Generate a strict Content-Security-Policy header (or <meta http-equiv>) from readable directives. Client-side only.
If you already have a CSP string, paste it here and click Parse to populate fields.
Notes: parsing is best-effort; directives not represented below are preserved under Other directives.
One directive per box. Space-separated sources. Leave blank to omit.
Tip: avoid 'unsafe-inline' and 'unsafe-eval' unless you fully understand the tradeoffs.
object-src 'none', base-uri 'self', frame-ancestors 'none' (if you don’t need embedding).'unsafe-inline', 'unsafe-eval', wildcard *.This tool does not phone home; everything stays in your browser.