Security Headers - Free Online HTTP Security Header Generator Tool | IconVault
Generate copy-paste HTTP security headers for nginx, Apache and more: CSP, HSTS, X-Frame-Options and friends. Free, in your browser.
Security Headers
Copy-paste security headers for nginx and Apache
Strict-Transport-Security
+25 ptsForces HTTPS for all future visits, blocking SSL-stripping attacks.
Content-Security-Policy
+20 ptsRestricts where scripts, styles and other resources may load from.
X-Content-Type-Options
+15 ptsStops browsers guessing content types, blocking MIME-sniffing attacks.
X-Frame-Options
+15 ptsRefuses to render inside frames, blocking clickjacking.
Permissions-Policy
+15 ptsDisables powerful features (camera, mic, geolocation) your site does not use.
Referrer-Policy
+10 ptsLimits how much referrer data leaks to other sites.
Your security grade
Excellent. A hardened header set.
Server config
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always; add_header Content-Security-Policy "default-src 'self'; object-src 'none'; base-uri 'self'" always; add_header X-Content-Type-Options "nosniff" always; add_header X-Frame-Options "DENY" always; add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always; add_header Referrer-Policy "strict-origin-when-cross-origin" always;
5 of 5 free copies left.
preload submits you to browser preload lists. Test every change, headers can break embedded content.About this tool
IconVault's Security Headers tool generates ready-to-paste HTTP security header configurations for your server. It covers Content-Security-Policy, Strict-Transport-Security (HSTS), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and Cross-Origin policies, with output formatted for nginx and Apache (plus plain header text you can adapt anywhere).
Generation runs 100% in your browser and it is free with no signup. The honest note: this tool writes the config, it does not scan your site. A strict Content-Security-Policy can break scripts, styles or embeds, so test on staging first and confirm with a real header scanner before calling it done.
Frequently asked questions
Popular searches
More tools
AES Encryptor
AES-256-GCM text encryption in your browser
HMAC Generator
HMAC-SHA signatures in hex or Base64, with tag verify mode
Header Analyzer
Paste raw response headers, get a security audit in seconds
JWT Builder
Sign and verify HS256/HS384/HS512 tokens
Coming soon
CLI
Coming soon
Figma plugin
Coming soon
VS Code extension
Coming soon
Chrome extension
Coming soon
AI icon generator
Coming soon
Team workspaces
Coming soon