Content Security Policy Generator & Analyzer

Generates a Content Security Policy directive by directive (sources, schemes, nonces, hashes, 'strict-dynamic'), with output as an enforcement header, a Report-Only header, a <meta> tag, or a sample Next.js configuration. Analyzes a pasted policy, detecting duplicate directives, unknown values, broad wildcards, 'unsafe-inline'/'unsafe-eval', missing object-src/base-uri/frame-ancestors/form-action, and quoting errors. It never tests the policy against a real URL and never claims CSP replaces escaping and sanitizing content.

Processed on your device, no AIhasta 60 directivas, 100 fuentes por directiva

Data is processed on your device and never sent to the server.

CSP is an additional layer and doesn't replace escaping, validation, and sanitization of content.

Report-Only lets you observe issues before enforcing the policy, but doesn't block any resources.

The data is processed on your device and is never sent to the server.

Use cases

How to use this tool

  1. Choose to generate or analyze
  2. Fill in the directives or paste the existing policy
  3. Copy or download the result

Frequently asked questions

Does CSP prevent all XSS attacks?
No. CSP is an additional layer of defense, not a substitute for escaping, validating, and sanitizing content; this tool states that explicitly and never claims total protection.
What's the difference between the normal header and Report-Only?
Report-Only lets you observe what the policy would block (via reports) without actually blocking any resource yet; it's useful for testing a policy before really enforcing it.

Related tools

← Back to home