← All tools

Content Security Policy Builder: CSP Header Templates

Create explicit resource-source policies and Report-Only templates with restrictive defaults and clear per-response nonce boundaries.

Enabling local controls…

1. Set sources by resource

Generates locally without website scans, code execution or reports. 13 directives, up to 4,096 characters / 32 sources per field; total input: 1 MiB UTF-8; output: 64 KiB. Invalid or over-limit data is rejected entirely.

Separate sources with spaces or new lines. Keep quotes around 'self' / 'none'; 'none' must stand alone. Exact ASCII HTTP(S) origins (optional port) only; no paths, queries, wildcard hosts, IPv6, fixed nonces or hashes. Use punycode for IDNs. WS(S) only for connect-src. data: only for images/fonts/media; blob: only for images/media/workers/connections. Other features are outside this first version.

Per-response nonce template (optional)

Nonce output uses {{NONCE_PER_RESPONSE}} and cannot be deployed directly. For each response, the server must generate a new cryptographically random value of at least 128 bits and use it in the policy and that response’s intended script/style elements. Never reuse across responses. A header alone does not add element nonces.

An endpoint adds report-to and Reporting-Endpoints. Deploy your collector and test browser support yourself; this tool sends no requests. Without an endpoint, use console diagnostics; remote collection is not configured.

Defaults omit unsafe-inline / unsafe-eval. Manually adding unsafe-inline for script/style, unsafe-eval for script, or broad * / https: sources produces warnings. CSP can break site functionality; exercise complete flows in your test environment before deciding on enforcement.

2. Policy template and warnings

Use defaults or load a sample, then build a policy.

This first-version policy generator is not a site audit and does not guarantee security or compatibility. It does not cover all CSP Level 3 features, hashes / strict-dynamic, trusted-types, sandbox or every directive. HTTP headers only; no limited meta substitute.

How to use this tool

Set required resource sources, review warnings and copy a policy template. Start with Report-Only in your own test environment, inspect violations and implement fresh nonces on the server when needed.

When not to use it

A generated policy is not a security audit. Report-Only does not block resources; a nonce placeholder is not a reusable token. CSP does not replace escaping, authentication or authorization.

Read the guide →