Security

Clickjacking Protection Generator

Generate the HTTP headers that protect a site from clickjacking, using X-Frame-Options and the Content-Security-Policy frame-ancestors directive.

Last reviewed by the Radiatus Cloud team

Generate headers that protect your site from clickjacking attacks.

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

Protect against clickjacking

Clickjacking is an attack where a malicious site loads your page inside an invisible frame and tricks a user into clicking something they did not intend, such as a hidden button. The defence is to control who may frame your page using HTTP headers. This generator produces both the older X-Frame-Options header and the modern Content-Security-Policy frame-ancestors directive, configured to deny all framing, allow only your own site, or permit a specific list of trusted origins.

The frame-ancestors directive is the current standard and can list multiple origins, which the single-valued X-Frame-Options header cannot.

Framing controls explained

Setting the policy to deny framing entirely is the safest choice for pages that never need to be embedded, such as login and banking pages. Allowing only the same origin lets your own site frame its pages while blocking others. If a trusted partner must embed your page, list their origin in frame-ancestors. Sending both headers maximises browser coverage, with X-Frame-Options as a fallback for older browsers.

Because X-Frame-Options cannot express a list of origins, use frame-ancestors when you need to allow specific external sites. Apply these headers to all sensitive pages. All generation happens locally in your browser.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

What is clickjacking?

It is an attack that loads your page in an invisible frame over a decoy, tricking users into clicking hidden elements they did not intend to.

What is the difference between the two headers?

X-Frame-Options is older and single-valued, while the CSP frame-ancestors directive is current and can list multiple allowed origins.

Which option should I choose?

Deny framing for pages that never need embedding, allow same-origin for your own site, or list specific origins only for trusted partners.

Should I send both headers?

Yes. Sending both maximises coverage, with frame-ancestors as the modern control and X-Frame-Options as a fallback for older browsers.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Choose who may frame your page, then copy the headers.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.