🛡️ CSP Generator
Build your Content Security Policy headers with a visual interface and protect your website from XSS and data injection attacks.
📦 Presets
📋 Basic Directives
Fallback source for other directives. Default: 'none'
JavaScript sources. NOTE: 'unsafe-inline' can pose a security risk.
CSS sources.
Image sources. Supports data: URIs.
Font sources.
AJAX, WebSocket, EventSource connections.
iframe sources.
Video and audio sources.
Flash and plugin sources. 'none' is recommended.
🔒 Additional Security Directives
Restricts the source of the <base> tag.
Restricts the sources a form can be submitted to.
Controls whether your site can be embedded in a frame.
Automatically upgrades HTTP requests to HTTPS.
Blocks HTTP content on HTTPS pages.
Content-Security-Policy header will appear here...
📖 How to Use?
- Choose one of the presets or fill in the directives manually.
- Adjust the directives you need.
- Click the "Generate CSP" button.
- Add the generated CSP header to your server configuration.
- Note: You can add the CSP to your .htaccess, Nginx config, or web.config file.
💡 Common Source Values
'self'- Same domain'none'- No sources allowed'unsafe-inline'- Allows inline code (XSS risk)'unsafe-eval'- Allows use of eval() (risky)data:- Base64 encoded contenthttps:- All HTTPS sources