How to use CSP Header Generator
Generate a restrictive baseline policy and optionally add explicitly entered HTTPS origins for scripts. Review requirements before deploying.
- Set Text.
- Run the tool, review the result and its stated limitations, then copy or download if needed.
Example & practical use
Generate a restrictive baseline policy and optionally add explicitly entered HTTPS origins for scripts. Review requirements before deploying. The example below demonstrates Text.
Example input:
{
"text": "https://www.googletagmanager.com"
}
Expected result (relevant fields):
"default-src 'self'; script-src 'self' https://www.googletagmanager.com; object-src 'none'; base-uri 'self'; frame-ancestors 'none'"Features & result limitations
Generate a restrictive baseline policy and optionally add explicitly entered HTTPS origins for scripts. Review requirements before deploying.
Frequently asked questions
What inputs does CSP Header Generator accept?
Text
How should I interpret the CSP Header Generator result?
Generate a restrictive baseline policy and optionally add explicitly entered HTTPS origins for scripts. Review requirements before deploying.
Where does CSP Header Generator process my data?
Inputs are processed locally in your browser. Submitted text is not sent to external services. A successful-run event increments an aggregate tool counter without your input.