Working…

Content-Security-Policy generator

Your policy

{{ directives.filter(d => tokensFor(d).length).length }} directive(s)
Type or paste a policy here (with or without a leading Content-Security-Policy:), or use the form below — the two stay in sync.

Quick start

A preset replaces the whole policy below — fine-tune from there.
Rewrites any http:// sub-resource request on the page to https:// before it's sent.
Legacy but still the most widely supported way to collect violation reports.
Names a group from a Reporting-Endpoints header - the modern replacement for report-uri.

How to publish

  1. Prefer sending it as a real HTTP response header - Copy header line above gives you the exact line to set in your web server / app framework config.
  2. Can't set headers? A few directives (frame-ancestors, report-uri, report-to, and sandboxing) are ignored inside an HTML <meta> tag - the header is always the more complete option.
  3. Turn on Report-Only first and watch your reporting endpoint / browser console for a few days before enforcing - a policy that's too strict silently breaks the page instead of erroring loudly.
  4. Once quiet, switch off Report-Only so the policy actually blocks violations.
{{ n.text }}
Everything happens in your browser - nothing you enter here is submitted to SYSBOX or anywhere else.