Security Headers Generator
Build security header configuration for Apache, nginx, Netlify or Vercel.
Build a Content Security Policy without locking yourself out.
Deploy in report-only mode first. It reports what would have been blocked without blocking anything, which is how you find out what your site actually loads before you start enforcing.
A Content Security Policy tells the browser which sources a page is allowed to load scripts, styles, images and other resources from. Done well it is the strongest defence against cross-site scripting there is, because even an injected script will not execute if its source is not permitted.
Done badly it breaks the site, which is why this generator builds the policy one directive at a time with each source value explained. You can see exactly what self, none, a domain, a nonce and the unsafe values each permit, instead of copying a policy from somewhere and hoping.
Two features exist because they are what makes CSP survivable in practice. Report-only mode sends the policy as a header that reports violations without enforcing anything, which is how you find what your site actually loads before you start blocking. And the tool flags unsafe-inline and unsafe-eval clearly, because a script-src containing unsafe-inline provides essentially none of the protection the policy was added for.
The csp generator is used by writers, developers, students, marketers and anyone else who needs the job done once without installing software. Common cases include:
Deploy in report-only mode. It sends the policy as Content-Security-Policy-Report-Only, which reports what would have been blocked without blocking anything. Run it for a week, look at what your site actually loads, then enforce.
Because it permits any inline script, which is exactly what an injected script is. A script-src with unsafe-inline provides almost none of the protection a CSP is meant to give. Use a nonce or a hash for the inline scripts you genuinely need.
A random value generated per request, placed in both the policy and the script tag. Only scripts carrying the matching nonce run. It requires server-side rendering, since the value must be different on every response, and reusing one defeats the purpose entirely.
It is the fallback for most fetch directives, but not all. Notably frame-ancestors, base-uri and form-action do not fall back to it and must be set explicitly.
It will if their domains are not allowed. This is the main reason report-only mode exists: third-party scripts load from more hosts than their documentation admits, and the violation reports tell you which.
No. It is a strong second line of defence. Escaping output correctly remains the first, and a CSP is what limits the damage when something slips through.
If the csp generator is not quite what you need, these other free tools solve closely related problems.
Build security header configuration for Apache, nginx, Netlify or Vercel.
Generate .htaccess rules for redirects, caching, compression and security headers.
A searchable reference for every HTTP status code, with practical guidance.
Check password strength by entropy and pattern, entirely in your browser.
Generate cryptographic hashes of text, computed in your browser.