CSP Reporting Wiring Wizard

Given an endpoint URL, generate: Report-To header, Content-Security-Policy-Report-Only header, and a clean enforce CSP. Client-side only.

home · tools · csp builder

1) Inputs

Tip: Start with Report-Only for a day, then enforce once violations are handled.

2) Outputs

Open enforce CSP in Builder

3) Test your reporting endpoint

Generate a sample CSP report payload + curl POST so you can validate your endpoint before waiting for real violations.