CSP Builder & Validator

Build and validate Content-Security-Policy headers. Visual builder and security validator.

Build Content-Security-Policy headers with a visual builder and validate existing CSP for unsafe-inline, wildcards, and missing directives. Runs in your browser.

Frequently Asked Questions

What does the validator flag?

Unsafe-inline, wildcard origins, missing form-action or frame-ancestors, and overly permissive object-src.

More Security Tools

Explore Other Tool Hubs