SSL & Security
CSP Builder
Build Your CSP
Generated CSP Policy
Content-Security-Policy — configure directives above to update
Tool features
Visual Builder
Policy Presets
Validation
Export Formats
What is a Content Security Policy & how it works
A Content Security Policy (CSP) is a response header that tells the browser exactly which sources a page may load scripts, styles, images, frames and connections from. Anything not on the list is blocked, which stops most cross-site scripting (XSS) and content-injection attacks.
A policy is a list of directives, each with its allowed sources. default-src sets the fallback, and specific directives such as script-src or img-src override it. Because a strict policy can break a site, the usual path is to deploy it in Report-Only mode first, fix what it reports, then enforce it.
How to use this tool
Related tools
Frequently asked questions
script-src: it re-enables the inline scripts that XSS relies on. Move inline code into files, or allow specific blocks with a nonce or hash. It is less risky in style-src.default-src 'self', then opening up only the specific directives that need more.