Compliance

CSP Generator

Create a CSP header configuration to prevent XSS.

Last reviewed by the Radiatus Cloud team

Content Security Policy (CSP) Generator

Create a secure Content-Security-Policy header to prevent XSS and data injection.

Fallback for other directives.
Tip: Always test your CSP in "Report-Only" mode first to avoid breaking your site.

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

Build a Content Security Policy

A Content Security Policy is one of the strongest defences against cross-site scripting, and configuring it correctly matters. This tool creates a CSP header configuration, so you can control what resources your pages are allowed to load and run.

Why a CSP defends against XSS

Cross-site scripting attacks work by getting a page to run malicious script, and a Content Security Policy defends against this by telling the browser exactly which sources of scripts, styles and other resources are allowed, blocking everything else. A well-configured CSP means that even if an attacker injects a script, the browser refuses to run it because its source is not permitted. Getting the policy right is delicate, too strict and it breaks legitimate resources, too loose and it does not protect, which is why generating a considered starting configuration helps you find the balance.

A tool, not legal advice

It runs entirely in your browser, so nothing you enter is uploaded and the generated output is yours to use, which matters when the input or result concerns your own site or organisation.

Related tools

Frequently Asked Questions

What does a Content Security Policy do?

It tells the browser which sources of scripts, styles and other resources a page may load, blocking everything else, which defends against cross-site scripting.

How does a CSP stop XSS?

By refusing to run injected scripts whose source is not on the allowed list, so even a successful injection cannot execute.

Why is CSP hard to configure?

Because too strict a policy breaks legitimate resources, while too loose a one does not protect. Finding the balance takes a considered configuration.

Is a CSP enough on its own?

No. It is a strong layer, but input handling and output encoding remain essential. Defence in depth is more robust than any single control.

Is my input uploaded?

No. The generation runs entirely in your browser.

Privacy & Security

Local generation.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.