CSP Generator
Build a Content-Security-Policy header directive-by-directive and evaluate it live for XSS bypasses (unsafe-inline, wildcards, missing object-src/base-uri). Supports strict-dynamic + nonce/hash, Report-Only, reporting endpoints, Nginx/Apache/meta output, and paste-to-audit. 100% client-side.
Build a Content-Security-Policy header directive-by-directive and evaluate it live for XSS bypasses (unsafe-inline, wildcards, missing object-src/base-uri). Supports strict-dynamic + nonce/hash, Report-Only, reporting endpoints, Nginx/Apache/meta output, and paste-to-audit. 100% client-side. Everything runs locally in your browser — your data never leaves your device.
How to use
- Enter your input in the tool above.
- Adjust any options to your preference.
- Use the Copy or Download buttons to save the result.
- Everything happens locally — your data never leaves your browser.