Security Headers Generator

Generate the HTTP security headers a site should send.

Developer Tools Free, no sign-up Runs in your browser

Security Headers Generator tool

Headers to include

What each header does

About the Security Headers Generator

Security headers are instructions a server sends with every response, telling the browser to enforce protections the page cannot enforce for itself. This generator assembles them into configuration for whichever server you run, with each header explained rather than just emitted.

The set covers what is actually worth sending today: Strict-Transport-Security to require https, X-Content-Type-Options to stop browsers guessing at content types, X-Frame-Options to prevent your pages being framed for clickjacking, Referrer-Policy to control how much of your URL leaks to other sites, Permissions-Policy to switch off browser features your site does not use, and Cross-Origin-Opener-Policy for process isolation.

Two cautions are built into the tool because they matter. HSTS with a long max-age and the preload directive is extremely difficult to undo, so a site not fully ready for https should start with a short max-age. And headers that were once recommended but are now harmful, notably X-XSS-Protection, are explained rather than offered.

How to use the Security Headers Generator

  1. Choose your serverApache, nginx, Netlify, Vercel or a plain header list.
  2. Pick the headersEach one is explained, with its options.
  3. Read the warningsHSTS in particular is hard to reverse once deployed.
  4. Copy the configurationPaste it into your server config and verify the response headers.

Features

  • HSTS with max-age, subdomains and preload options
  • X-Content-Type-Options, X-Frame-Options and Referrer-Policy
  • Permissions-Policy with the common features
  • Cross-Origin-Opener and Resource policies
  • Apache, nginx, Netlify, Vercel and plain list output
  • Explains what each header does and its trade-offs
  • Warns about irreversible HSTS settings
  • Notes the headers that are now obsolete and why

Who uses this tool

The security headers generator is used by writers, developers, students, marketers and anyone else who needs the job done once without installing software. Common cases include:

  • Hardening a site before a security review
  • Adding headers a scanner flagged as missing
  • Setting a referrer policy that stops URL leakage
  • Switching off browser features a site never uses
  • Converting a header set between server formats

Frequently asked questions

Which header should I add first?

X-Content-Type-Options with nosniff, because it is a single value, breaks nothing, and closes a real class of attack. Referrer-Policy is a close second and equally safe.

Why is HSTS dangerous to get wrong?

Because browsers remember it for the max-age you set, and will refuse to load your site over http for that entire period. If https later breaks, your site is unreachable and you cannot fix it by changing the header. Start with a short max-age, confirm everything works, then increase it.

Should I use preload?

Only when you are certain. Preloading puts your domain in a list compiled into browsers, including all subdomains, and removal takes months. It is the strongest version of a commitment that is already hard to reverse.

Is X-Frame-Options still needed?

It is superseded by the Content Security Policy frame-ancestors directive, which is more flexible. Sending both is the pragmatic choice while older browsers remain in use.

What about X-XSS-Protection?

Do not send it. The browser feature it controlled has been removed, and in its later years the filter itself introduced vulnerabilities. A Content Security Policy is the modern defence.

Do headers replace fixing the underlying problem?

No. They are defence in depth. A header that blocks an attack on an application with an injection flaw is a safety net, not a repair.

If the security headers generator is not quite what you need, these other free tools solve closely related problems.

CSP Generator

Generate a Content Security Policy header directive by directive, with explanations.

Developer Tools Use tool

.htaccess Generator

Generate .htaccess rules for redirects, caching, compression and security headers.

SEO Tools Use tool

MIME Type Lookup

Look up MIME types by extension, or find which extensions use a type.

Developer Tools Use tool