Security

HSTS Header Generator

Generate a Strict-Transport-Security (HSTS) header to force browsers to use HTTPS, with max-age, includeSubDomains and preload options.

Last reviewed by the Radiatus Cloud team

Generate a Strict-Transport-Security (HSTS) header to enforce HTTPS.

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

Generate an HSTS header

HTTP Strict Transport Security, or HSTS, is a response header that tells browsers to only ever connect to your site over HTTPS, never plain HTTP, for a specified period. This generator builds the Strict-Transport-Security header with your chosen max-age, and options to apply the policy to all subdomains and to request inclusion in browser preload lists. Once a browser sees this header, it automatically upgrades any future HTTP request to HTTPS before sending it.

A long max-age, such as one year, is recommended for production so the protection persists between visits.

Enforcing secure connections

HSTS defends against downgrade attacks and cookie hijacking by removing the brief insecure first request that an attacker could intercept. The includeSubDomains option extends the protection to every subdomain, and the preload option, combined with submitting your domain to the preload list, hard-codes the HTTPS requirement into browsers so even the very first visit is secure.

Only enable preload and a long max-age once you are confident every part of your site, including all subdomains, works over HTTPS, because the policy is hard to reverse quickly. All generation happens locally in your browser.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

What does HSTS do?

It instructs browsers to use HTTPS exclusively for your site for the max-age period, automatically upgrading any HTTP request to HTTPS.

What max-age should I use?

One year is a common production value. Use a short value like one day only while testing, since the policy persists in browsers.

What is the preload option?

It requests inclusion in browser preload lists so HTTPS is enforced even on the first-ever visit. Submit your domain separately after adding it.

Is HSTS risky to enable?

A long max-age is hard to undo quickly, so ensure your whole site and all subdomains work over HTTPS before using includeSubDomains and preload.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Choose the max-age and options, then copy the HSTS header.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.