Content Security Policy Builder
Build a Content-Security-Policy header by choosing allowed sources for scripts, styles, images and more to defend against XSS.
Last reviewed by the Radiatus Cloud team
Build a Content-Security-Policy header to defend against cross-site scripting.
Need this handled by experts?
Radiatus runs VAPT, managed SOC & security engineering for regulated teams.
Build a Content Security Policy
A Content Security Policy, or CSP, is an HTTP header that tells the browser which sources of content are allowed to load on your page, and it is one of the most effective defences against cross-site scripting attacks. This builder assembles a valid CSP header from the sources you specify for each directive, such as which origins may serve scripts, styles, images, fonts and network connections. You can also restrict who may frame your page and automatically upgrade insecure requests to HTTPS.
By default each directive is set to self, meaning only your own origin, which is a safe starting point you then widen as needed.
Locking down content sources
CSP works by refusing to load or execute anything that is not explicitly allowed, so an injected malicious script from an unapproved origin simply does not run. The script-src directive is the most important for stopping cross-site scripting, and avoiding unsafe-inline there dramatically strengthens protection. The frame-ancestors directive prevents clickjacking by controlling who can embed your page in a frame.
Start strict and loosen only what your site genuinely needs, testing in a report-only mode first if possible. All generation happens locally in your browser.
Related tools
- Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
- Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
- Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
- Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
Frequently Asked Questions
What does a CSP protect against?
Primarily cross-site scripting, by only allowing content from sources you approve, so injected scripts from other origins will not execute.
What does 'self' mean?
It allows content from your own origin, the same scheme, host and port as the page, and is a safe default for most directives.
Why avoid unsafe-inline in script-src?
It permits inline scripts, which defeats much of CSP protection against cross-site scripting. Use nonces or hashes instead where possible.
Should I test before enforcing?
Yes. Deploy in report-only mode first to see what would be blocked, then switch to enforcement once legitimate content is accounted for.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Set the sources for each directive, then copy the CSP header.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Password Strength Checker
SecurityMeasure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
Password Generator
SecurityGenerate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
Hash Generator
SecurityGenerate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.