CSP Generator

Generate Content Security Policy headers with an interactive directive builder

All data stays in your browser
default-src
script-src
style-src
img-src
font-src
connect-src
frame-src
object-src

HTTP Header

Content-Security-Policy: default-src 'self'

HTML Meta Tag

<meta http-equiv="Content-Security-Policy" content="default-src 'self'">

Policy String

default-src 'self'