CSP Generator

Build a Content Security Policy without locking yourself out.

Developer Tools Free, no sign-up Runs in your browser

CSP Generator tool

Directives

Deploy in report-only mode first. It reports what would have been blocked without blocking anything, which is how you find out what your site actually loads before you start enforcing.

About the CSP Generator

A Content Security Policy tells the browser which sources a page is allowed to load scripts, styles, images and other resources from. Done well it is the strongest defence against cross-site scripting there is, because even an injected script will not execute if its source is not permitted.

Done badly it breaks the site, which is why this generator builds the policy one directive at a time with each source value explained. You can see exactly what self, none, a domain, a nonce and the unsafe values each permit, instead of copying a policy from somewhere and hoping.

Two features exist because they are what makes CSP survivable in practice. Report-only mode sends the policy as a header that reports violations without enforcing anything, which is how you find what your site actually loads before you start blocking. And the tool flags unsafe-inline and unsafe-eval clearly, because a script-src containing unsafe-inline provides essentially none of the protection the policy was added for.

How to use the CSP Generator

  1. Start with a preset or a blank policyPresets cover a strict policy, a typical site and a report-only rollout.
  2. Set each directiveEvery source value is explained as you add it.
  3. Start in report-only modeCollect violations before enforcing anything.
  4. Copy the headerAs a header line or as server configuration.

Features

  • All the common directives, each explained
  • Source values including self, none, nonce, hash and domains
  • Report-only mode for a safe rollout
  • Clear warnings on unsafe-inline and unsafe-eval
  • Presets for strict, typical and report-only policies
  • Header line plus Apache and nginx configuration
  • Explains why frame-ancestors supersedes X-Frame-Options

Who uses this tool

The csp generator is used by writers, developers, students, marketers and anyone else who needs the job done once without installing software. Common cases include:

  • Adding a CSP to an existing site without breaking it
  • Tightening a policy that currently allows unsafe-inline
  • Restricting which domains can be framed
  • Understanding a policy somebody else wrote
  • Setting up violation reporting before enforcement

Frequently asked questions

What should I do first?

Deploy in report-only mode. It sends the policy as Content-Security-Policy-Report-Only, which reports what would have been blocked without blocking anything. Run it for a week, look at what your site actually loads, then enforce.

Why is unsafe-inline a problem?

Because it permits any inline script, which is exactly what an injected script is. A script-src with unsafe-inline provides almost none of the protection a CSP is meant to give. Use a nonce or a hash for the inline scripts you genuinely need.

What is a nonce?

A random value generated per request, placed in both the policy and the script tag. Only scripts carrying the matching nonce run. It requires server-side rendering, since the value must be different on every response, and reusing one defeats the purpose entirely.

Does default-src cover everything?

It is the fallback for most fetch directives, but not all. Notably frame-ancestors, base-uri and form-action do not fall back to it and must be set explicitly.

Will a CSP break my analytics or ads?

It will if their domains are not allowed. This is the main reason report-only mode exists: third-party scripts load from more hosts than their documentation admits, and the violation reports tell you which.

Is a CSP enough on its own?

No. It is a strong second line of defence. Escaping output correctly remains the first, and a CSP is what limits the damage when something slips through.

If the csp generator is not quite what you need, these other free tools solve closely related problems.

.htaccess Generator

Generate .htaccess rules for redirects, caching, compression and security headers.

SEO Tools Use tool

Hash Generator

Generate cryptographic hashes of text, computed in your browser.

Developer Tools Use tool