Dev
Generator für Mock-CSP-Header
A mock CSP header generator produces example Content-Security-Policy headers for learning, testing, and documentation. CSP is a powerful browser security feature that controls which sources a page may load scripts, styles, images, and other resources from, helping defend against cross-site scripting and injection attacks. This tool emits valid CSP headers at different strictness levels, from a locked-down policy to a report-only one. Choose a level and copy the header. It is ideal for learning CSP, hardening a site, and documenting security headers. The headers follow the real CSP syntax, so they show how directives like default-src, script-src, and frame-ancestors restrict resource origins. A practical tip: start with a report-only policy to see what a strict CSP would block before enforcing it, since a too-tight policy can break a working site. Adapt the directives and allowed sources to your own application before deploying.
How to use
- Choose your options above
- Click Generate
- Copy your result
Detailed instructions
- Choose a strictness level.
- Click Generate to produce a CSP header.
- Test it in report-only mode first.
- Adapt the sources to your app.
Use Cases
- •Learning Content-Security-Policy
- •Hardening a website
- •Documenting security headers
- •Testing CSP configuration
- •Demoing web security
Tips
- →Start with report-only mode.
- →A strict CSP can break a site.
- →Allow only the sources you need.
- →frame-ancestors guards against clickjacking.
FAQ
what does Content-Security-Policy do
CSP tells the browser which sources a page may load scripts, styles, images, and other resources from. By restricting origins, it helps prevent cross-site scripting and injection attacks, since injected code from an untrusted source is blocked.
what is report-only mode
A report-only CSP does not block anything but reports what a policy would have blocked, to a URL you specify. It lets you test a strict policy against a live site safely before enforcing it, avoiding breakage from a too-tight policy.
why might a strict CSP break my site
A strict policy can block scripts, styles, or resources your site actually relies on — inline scripts, third-party widgets, or CDNs. Starting in report-only mode reveals what would break, so you can allow the legitimate sources before enforcing.
What does a Content-Security-Policy header do?
A CSP header tells the browser which sources of scripts, styles, images, and other resources are allowed to load, which blocks most cross-site scripting (XSS) and injection attacks by refusing anything not on your allowlist. Directives like default-src 'self' restrict loading to your own origin. The generator produces example policies at different strictness levels to adapt.
You might also like
Popular tools from other categories that share themes with this one.
Try these next
More free tools from other corners of the catalog, picked by shared themes.