Skip to content
Runs privately in your browser

Free Online CSP Header Generator

Generate a restrictive baseline policy and optionally add explicitly entered HTTPS origins for scripts. Review requirements before deploying.

Your input stays on this device. Processing is bounded; regex runs in a worker with a two-second timeout.

Result

How to use CSP Header Generator

Generate a restrictive baseline policy and optionally add explicitly entered HTTPS origins for scripts. Review requirements before deploying.

  1. Set Text.
  2. Run the tool, review the result and its stated limitations, then copy or download if needed.

Example & practical use

Generate a restrictive baseline policy and optionally add explicitly entered HTTPS origins for scripts. Review requirements before deploying. The example below demonstrates Text.

Example input:
{
  "text": "https://www.googletagmanager.com"
}
Expected result (relevant fields):
"default-src 'self'; script-src 'self' https://www.googletagmanager.com; object-src 'none'; base-uri 'self'; frame-ancestors 'none'"

Features & result limitations

Generate a restrictive baseline policy and optionally add explicitly entered HTTPS origins for scripts. Review requirements before deploying.

Frequently asked questions

What inputs does CSP Header Generator accept?

Text

How should I interpret the CSP Header Generator result?

Generate a restrictive baseline policy and optionally add explicitly entered HTTPS origins for scripts. Review requirements before deploying.

Where does CSP Header Generator process my data?

Inputs are processed locally in your browser. Submitted text is not sent to external services. A successful-run event increments an aggregate tool counter without your input.