Build Content Security Policy headers visually with live preview and presets.
Presets
Directives
upgrade-insecure-requestsblock-all-mixed-contentBuild Content Security Policy (CSP) headers visually. Select directives, add source allowlists, toggle common source keywords like 'self', 'none', and 'unsafe-inline', and get a ready-to-use CSP header string plus an HTML meta tag. Includes Strict, Moderate, and Permissive presets. Helps protect your web app against XSS and data injection attacks.
The CSP Header Builder allows you to construct and customize Content Security Policy headers visually without manually writing complex syntax. It features quick-start presets like Strict, Moderate, and Permissive, along with options to toggle common keywords and source allowlists. You can instantly copy the ready-to-use header string or HTML meta tag to help protect your web application against XSS and data injection attacks.
Good to know: Complex enterprise security architectures with automated policy testing pipelines or server-side integration testing may require more advanced deployment frameworks.
Create a secure Content Security Policy header to protect your website from XSS and data injection attacks.
Select a security policy preset
Choose from Strict, Moderate, or Permissive presets to automatically populate the builder with recommended security baselines.
Configure individual CSP directives
Navigate through directives like script-src or style-src to define specific security rules for your web application.
Add source allowlists and keywords
Toggle common source keywords such as 'self' or 'unsafe-inline' and manually input trusted domains into the allowlist.
Preview the generated CSP string
Review the live preview of your Content Security Policy header and HTML meta tag to ensure all directives are correct.
Copy and implement the header
Copy the ready-to-use header string or meta tag and paste it into your server configuration or HTML head section.
Estimated time: PT2M
Share this tool
Check password strength: entropy, crack time, patterns, and breach check.
Generate HMAC-SHA256/512 signatures for API authentication and webhooks.
Generate a robots.txt file with crawl rules and sitemap.
Generate strong, customizable secure passwords instantly.
Generate MD5, SHA-1, SHA-256, SHA-512 hashes from text.
Encode and decode text with ROT13, Caesar, Atbash, and Vigenère ciphers.
AES-256-GCM encrypt and decrypt text with a passphrase — runs in your browser.
Build and sign JWTs with HS256/384/512. Verify signatures. Runs in your browser.
Generate live TOTP/2FA codes from a base32 secret. Scan QR with any authenticator.
Convert text or Markdown to a Word .docx file with live preview, RTL, and page-setup options.
Draw a Secret Santa with exclusions and share a private reveal link for each person.
Make custom bingo cards from your own words — play, print, or share a link.
Convert images to video with the Ken Burns zoom/pan effect. Add music and export as WebM.
Load and compare multiple URLs side by side in resizable iframes.
Rank anything with quick 1-v-1 matchups → a full ordered list you can share.
Convert Markdown to a fully customized, RTL-ready PDF.
See your public IP address plus full location, ISP, ASN, timezone, coordinates, and more.