CSP Generator and Pasted-Policy Checker

Draft a Content Security Policy from a strict baseline, or check a pasted policy for structural problems.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Build or check the policy controls

What do you want to do

Used when drafting. Both baselines start from default-src 'self' and allow no outside host.

Widens script-src and gives up much of what the policy is for.

Used in check mode. Paste the policy exactly as it appears in the header or meta tag.

Processed in your browser. Your inputs stay on this device.

Showing a generated example. Generate again for a new result.

How to use CSP Generator and Pasted-Policy Checker

  1. Leave the mode on Draft a policy, pick a baseline, and switch on any extra your own site needs.
  2. Read the drafted policy, copy it, and add it as a Content-Security-Policy response header on a test host.
  3. Switch to Check a policy I paste when you want to see how a policy you already have is written.
  4. Fix what the findings point at, then load the real site with the browser console open before you enforce anything.

Example: CSP Generator and Pasted-Policy Checker

Check a pasted policy that mixes an unquoted keyword and an empty directive into otherwise tidy rules.

You add
Mode: Check a policy I paste. Policy: default-src 'self'; script-src 'self' https://cdn.example.com 'unsafe-inline' self; style-src; report-uri /csp-report
You get
The summary reads 4 directives, 1 structural issue and 4 notes. The issue asks for self to be written as 'self' with single quotes. The notes cover unsafe-inline in script-src, the empty style-src, the deprecated report-uri, and the missing base-uri.

Options

Baseline
The same-origin baseline keeps every request on this site and blocks frames and objects. The second baseline adds media-src and worker-src for a site that serves its own audio, video and workers. Both start from default-src 'self' and allow no outside host, so neither one covers a site that loads scripts from a network. A policy built around nonces or hashes is stricter than either, and this page does not draft one.
Extra permissions
Each switch widens one directive: inline styles, inline scripts, eval-style code, Google Fonts, or YouTube frames. The result lists what each switch added, because every one of them gives the browser more room than the baseline does.
Findings
An issue is a structural problem such as an unquoted keyword, a comma between sources or an empty source list. A note is advice about a policy that may still work, such as a deprecated directive or a missing default-src. Neither kind says whether the policy suits your site.

Supported inputs and limits

Policies up to 8,000 characters. The checker reads structure only: it cannot tell which origins your site really loads, cannot see a response header, and never fetches or scans anything. Directive names come from CSP Level 3, so a newer or vendor name is reported as unknown even when a browser accepts it. A policy that reads cleanly can still break a page, and a policy a browser enforces can still be bypassed by a flaw it does not cover. Send it as Content-Security-Policy-Report-Only first and watch the reports before you enforce it.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

A policy constrains the browser, not the server

A Content Security Policy is a list of instructions the browser applies while it loads a page. It decides which scripts, styles, images, frames and connections the browser will accept, and it is applied after the page has been delivered. That makes it a second line of defence: content that slipped into the page still has to pass the policy before it runs. It is not a substitute for escaping and validating what the server renders, because a policy cannot repair a flaw that lets an attacker write the page in the first place. The browser also has the final say on which directives it supports, so the same policy can behave differently across versions.

MDN: Content Security Policy (CSP)

W3C: Content Security Policy Level 3

Why a first draft is a starting point

A worked example is the quickest way to see what a policy does. Load the page with the policy set to report-only, open the console, and read which requests the browser would have blocked. Each line names the directive that refused the request, so you learn which source has to be added and which one can be removed. A quiet report only covers the pages and flows you exercised, so walk through representative pages and actions before you consider enforcement, then keep watching afterwards, because a new script or font can end up blocked later.

Questions about CSP Generator and Pasted-Policy Checker

Does a clean check mean my site is secure?

No. The check reads how the text is written. A policy limits what the browser will load; it does not repair a flaw that lets an attacker put content into your page, and no policy can promise that a browser has no bypass.

Why is report-uri only a note?

It is deprecated in CSP Level 3 in favour of report-to, but many browsers still collect reports from it. Keeping both while support catches up is a common choice, so the checker advises instead of demanding a change.

Can it check the policy my site already sends?

Not directly, because nothing here makes a request. Open the response headers in your browser's network panel or in your server configuration, copy the Content-Security-Policy value, and paste that text into the policy box.

Why is a directive I copied called unknown?

The checker holds the directive names from CSP Level 3. A vendor-specific name, a newer draft name, or a misspelling is reported as unknown so you can check it against the specification rather than trusting a typo.

Will the drafted policy break my site?

It may, and that is expected for a first draft. A baseline that allows only your own origin blocks third-party scripts, fonts and frames. Send it in report-only mode, read what gets blocked, and add only the sources the site genuinely needs.

Project manager: Tony Hines · Content updated 29 September 2026 · Report a problem