Security Header and CSP Generator

Generate Content-Security-Policy, HSTS, X-Content-Type-Options and the rest, in plain, nginx or vercel.json form — with warnings for the settings that usually backfire.

Runs in your browser: input and output are never sent to the server, and the platform does not store your input.

Input

Not stored

Separate several origins with spaces or commas.

Output

Fill in the fields on the left, then run.

How to use

  1. 1Pick a strictness level and list the third-party origins your pages actually load.
  2. 2Choose an output format and copy it into your server config or vercel.json.
  3. 3Ship it as Report-Only for a few days, check the console for false positives, then switch it on for real.

FAQ

Why start with Report-Only?

A wrong CSP blocks scripts or styles outright, often only on a page you did not test. Report-Only lets the browser load everything while reporting violations, so you can complete the list without breaking anything for visitors.

What is wrong with 'unsafe-inline'?

It permits every inline script on the page, and inline scripts are exactly what an XSS injects. A nonce or a hash allows only the ones you emitted yourself.

How do I generate the nonce?

Produce a fresh random value per request (16 random bytes, base64 encoded, is plenty) and put the same value in the CSP header and in that response's script tags. Reusing one nonce removes the protection entirely.

What is the risk with HSTS preload?

The preload list is compiled into browsers, so removal takes several release cycles. It also covers every subdomain — one subdomain without HTTPS becomes unreachable.

Is my input uploaded?

No. This is plain string generation running entirely in your browser; no sign-in and no quota.