✓ Runs locally in your browser

Content Security Policy Builder

Generate Content-Security-Policy directives and an HTML meta equivalent locally.

Loading the local tool workspace…
About this tool

What is Content Security Policy Builder?

Content Security Policy Builder creates a restrictive starting policy from selected resource and embedding controls.

Three simple steps

How to use Content Security Policy Builder

  1. 01

    Enable the directives appropriate for your application's own resources.

  2. 02

    Add a reporting endpoint only when one is configured and trusted.

  3. 03

    Copy the HTTP header or HTML meta form and test it before enforcement.

Common questions

Content Security Policy Builder FAQ

Can I paste this policy into production without testing?

No. Inventory every legitimate resource source and validate the policy in report-only mode before enforcing it.

Is Content Security Policy Builder private to use?

Yes. Security values and pasted configuration data are processed locally and are not sent to Toolnera or external targets.