Content-Security-Policy generator
Your policy
{{ directives.filter(d => tokensFor(d).length).length }} directive(s)Type or paste a policy here (with or without a leading
Content-Security-Policy:), or use the form below — the two stay in sync.Quick start
A preset replaces the whole policy below — fine-tune from there.
Rewrites any
http:// sub-resource request on the page to https:// before it's sent.Legacy but still the most widely supported way to collect violation reports.
Names a group from a
Reporting-Endpoints header - the modern replacement for report-uri.How to publish
- Prefer sending it as a real HTTP response header -
Copy header lineabove gives you the exact line to set in your web server / app framework config. - Can't set headers? A few directives (
frame-ancestors,report-uri,report-to, and sandboxing) are ignored inside an HTML<meta>tag - the header is always the more complete option. - Turn on Report-Only first and watch your reporting endpoint / browser console for a few days before enforcing - a policy that's too strict silently breaks the page instead of erroring loudly.
- Once quiet, switch off Report-Only so the policy actually blocks violations.
{{ n.text }}
Everything happens in your browser - nothing you enter here is submitted to SYSBOX or anywhere else.