CSP Generator
Generate Content Security Policy headers
How to use CSP Generator
- 1Enter the policy directives you plan to allow (default-src, script-src, img-src, etc.).
- 2Enter the domains or schemes you trust as sources.
- 3Read the generated Content-Security-Policy header to paste into your server config.
Building a Content Security Policy
CSP = directive1 value1 value2; directive2 value3; ...A CSP whitelists where the browser may load scripts, styles, images and connections, blocking injection of unauthorized content even if an XSS bug exists.
Start in report-only mode to log violations before enforcing, otherwise a too-strict policy can break legitimate resources on your site.
Frequently asked questions
What does default-src do?
It sets the fallback for any directive you do not specify explicitly, so 'self' there covers most tags.
Should I use report-only first?
Yes, monitor reported violations for a while so you can tune the policy without breaking the site.
Does CSP stop all XSS?
It drastically reduces impact but is a defense-in-depth layer, not a replacement for input sanitization.
