security.txt Generator

security.txt Generator

Build an RFC 9116 security.txt file: configure Contact, Expires, Encryption, Acknowledgments, Preferred-Languages, Canonical, Policy, and Hiring fields, with live preview and download. Also parses an existing security.txt back into the form.

Per RFC 9116, publish the generated file at /.well-known/security.txt at your domain's root (a legacy /security.txt location is also checked by some tools, but /.well-known/ is canonical). Contact and Expires are the only required fields — set Expires to a date no more than a year out and remember to refresh it before it lapses.

security.txt Generator

Build an RFC 9116 security.txt file: configure Contact, Expires, Encryption, Acknowledgments, Preferred-Languages, Canonical, Policy, and Hiring fields, with live preview and download. Also parses an existing security.txt back into the form.

Common uses

  • Generate a security.txt with a PGP key link
  • Build a vulnerability disclosure contact file
  • Parse an existing security.txt

Frequently asked questions

Can I use security.txt Generator to generate a security.txt with a PGP key link?

Yes. security.txt Generator can generate a security.txt with a PGP key link, directly in your browser.

Can I use security.txt Generator to build a vulnerability disclosure contact file?

Yes. security.txt Generator can build a vulnerability disclosure contact file, directly in your browser.

Can I use security.txt Generator to parse an existing security.txt?

Yes. security.txt Generator can parse an existing security.txt, directly in your browser.

Is my data uploaded to a server?

No. This tool runs entirely in your browser — your input is processed locally on your device and is never uploaded or stored on a server.