CSP Header Builder
Build Content-Security-Policy headers visually with presets, per-directive toggles, and custom domain inputs.
All processing happens in your browser
Presets
default-src
script-src
style-src
img-src
font-src
connect-src
frame-src
media-src
object-src
CSP Header
default-src 'self'
Usage in HTTP header:
Content-Security-Policy: default-src 'self'