Content Security Policy Generator

Build, validate, and export CSP headers visually. Protect your site from XSS, clickjacking, and code injection attacks.

CSP Directives

(Upgrades HTTP to HTTPS)
(Deprecated, use upgrade-insecure-requests)

Generated CSP

Content-Security-Policy: default-src 'self'