CSP Generator

Generate Content Security Policy headers

How to use CSP Generator

  1. 1Enter the policy directives you plan to allow (default-src, script-src, img-src, etc.).
  2. 2Enter the domains or schemes you trust as sources.
  3. 3Read the generated Content-Security-Policy header to paste into your server config.

Building a Content Security Policy

CSP = directive1 value1 value2; directive2 value3; ...

A CSP whitelists where the browser may load scripts, styles, images and connections, blocking injection of unauthorized content even if an XSS bug exists.

Start in report-only mode to log violations before enforcing, otherwise a too-strict policy can break legitimate resources on your site.

Frequently asked questions

What does default-src do?

It sets the fallback for any directive you do not specify explicitly, so 'self' there covers most tags.

Should I use report-only first?

Yes, monitor reported violations for a while so you can tune the policy without breaking the site.

Does CSP stop all XSS?

It drastically reduces impact but is a defense-in-depth layer, not a replacement for input sanitization.

More Tools