CSP Header Generator
Build a Content-Security-Policy header by configuring each directive.
Build a Content-Security-Policy header by configuring each directive.
Fallback for other fetch directives
Valid sources for JavaScript
Valid sources for stylesheets
Valid sources for images
Valid sources for fonts
Valid targets for fetch, XHR, WebSocket
Valid sources for frames/iframes
Valid sources for <object>, <embed>
Valid sources for audio/video
Valid URLs for the <base> element
Valid endpoints for form submissions
Who can embed this page in a frame
Content-Security-Policy: default-src 'self'; upgrade-insecure-requests