Skip to content

CSP Builder

Build a Content-Security-Policy header interactively. Toggle directives, add sources, see the assembled header in real time — with a security score that flags unsafe sources.

Privacy & Security
cosmodev ~/tools/csp-builder-

Security score 90/100 · 0 directives enabled

  • No default-src - every directive you don't set explicitly falls back to the browser's permissive default.

Fallback for every fetch directive you do not set explicitly. Set this first, then tighten individual directives.

No sources yet - this directive will be omitted until you add one.

Enable directives above - the assembled header appears here.