Content Security Policy Builder

Build and review a Content-Security-Policy header locally with safe starter defaults, risk warnings and copyable header or meta-tag output.

Privacy: policy values stay in this browser. Start from the safer preset, then loosen only the directives your site actually needs.

Advanced directives

How to use this CSP builder

Content Security Policy limits which resources a page may load or execute. Start strict, test in a non-production environment, then add only the exact origins your application needs. Avoid 'unsafe-inline', 'unsafe-eval' and broad wildcards unless you understand the risk.

Header versus meta tag

The HTTP response header is the preferred deployment method. Some directives, including frame-ancestors, are not effective from a meta tag, so the generated meta output omits them.