Content Security Policy Builder
Build a CSP header from drop-down policies for each directive.
- Developer
- Free to use
- Runs in your browser
Your input
Set your options
Run Content Security Policy Builder
Private by default. Runs entirely in your browser — files never uploaded.
Three steps
How to use Content Security Policy Builder
- Step 01
Pick your input
Paste your text into the box above.
- Step 02
Configure & run
Adjust the options (default src, script src, style src, img src, font src, connect src, frame ancestors, upgrade insecure requests, report uri) and click Run. Everything happens in your browser via WebAssembly.
- Step 03
Download the result
A JSON document is downloadable below.
This tool runs entirely in your browser. Your file is never uploaded to our servers.
About content security policy builder
Build a CSP header from drop-down policies for each directive. It sits in the developer shelf alongside 76 other developer tools, needs no account, and keeps the same behaviour whether you open it here or call it through the REST API.
It works from what you type in rather than a file and gives back JSON. The work happens in your browser, so nothing is sent to us at all and the tool keeps working offline. The same operation is available programmatically at POST /v1/dev/csp-builder.
Content Security Policy Builder questions
Does Content Security Policy Builder upload my file?
No. Content Security Policy Builder runs as WebAssembly inside this browser tab: the file is read from your disk by the page, processed on your own machine, and handed straight back. It is never sent anywhere, so there is nothing for us to store or delete.
Do I need an account to use Content Security Policy Builder?
No. Content Security Policy Builder works without signing in, and that is not a trial — it is how the free tier works. An account only matters for things that need one to exist at all: larger server jobs against your quota, API keys, saved workflows and billing.
Can I run Content Security Policy Builder from my own code?
Yes. Every tool on the site is reachable from the REST API with the same slug — `csp-builder` — and the same options as this page, so anything you can do here you can automate against your own files.
Related tools
- Cron Expression GeneratorBuild a cron expression from minute / hour / day / month dropdowns.
- CSS Grid GeneratorBuild CSS grid layouts visually.
- Email Signature GeneratorBuild a HTML email signature with name, title, logo, and social icons.
- Favicon GeneratorBuild a complete favicon set from one image — manifest, .ico, every size.
- CSS Flexbox GeneratorBuild flexbox layouts visually; copy CSS.
- Gradient GeneratorBuild a CSS gradient from N colours.