Content Security Policy builder

Draft a restrictive response policy from the HTTPS origins your page needs.

On your device · No account
Privacy details

Content Security Policy builder processes your input in this browser. Inputs and results are excluded from analytics. Recent tools save tool names, visit counts and last-visit times. Saved tools store only their names. Draft saving is optional and stays on this device; delete saved text with the draft controls. Loading text from a URL is optional and contacts that server; its URL and your IP address are visible to the server. An optional “Use in” action keeps a handoff in this tab. The next tool removes it on arrival and ignores it if more than a minute has passed.

Copy link includes the inputs you choose to share in the address. Anyone with that link can reopen them. Files and generated results are excluded. Password and key tools share settings only.

Leave blank to use only same-origin resources.

More options

Your result

Reset reloads the tool with its starting values and releases open files and device controls. Saved drafts stay on this device until you delete them.

Links include your inputs and settings. Anyone with the link can see them, so leave out private text. Files and generated results are left out; random draws run again.

Keyboard shortcuts

Updated

Using Content Security Policy builder

Content Security Policy builder accepts explicit HTTPS origins and generates separate directives. It rejects paths and injected directives instead of silently broadening the policy.

Next: Cache-Control builder

A worked example

An empty origin list allows same-origin scripts, styles, images, fonts and connections while setting default-src to none.

Before you use the result

This is a starting policy, not a security audit. It does not support inline code, nonces, hashes, workers or frames. Report-only does not block resources and no reporting endpoint is configured. Validate it against your application before enforcement.

Cite this page

ToolOctopus. “Content Security Policy builder.” Updated 2026-09-19. https://tooloctopus.com/content-security-policy-builder.

Add an access date if your instructions require one.

Citation formatting uses citeproc-js by Frank Bennett and Citation Style Language styles. Licence and source code.

Find a tool

Search by task. Use ↓ and ↑ to choose, Enter to open.