CSP Builder
Build and check a Content-Security-Policy
Build a Content-Security-Policy header directive by directive, get warnings for risky settings, and copy it for your server or meta tag.
- CSP
- Security headers
- XSS
How to use CSP Builder
- Start from a preset (Strict nonce, Single-page app, Static site), paste an existing policy (header, meta tag, or an nginx/Apache line) and press Load into builder, or Add a directive yourself.
- For each directive, add source chips: keywords like
'self'and'none', schemes likehttps:anddata:, hosts, nonces and hashes. Invalid sources are explained before they are added. - Read the Evaluation: a grade plus findings by severity (High, Medium, Low, Syntax, Info), each with a suggested fix.
- Pick an output format (header, meta tag, nginx, Apache, Vercel or Netlify), optionally as Report-Only, and copy it. Use the hash generator for inline scripts and styles.
How it works
The policy is held as an ordered list of directives. Pasted text is parsed with the same CSP parser used by the HTTP Headers tool (duplicates are dropped, as browsers use only the first). The evaluator follows Content-Security-Policy fallback rules (for example script-src to default-src, worker-src to child-src to script-src) and flags the problems Google's CSP Evaluator looks for: 'unsafe-inline' without a nonce or hash, 'unsafe-eval', wildcards and broad schemes in script-src, plain-HTTP sources, missing object-src, base-uri, frame-ancestors and form-action, 'strict-dynamic' without a nonce, short nonces, and a built-in list of hosts known to serve JSONP, AngularJS or user content that can bypass an allowlist. Hashes are computed with the Web Crypto API (SHA-256, SHA-384 or SHA-512) over the exact text you provide, and nonces come from crypto.getRandomValues.
Limits
- The evaluator is a static approximation: it does not fetch your scripts, test for real bypasses, or know your site. A good grade does not prove the policy is safe or that it won't break your pages.
- The list of bypass-prone hosts is small and may be out of date; it only inspects script sources.
- Meta tags ignore
frame-ancestors,report-uri,report-toandsandbox, and cannot be Report-Only; the meta output leaves those directives out and lists them. - A nonce generated here is only an example. A real nonce must be fresh and unpredictable on every response, which a static file or this page cannot provide.
- Hash sources must match the script text byte for byte, including whitespace and line endings.
Privacy
The policy, pasted text and hashed code are processed in your browser and never uploaded or stored. "Copy share link" puts the policy in the link's fragment, which is not sent to any server.
Frequently asked questions
Why is 'unsafe-inline' flagged when I have a nonce?
It isn't, as a problem. Browsers that understand nonces or hashes ignore 'unsafe-inline' when one is present, so it is reported as an info note about older browsers.
Should I use a host allowlist or a nonce?
A nonce with 'strict-dynamic' is the more robust choice. Allowlists are easy to bypass when an allowed host serves JSONP endpoints or user-controlled files, which many popular CDNs do.
How do I roll out a CSP safely?
Deploy it as Content-Security-Policy-Report-Only with a report-to or report-uri endpoint, fix the violations, then switch to the enforcing header.
Why does the meta tag drop some directives?
Browsers ignore frame-ancestors, report-uri, report-to and sandbox in a meta tag (the tag also can't be Report-Only), so they must be sent as an HTTP header.
More tools
- Clean Image: Inspect and remove hidden image metadata
- JWT Decoder: Decode and verify JSON Web Tokens
- Diff Checker: Compare two texts line by line
- JS Runner: Run JavaScript and TypeScript in your browser
- JSON Formatter: Format, validate and minify JSON
- Encode / Decode: Base64, URL, HTML entity and hex
- Hash Generator: MD5, SHA and HMAC of any text
- UUID Generator: Generate UUID v4 and v7 in bulk
- Timestamp Converter: Unix time ↔ human dates
- Regex Tester: Test regular expressions live
- URL Parser: Break a URL into its parts
- HTTP Status Codes: Look up any HTTP status code
- MIME Type Lookup: File extension ↔ MIME type
- Password Generator: Strong random passwords and passphrases
- Random String Generator: Random tokens, IDs and keys
- Slug Generator: Turn titles into URL slugs
- Case Converter: camelCase, snake_case, Title Case and more
- Word Counter: Count words, characters and reading time
- JSON to TypeScript: Generate TypeScript types from JSON
- JSON Diff: Compare two JSON documents structurally
- JSON to SQL: Turn JSON arrays into SQL inserts
- YAML ↔ JSON: Convert between YAML and JSON
- XML ↔ JSON: Convert between XML and JSON
- CSV ↔ JSON: Convert between CSV and JSON
- CSV Viewer: View, sort and filter CSV files
- SQL Formatter: Format and beautify SQL queries
- cURL ↔ Fetch: Convert cURL commands to fetch and back
- Markdown Editor: Write Markdown with a live preview
- Text Cleaner: Remove duplicate lines, empty lines and extra spaces
- Find & Replace: Find and replace in any text
- Cron Expression Builder: Build and explain cron schedules
- User-Agent Parser: Identify browser, OS and device from a user agent
- HTTP Headers Inspector: Paste response headers and get them explained
- JWT Generator: Create and sign test JSON Web Tokens
- Certificate Inspector: Decode PEM certificates and keys
- Meta Tag Inspector: Check a page's SEO and social tags
- UTM Builder: Build campaign URLs with UTM parameters
- URL Cleaner: Strip tracking parameters from links
- Robots.txt Generator: Create and test a robots.txt file
- Sitemap Generator: Create an XML sitemap from a list of URLs
- Image Compressor: Shrink JPEG, WebP and AVIF images in your browser
- Image Resizer: Resize images by pixels, percentage or to fit a box
- Image Converter: Convert between PNG, JPEG, WebP and AVIF
- Image to Base64: Encode images as Base64 data URIs and decode them back
- SVG Optimizer: Minify and sanitize SVG files
- Favicon Generator: Make favicon.ico, Apple and Android icons from an image or emoji
- Color Converter: HEX, RGB, HSL, OKLCH and contrast checks
- Number Base Converter: Binary, octal, decimal, hex and float bits
- IP / CIDR Calculator: Subnets, masks and IP ranges for IPv4 and IPv6
- JSONPath Query: Query JSON with JSONPath expressions
- JSON Schema Validator: Validate JSON against a schema, or generate one
- Semver Checker: Check versions against semver ranges
- chmod Calculator: Unix permissions: rwx ↔ octal
- .env Diff: Compare and validate .env files
- TOTP Generator: Generate and verify 2FA codes
- String Escaper: Escape and unescape strings for any language
- Unicode Inspector: See every character, code point and hidden symbol
- Mock Data Generator: Generate realistic fake data
- QR Code Generator: Create QR codes for links, Wi-Fi and contacts
- Lorem Ipsum Generator: Placeholder text in paragraphs, sentences or words
- Date Calculator: Date differences, business days and durations
- Unit Converter: Convert bytes, lengths, weights, temperatures and more
- Query CSV with SQL: Run SQL queries on CSV files
- PDF Merge & Split: Merge, split, reorder and rotate PDFs
- PDF Metadata Cleaner: See and remove hidden PDF metadata
- Office Metadata Cleaner: Remove author and revision data from Word, Excel and PowerPoint
- Images to PDF: Combine images into one PDF
- Image Editor: Crop, rotate, resize and adjust images
- Encrypt / Decrypt Text: Encrypt text with a passphrase (AES-GCM)
- SSH Key Generator: Generate Ed25519 and RSA SSH keys locally
- Email Header Analyzer: Trace an email's path and check SPF, DKIM and DMARC
- JSON to Code: Generate Go, Python, Rust, Java, C# and Kotlin models from JSON
- docker run ↔ Compose: Convert docker run commands to docker-compose and back
- Color Palette Extractor: Pull the dominant colours out of any image
- Password Strength Checker: How long would your password take to crack?
- SPF / DKIM / DMARC Checker: Validate and explain email DNS records
- Kubernetes YAML Checker: Validate and explain Kubernetes manifests
- .gitignore Generator: Build a .gitignore from presets
- JSON-LD Generator: Create schema.org structured data
- Open Graph Image Generator: Make 1200×630 social preview images
- CSS Generator: Gradients, shadows, clamp() and more
- Time Zone Meeting Planner: Find meeting times across time zones