CSP Builder

Generate a Content Security Policy header step by step.

Privacy: this tool processes your data entirely in your browser. Nothing you paste or type is sent to the server.

Sources for JavaScript.

Sources for CSS.

Sources for images.

Sources for fonts.

Allowed connections.

Allowed iframe embedding.

Allowed base URLs.

Allowed form targets.

Upgrade HTTP to HTTPS.

Result

Enter your values and press Calculate — the result appears here.

Worked examples

Strict CSP

  • scriptSrc = 'self'

Result: CSP header generated.

Frequently asked questions

What is CSP?

Content Security Policy controls which content sources are allowed.

💬 Discuss on BestWordz Community

Join the conversation about Cybersecurity, csp builder, content security policy on the BestWordz Community forum.

Visit Forum →
Copied!