sent to your server?

No. This tool runs entirely in your browser using the Web Crypto API and JavaScript. Nothing you type or generate is uploaded, logged or stored.

Guides & Tutorials

Related Tools