Security Headers Generator
Build a complete set of HTTP security response headers from your requirements, and get the ready to paste configuration for Nginx, Apache, Cloudflare Workers or Express.
Last reviewed by the Radiatus Cloud team
Need this handled by experts?
Radiatus runs VAPT, managed SOC & security engineering for regulated teams.
A small set of headers does most of the work
Browser security headers are one of the highest leverage changes available to a web application, because they enable protections the browser already implements and which are off by default for backward compatibility. Strict-Transport-Security removes the window in which a first request can be downgraded to HTTP. Content-Security-Policy restricts where scripts may come from, which turns most cross site scripting bugs from exploitable into inert. X-Content-Type-Options stops content sniffing. Referrer-Policy stops URLs leaking to third parties.
Content-Security-Policy is the difficult one
The others are essentially set and forget. CSP requires knowing what your page actually loads, and a policy that is too strict breaks the site while one that is too loose achieves nothing. The single most common mistake is including unsafe-inline in script-src, which permits exactly the injection CSP exists to prevent. The path that works is to deploy in report-only mode first, collect violation reports for a week, then enforce, using nonces or hashes for the inline scripts you genuinely need.
Headers people still set that no longer help
X-XSS-Protection was a filter in old browsers that introduced its own vulnerabilities and has been removed from every modern engine; setting it to 1 is worse than not setting it. X-Frame-Options is superseded by the frame-ancestors CSP directive, though it is still worth sending for old browsers. Expect-CT is deprecated and Feature-Policy has been renamed to Permissions-Policy. This generator emits current headers and explains the ones it deliberately omits.
Related tools
- Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
- Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
- Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
- Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
Frequently Asked Questions
Which headers matter most?
Strict-Transport-Security and Content-Security-Policy by a wide margin, followed by X-Content-Type-Options and Referrer-Policy. The first two prevent whole vulnerability classes; the rest close narrower gaps.
Why is unsafe-inline a problem in CSP?
Because it permits inline script execution, which is the primary mechanism of reflected and stored cross site scripting. A policy containing unsafe-inline in script-src provides essentially no protection against the attack CSP was designed to stop.
How do I deploy CSP without breaking the site?
Send Content-Security-Policy-Report-Only with a report-uri or report-to first. Collect violations for a week or two, fix or allowlist the legitimate sources, then switch the header to enforcing. Going straight to enforcement on a site of any size reliably breaks something.
Should I still send X-XSS-Protection?
No. The filter it enabled has been removed from every modern browser and it introduced its own information disclosure issues. If you send it at all, send 0. A correct CSP replaces it entirely.
What does HSTS preload actually do?
It embeds your domain in a list shipped with browsers, so they never make a plaintext request to it even on the very first visit. Submission requires max-age of at least one year, includeSubDomains and the preload token, and removal takes months, so it is a genuine commitment.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Choose the protections you need and copy the generated header configuration for your server.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Password Strength Checker
SecurityMeasure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
Password Generator
SecurityGenerate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
Hash Generator
SecurityGenerate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.