Security · resource loading
Content security policy.
Assemble a readable CSP, inspect source expressions, and test a report-only draft before enforcement. Your policy text stays in this browser.
Generate a header
Generated header
Generate a header to see the result.
The validator will flag unknown directives, malformed sources, and risky allowances.
Validate an existing policy
Paste only a policy you are authorized to inspect.Your validation result will appear here.
What this checks
- Known CSP directives, duplicates, required values, and no-value directives
- Keywords, HTTPS origins, scheme sources, nonces, hashes, and wildcard hosts
- Warnings for unsafe-inline, unsafe-eval, broad HTTP/data sources, and missing fallbacks
- Enforce vs report-only header naming
Nonce and hash guidance: a nonce must be unpredictable and freshly generated for each response; a hash must match the exact inline content. This page only recognises their shape and never fabricates a security token or proves deployment safety.
MDN CSP header reference · MDN CSP deployment guide · W3C CSP Level 3