CSP Report-Only Analyzer

Paste CSP violation logs (browser console) or JSON reports. Get suggested directive updates. Client-side only.

home · tools · csp builder

1) Paste violations

Supports common Chrome/Firefox console strings and JSON bodies containing csp-report.


2) Merge into an existing CSP (optional)

Paste your current CSP header value below, then merge suggestions into it (union sources per directive).

Open in CSP Builder

This tool suggests additions; it cannot know your full intent. Prefer least privilege and avoid wildcards.

How to use

Safety notes