← Cybersecurity Tools

🛡️ CSP Generator

Build your Content Security Policy headers with a visual interface and protect your website from XSS and data injection attacks.

📦 Presets

📋 Basic Directives

Fallback source for other directives. Default: 'none'

JavaScript sources. NOTE: 'unsafe-inline' can pose a security risk.

CSS sources.

Image sources. Supports data: URIs.

Font sources.

AJAX, WebSocket, EventSource connections.

iframe sources.

Video and audio sources.

Flash and plugin sources. 'none' is recommended.

🔒 Additional Security Directives

Restricts the source of the <base> tag.

Restricts the sources a form can be submitted to.

Controls whether your site can be embedded in a frame.

Automatically upgrades HTTP requests to HTTPS.

Blocks HTTP content on HTTPS pages.

Content-Security-Policy header will appear here...

📖 How to Use?

  1. Choose one of the presets or fill in the directives manually.
  2. Adjust the directives you need.
  3. Click the "Generate CSP" button.
  4. Add the generated CSP header to your server configuration.
  5. Note: You can add the CSP to your .htaccess, Nginx config, or web.config file.

💡 Common Source Values