UnQTools
Network, Runs in your browser

CSP Generator

Build a Content-Security-Policy header directive-by-directive and evaluate it live for XSS bypasses (unsafe-inline, wildcards, missing object-src/base-uri). Supports strict-dynamic + nonce/hash, Report-Only, reporting endpoints, Nginx/Apache/meta output, and paste-to-audit. 100% client-side.

100% Private Works Offline Instant

Build a Content-Security-Policy header directive-by-directive and evaluate it live for XSS bypasses (unsafe-inline, wildcards, missing object-src/base-uri). Supports strict-dynamic + nonce/hash, Report-Only, reporting endpoints, Nginx/Apache/meta output, and paste-to-audit. 100% client-side. Everything runs locally in your browser — your data never leaves your device.

How to use

  1. Enter your input in the tool above.
  2. Adjust any options to your preference.
  3. Use the Copy or Download buttons to save the result.
  4. Everything happens locally — your data never leaves your browser.