Content Security Policy Generator
Build a Content-Security-Policy header with sensible defaults.
Input
Settings
Run
Results
Results will appear here once you run the tool.
About Content Security Policy Generator
Build a Content-Security-Policy header with sensible defaults. Content Security Policy Generator needs no input file — choose your settings and it generates the result straight away.
Your files stay on your device. ZyncTools has no upload step: the file is read in your browser, processed there, and handed straight back to you. There is no account, no watermark and no size cap beyond what your own device can hold.
Settings. Content Security Policy Generator gives you control over start from, default to 'self', extra script sources, extra style sources, extra font sources, extra image sources, extra connect sources and allow inline styles ('unsafe-inline'), plus 5 more.
Also known as: csp, content security policy, header, security, xss, nginx, apache.
How to use Content Security Policy Generator
- Open the tool. Open Content Security Policy Generator. There is nothing to upload — it works from the settings alone.
- Choose your settings. Adjust start from, default to 'self', extra script sources and the other 10 settings to suit what you need.
- Generate. Press Generate. The result appears immediately and updates whenever you change a setting.
- Save the result. Copy the output, or press Download to save it. Nothing is kept once you close the tab.
Frequently asked questions
Are my files uploaded when I use Content Security Policy Generator?
No. Content Security Policy Generator runs entirely inside your browser. Your file is read locally, processed on your own device, and handed straight back to you. You can confirm this yourself: open your browser's developer tools, watch the Network tab, and run the tool — no request carries your data anywhere.
Is Content Security Policy Generator free?
Yes, completely. No account, no sign-up, no watermark on your output, and no cap on how many times you can use it. The project is open source under the AGPL licence.
Does Content Security Policy Generator work offline?
Mostly. The site caches itself after your first visit, so it keeps working without a connection. Tools that need a specialised library — PDF editing, OCR, QR codes, MP3 encoding — need a connection the first time you run them, then that library is cached too.