Security · resource loading

Content security policy.

Assemble a readable CSP, inspect source expressions, and test a report-only draft before enforcement. Your policy text stays in this browser.

MDN + W3C reviewed 29 September 2026HTTP response header · not a penetration test

Advertisement

Generate a header

SourcesSpace-separated expressions; keep the list narrow.

The starter policy is intentionally conservative. This generator never invents a nonce or hash. Add those server-generated values only after you have tied them to exact response content.

Generated header

Generate a header to see the result.

The validator will flag unknown directives, malformed sources, and risky allowances.

Validate an existing policy

Paste only a policy you are authorized to inspect.

Your validation result will appear here.

What this checks

Nonce and hash guidance: a nonce must be unpredictable and freshly generated for each response; a hash must match the exact inline content. This page only recognises their shape and never fabricates a security token or proves deployment safety.

MDN CSP header reference · MDN CSP deployment guide · W3C CSP Level 3

Advertisement
Advertisement
Listening…