CSP Generator
Generate Content Security Policy headers
Fill the core CSP directives first to generate the policy header; report-uri and scenario comparisons are available in Advanced mode.
The full guide also includes pitfalls, worked examples, snippets, FAQs, and related tools for checking results or troubleshooting.
About this tool
Assemble default-src, script-src, style-src, img-src and connect-src into a CSP header value and an HTML meta tag. An optional report-uri is included only in the header value because CSP reporting is unsupported in meta delivery. Source expressions are copied as entered; the tool does not validate the policy, inspect your appβs dependencies or create a reporting endpoint.
Production Snippets
The report endpoint belongs in an HTTP header
text
Header value:
default-src 'self'; report-uri https://example.com/csp-report
Meta:
<meta http-equiv="Content-Security-Policy" content="default-src 'self'">
A report-uri does not make a policy report-only. Set the Content-Security-Policy-Report-Only header explicitly when that is your intent.Frequently Asked Questions
Does this output a complete HTTP response header?
The panel displays Content-Security-Policy followed by the value, but its copy button copies the value alone. Set the header name yourself; use Content-Security-Policy-Report-Only when testing without enforcement.
Are header and meta delivery interchangeable?
No. Meta CSP cannot deliver report-only policies or report-uri; some other directives such as frame-ancestors also require headers. This generator omits report-uri from its meta output. Place a meta policy early in head when that delivery method fits your site.
What should I enter for a same-origin source?
Use the CSP source expression with its single quotes, for example 'self'. The form does not add quotes, generate nonces or hash inline scripts. A source list must match the actual resources your app loads.
Does generating a CSP prove that my app is protected?
No. Test the policy against real page behavior and inspect violations. Broad sources, unsafe-inline and unsafe-eval can weaken it. A report-uri line only names an endpoint you must provide, and reporting support varies by browser.
Keep browsing