CSP Builder

Generate a strict Content-Security-Policy header (or <meta http-equiv>) from readable directives. Client-side only.

home · tools · skill.md

1) Paste existing CSP (optional)

If you already have a CSP string, paste it here and click Parse to populate fields.

Notes: parsing is best-effort; directives not represented below are preserved under Other directives.

2) Configure directives

One directive per box. Space-separated sources. Leave blank to omit.

3) Output

Tip: avoid 'unsafe-inline' and 'unsafe-eval' unless you fully understand the tradeoffs.

Quick sanity checks

This tool does not phone home; everything stays in your browser.