C CSP Generator

Build a tighter content security policy.

Paste the allowed sources for each resource type. The policy updates as you work, ready to copy into your HTTP response header or meta tag.

Generated Content-Security-Policy

Duplicate sources are removed automatically. Keep the generated header server-side whenever possible.

Copied to clipboard

Import an existing CSP header

Paste a complete Content-Security-Policy value (the header label is optional) to populate the fields below.

Policy directives

One source per line, or separate with commas.