CSP Builder - Free Online Content Security Policy Tool | IconVault

Build a Content-Security-Policy header visually: toggle directives, add sources with one click, start from strict, balanced or legacy presets. Free.

All tools

CSP Builder

Build a Content-Security-Policy header visually

5 of 5 free uses left
Start from a preset:

default-src

Fallback for every fetch directive

script-src

Where scripts may load from

style-src

Where stylesheets may load from

img-src

Where images may load from

connect-src

fetch, WebSocket, EventSource targets

font-src

Where fonts may load from

frame-src

Where frames may be embedded from

media-src

Where audio/video may load from

object-src

Plugins and embeds (usually 'none')

base-uri

Allowed <base> tag URLs

form-action

Where forms may submit to

frame-ancestors

Who may embed this page

Generated header

default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; connect-src 'self' https:; font-src 'self' https: data:; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; upgrade-insecure-requests

5 of 5 free copies left.

Deploy with the Content-Security-Policy response header, or as a <meta http-equiv> tag for testing. Meta tags cannot use frame-ancestors or reporting.

About this tool

IconVault's CSP Builder turns writing a Content-Security-Policy header into clicking instead of memorizing. Toggle any of 12 directives, from default-src and script-src to frame-ancestors and form-action, and add sources with one-click chips like 'self', 'none', https:, data: and blob:. You can also type custom hosts and hashes.

Start from a Strict, Balanced or Legacy preset instead of a blank page, watch the finished header assemble live, and copy it when it looks right. The strict preset flags the tradeoff honestly: maximum protection means inline scripts and styles are blocked, so you will need nonces or hashes. Free and runs fully in your browser.

Frequently asked questions

Popular searches

csp buildercontent security policy buildercsp header buildercsp generatorcsp policy generatorcontent security policy generatorbuild csp headercsp header generatorgenerate content security policycsp directive builderscript src builderdefault src cspcsp strict policycsp balanced presetcsp legacy presetcsp nonce alternativecsp without unsafe inlineremove unsafe inline cspcsp policy examplecsp header examplecontent security policy examplecsp for websitecsp for react appcsp wordpresscsp nginx headercsp apache headercsp express helmethelmet csp buildercsp frame ancestorscsp form actioncsp base uricsp object src nonecsp img srccsp connect srccsp font srccsp style srccsp script src selfcsp policy testercsp syntax checkeronline csp builderfree csp generatorweb security headerssecurity header builderxss protection headerprevent xss cspcsp cheat sheetcsp quick referencecsp source listcsp header copy pastecontent security policy quickstartcsp sandbox directivecsp upgrade insecure requests

More tools

Coming soon

CLI

Coming soon

Figma plugin

Coming soon

VS Code extension

Coming soon

Chrome extension

Coming soon

AI icon generator

Coming soon

Team workspaces

Coming soon

View all 10+ tools →