Uploadless

CSP Header Builder

Build Content-Security-Policy headers visually with presets, per-directive toggles, and custom domain inputs.

All processing happens in your browser

Presets

default-src
script-src
style-src
img-src
font-src
connect-src
frame-src
media-src
object-src
CSP Header
default-src 'self'

Usage in HTTP header:

Content-Security-Policy: default-src 'self'