For strict CSPs without 'unsafe-inline': hash inline script/style content, or generate a nonce and add it to the matching directive.
Build a Content Security Policy header by enabling directives and entering allowed sources. Copy the header value or the .htaccess snippet when done.
Visual builder for Content Security Policy headers. Enable and configure 18 directives; add source expressions as chips; get live warnings for unsafe-inline and unsafe-eval; copy the ready-to-use header string. Also includes an Evaluate mode to paste an existing CSP header and get a graded security report.
Yes. CSP Builder can build a CSP allowing scripts from a CDN, directly in your browser.
Yes. CSP Builder can configure a nonce-based script-src directive, directly in your browser.
Yes. CSP Builder can evaluate an existing CSP header for weaknesses, directly in your browser.
No. This tool runs entirely in your browser — your input is processed locally on your device and is never uploaded or stored on a server.