HSTS Header Generator
Generate a Strict-Transport-Security (HSTS) header to force browsers to use HTTPS, with max-age, includeSubDomains and preload options.
Last reviewed by the Radiatus Cloud team
Generate a Strict-Transport-Security (HSTS) header to enforce HTTPS.
Need this handled by experts?
Radiatus runs VAPT, managed SOC & security engineering for regulated teams.
Generate an HSTS header
HTTP Strict Transport Security, or HSTS, is a response header that tells browsers to only ever connect to your site over HTTPS, never plain HTTP, for a specified period. This generator builds the Strict-Transport-Security header with your chosen max-age, and options to apply the policy to all subdomains and to request inclusion in browser preload lists. Once a browser sees this header, it automatically upgrades any future HTTP request to HTTPS before sending it.
A long max-age, such as one year, is recommended for production so the protection persists between visits.
Enforcing secure connections
HSTS defends against downgrade attacks and cookie hijacking by removing the brief insecure first request that an attacker could intercept. The includeSubDomains option extends the protection to every subdomain, and the preload option, combined with submitting your domain to the preload list, hard-codes the HTTPS requirement into browsers so even the very first visit is secure.
Only enable preload and a long max-age once you are confident every part of your site, including all subdomains, works over HTTPS, because the policy is hard to reverse quickly. All generation happens locally in your browser.
Related tools
- Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
- Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
- Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
- Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
Frequently Asked Questions
What does HSTS do?
It instructs browsers to use HTTPS exclusively for your site for the max-age period, automatically upgrading any HTTP request to HTTPS.
What max-age should I use?
One year is a common production value. Use a short value like one day only while testing, since the policy persists in browsers.
What is the preload option?
It requests inclusion in browser preload lists so HTTPS is enforced even on the first-ever visit. Submit your domain separately after adding it.
Is HSTS risky to enable?
A long max-age is hard to undo quickly, so ensure your whole site and all subdomains work over HTTPS before using includeSubDomains and preload.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Choose the max-age and options, then copy the HSTS header.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Password Strength Checker
SecurityMeasure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
Password Generator
SecurityGenerate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
Hash Generator
SecurityGenerate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.