Security Headers - Free Online HTTP Security Header Generator Tool | IconVault

Generate copy-paste HTTP security headers for nginx, Apache and more: CSP, HSTS, X-Frame-Options and friends. Free, in your browser.

All tools

Security Headers

Copy-paste security headers for nginx and Apache

5 of 5 free uses left

Strict-Transport-Security

+25 pts

Forces HTTPS for all future visits, blocking SSL-stripping attacks.

Content-Security-Policy

+20 pts

Restricts where scripts, styles and other resources may load from.

X-Content-Type-Options

+15 pts

Stops browsers guessing content types, blocking MIME-sniffing attacks.

X-Frame-Options

+15 pts

Refuses to render inside frames, blocking clickjacking.

Permissions-Policy

+15 pts

Disables powerful features (camera, mic, geolocation) your site does not use.

Referrer-Policy

+10 pts

Limits how much referrer data leaks to other sites.

Your security grade

A
100 / 1006 of 6 headers

Excellent. A hardened header set.

Server config

add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;
add_header Content-Security-Policy "default-src 'self'; object-src 'none'; base-uri 'self'" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-Frame-Options "DENY" always;
add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;

5 of 5 free copies left.

HSTS needs HTTPS to work, and preload submits you to browser preload lists. Test every change, headers can break embedded content.

About this tool

IconVault's Security Headers tool generates ready-to-paste HTTP security header configurations for your server. It covers Content-Security-Policy, Strict-Transport-Security (HSTS), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and Cross-Origin policies, with output formatted for nginx and Apache (plus plain header text you can adapt anywhere).

Generation runs 100% in your browser and it is free with no signup. The honest note: this tool writes the config, it does not scan your site. A strict Content-Security-Policy can break scripts, styles or embeds, so test on staging first and confirm with a real header scanner before calling it done.

Frequently asked questions

Popular searches

security headershttp security headerssecurity headers generatorgenerate security headerscontent security policy generatorcsp generatorstrict transport security headerhsts header generatorx frame options headerclickjacking protection headerx content type optionsreferrer policy headerpermissions policy headercross origin opener policycross origin embedder policynginx security headersapache security headerssecurity headers for nginxsecurity headers for apachehtaccess security headerscloudflare security headerssecurity headers checkertest website security headerssecurityheaders.com alternativewebsite security headers testhttp headers best practicessecure http headers listowasp secure headersowasp http headers cheat sheetweb security headers explainedwhat are security headerswhich security headers should i usesecurity headers for next.jsnextjs security headers configsecurity headers for wordpresswordpress security headers plugin alternativesecurity headers vercelnetlify security headersexpress security headershelmet js alternativenode js security headerssecurity headers copy paste configfree security headers toolsecurity headers in browsergenerate csp header onlinecsp nonce vs hashframe ancestors directivexss protection headersprevent mime sniffing headerssl hsts preloadsecurity headers 2026modern security headers guide

More tools

Coming soon

CLI

Coming soon

Figma plugin

Coming soon

VS Code extension

Coming soon

Chrome extension

Coming soon

AI icon generator

Coming soon

Team workspaces

Coming soon

View all 10+ tools →