Content Security Policy Generator
Build CSP headers to protect your website against XSS and code injection attacks.
Build a Content Security Policy header to protect your site against XSS, clickjacking, and other code injection attacks.
Presets:
default-srcFallback for other directivesscript-srcJavaScript sourcesstyle-srcCSS sourcesimg-srcImage sourcesfont-srcFont sourcesconnect-srcAJAX, WebSocket, fetch sourcesmedia-srcAudio/video sourcesobject-srcPlugin sources (Flash, etc.)frame-srciframe sourcesframe-ancestorsWho can embed this pagebase-uriRestrict base element URLsform-actionForm submission targetsupgrade-insecure-requestsUpgrade HTTP to HTTPSblock-all-mixed-contentBlock HTTP on HTTPS pages