Paste CSP violation logs (browser console) or JSON reports. Get suggested directive updates. Client-side only.
Supports common Chrome/Firefox console strings and JSON bodies containing csp-report.
Paste your current CSP header value below, then merge suggestions into it (union sources per directive).
This tool suggests additions; it cannot know your full intent. Prefer least privilege and avoid wildcards.
Content-Security-Policy-Report-Only first to collect violations./csp.html), then iterate.*, 'unsafe-inline', 'unsafe-eval' unless you accept the risk.https://cdn.example.com (not full paths)./csp-nonce.html and /csp-hash.html).