← All tools

Content Security Policy Builder

Compose and review a CSP locally. Start with a restrictive preset, add only the sources your application needs, then test in report-only mode before enforcing it.

Directives

Separate source expressions with spaces. Keywords require quotes, for example 'self', 'none', 'nonce-…', or 'sha256-…'.

Generated policy

Review findings