DEVELOPER WORKBENCH

Content Security Policy Builder

Draft a Content Security Policy from readable directives, inspect source lists and review notes, and export response-header, Nginx, Apache or Express snippets.

Local processingEditable exampleCopy + file exports

Settings

Try the example or enter your own settings.

A CSP draft can break scripts, styles, embedded tools and ads. Test it on your own staging site and review violations before enforcement. This tool does not modify ToolSorcerer’s policy, verify browser behavior or configure reporting endpoints.

Using Content Security Policy Builder

Draft a Content Security Policy from readable directives, inspect source lists and review notes, and export response-header, Nginx, Apache or Express snippets.

  1. Enter one directive and its space-separated sources per line, or load the static-site example.
  2. Choose report-only or enforced mode and your server output format. Review broad-source and missing-directive notes.
  3. Copy or download the draft, then test it in staging with the resources your site actually uses before installing it.

Example

Try the included editable example.
Choose report-only or enforced mode and your server output format. Review broad-source and missing-directive notes.

Questions & answers

Does this secure my website automatically?

No. It produces a text draft. Effective protection depends on your application, response headers, browser behavior and deployment testing.

Why start in report-only mode?

Report-only is intended for testing without general enforcement. A report-to directive also needs a separate Reporting-Endpoints header and receiver. This page does not collect violations.

What source syntax is supported?

The supported subset includes quoted keywords, nonce/hash expressions, selected schemes and HTTP/HTTPS/WS/WSS host sources, optional wildcard subdomains and paths. Complex sources, IPv6 literals and unknown directives are rejected rather than guessed.

Does default-src protect every directive?

No. In particular frame-ancestors, base-uri and form-action require explicit consideration. The tool flags selected absent directives but does not evaluate all fallback relationships.

Can I use unsafe-inline or unsafe-eval?

They can be entered, but are flagged for review. Their presence can weaken restrictions. Nonces must be unpredictable and generated anew per response; this tool does not mint or manage them.

Can I copy it into a meta tag?

This version generates response headers/server snippets rather than meta tags. Some directives and report-only policies are unsupported in meta delivery. Source input is capped at 12,000 characters and generated policy at 8,000 characters.

Help improve this tool

Report a problem or suggest an improvement

Describe the issue without pasting private tool input. Feedback goes to our admin inbox.

Find another tool · Read practical guides