How It Works
Content Security Policy is an HTTP response header that tells the browser which sources of scripts, styles, images, and other resources are allowed to load. Each directive targets a specific resource type: script-src controls JavaScript, style-src controls CSS, img-src controls images, and so on. The builder assembles only the directives you fill in, joins them with semicolons, and validates that no common insecure keywords ('unsafe-inline', 'unsafe-eval') appear in your script policy.
Use Cases
- Setting up a strict CSP for a new web application
- Auditing an existing policy to identify insecure directives
- Generating the
<meta http-equiv>equivalent for static sites that cannot set HTTP headers - Learning which directives exist and what they control
- Creating a baseline policy to refine with browser DevTools
Example
Input: default-src 'self', object-src 'none', base-uri 'self', upgrade-insecure-requests checked
Output:
default-src 'self'; object-src 'none'; base-uri 'self'; upgrade-insecure-requests