CSP policy builder
Draft a Content Security Policy header with editable source lists and an explicit fallback preview.
How it works & useful details
How it works & supported syntax
Build an HTTP header from 10 supported source-list directives and optional upgrade-insecure-requests. Empty fields omit a directive. Supports quoted CSP keywords, schemes, ASCII hosts with optional scheme/port/path and nonce/hash source syntax. No credentials, query strings, fragments or IPv6 hosts. Each field supports 30 expressions and 2,000 characters.
Preview explains default-src fallback for supported fetch directives. base-uri, frame-ancestors and form-action do not inherit it. Report-only does not block resources or configure a report endpoint. This builder does not test resource loading, generate nonces, verify hashes or certify a policy’s effectiveness.
Local workspace
Your input stays in this page. These tools calculate or process text; they do not run commands, start containers, contact servers or change settings on your device.
Previews pause above 20,000 combined characters. Use the action to process the full supported input. Exports contain the complete result within the tool’s stated limits.
