Axiomatic ToolsFree Fast Essential

Content Security Policy Builder

Build a CSP header from drop-down policies for each directive.

  • Developer
  • Free to use
  • Runs in your browser
Use via API

Your input

0 chars

Set your options

Options9 settings

Run Content Security Policy Builder

Private by default. Runs entirely in your browser — files never uploaded.

Report a bug

Three steps

How to use Content Security Policy Builder

  1. Step 01

    Pick your input

    Paste your text into the box above.

  2. Step 02

    Configure & run

    Adjust the options (default src, script src, style src, img src, font src, connect src, frame ancestors, upgrade insecure requests, report uri) and click Run. Everything happens in your browser via WebAssembly.

  3. Step 03

    Download the result

    A JSON document is downloadable below.

This tool runs entirely in your browser. Your file is never uploaded to our servers.

About content security policy builder

Build a CSP header from drop-down policies for each directive. It sits in the developer shelf alongside 76 other developer tools, needs no account, and keeps the same behaviour whether you open it here or call it through the REST API.

It works from what you type in rather than a file and gives back JSON. The work happens in your browser, so nothing is sent to us at all and the tool keeps working offline. The same operation is available programmatically at POST /v1/dev/csp-builder.

Content Security Policy Builder questions

Does Content Security Policy Builder upload my file?

No. Content Security Policy Builder runs as WebAssembly inside this browser tab: the file is read from your disk by the page, processed on your own machine, and handed straight back. It is never sent anywhere, so there is nothing for us to store or delete.

Do I need an account to use Content Security Policy Builder?

No. Content Security Policy Builder works without signing in, and that is not a trial — it is how the free tier works. An account only matters for things that need one to exist at all: larger server jobs against your quota, API keys, saved workflows and billing.

Can I run Content Security Policy Builder from my own code?

Yes. Every tool on the site is reachable from the REST API with the same slug — `csp-builder` — and the same options as this page, so anything you can do here you can automate against your own files.

Related tools

Content Security Policy Builder — Free, Online · Axiomatic Tools