Security utility

CSP Generator

Build a starter Content Security Policy string for website hardening, browser security review, and technical deployment planning with a fast browser-based workflow.

Generated policy
Common mistakes
  • deploying a restrictive policy without checking what scripts, fonts, or APIs your site actually loads
  • forgetting that inline scripts and third-party embeds often break under a stricter CSP
  • copying a sample policy directly into production without testing staging pages first