Security

CSP Nonce Generator

Generate a cryptographically random CSP nonce for safely allowing specific inline scripts in a Content Security Policy.

Last reviewed by the Radiatus Cloud team

Generate a random CSP nonce to safely allow specific inline scripts.

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

Generate a CSP nonce

A nonce is a random, single-use value that lets a Content Security Policy allow one specific inline script to run while still blocking all other inline scripts. This generator produces a cryptographically random nonce, encoded in base64, along with examples of how to use it in the script-src directive of your CSP header and in the matching script tag. Only scripts carrying the exact nonce value will execute.

Crucially, a fresh nonce must be generated for every page request, so this tool is for understanding and testing the format rather than hard-coding a value.

Nonces versus unsafe-inline

Allowing inline scripts with unsafe-inline in a CSP effectively disables the policy main protection against cross-site scripting. Nonces solve this: by generating a new random value per request and attaching it to your legitimate inline scripts, you keep the strong protection while still permitting the specific scripts you control. An attacker cannot guess the unpredictable nonce, so injected scripts without it are blocked.

Generate the nonce server-side on each request and insert it into both the CSP header and the trusted script tags. The browser random generator is used here where available for genuine unpredictability. All generation happens locally in your browser.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

What is a CSP nonce?

It is a random one-time value that allows a specific inline script to run under a Content Security Policy while all other inline scripts are blocked.

How often should the nonce change?

On every page request. A nonce must be unpredictable and single-use, so it should be freshly generated server-side for each response.

Why use a nonce instead of unsafe-inline?

unsafe-inline permits all inline scripts, defeating CSP protection. A nonce allows only your specific scripts while still blocking injected ones.

Where do I put the nonce?

In the script-src directive of the CSP header as nonce-value, and as the nonce attribute on each inline script tag you trust.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Generate a nonce and use it in your CSP header and script tags.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.