CSP & Security Headers Builder LOCAL ONLY

Build a Content-Security-Policy, inspect common gaps, and export header snippets for Nginx or Apache without scanning your site.

Policy editor

Paste an existing CSP to inspect it, or use the builder on the right. This tool analyzes only the text you enter.

Policy findings
Paste or build a CSP, then select Analyze policy.
Quick policy builder

Enter source expressions without the directive name. Leave a field blank to omit that directive.

Additional response headers

Only use HSTS after HTTPS is correctly configured for every relevant subdomain. Review generated values against your application requirements.

HTTP headers
Build a CSP, then generate header snippets.
Nginx
Build a CSP, then generate header snippets.
Apache
Build a CSP, then generate header snippets.

Start restrictive, then observe and refine

A CSP should match the resources your application genuinely needs. Roll it out carefully, consider report-only testing first, and avoid copying a policy between sites without reviewing scripts, frames, APIs, and third-party assets.

Recent tools: