CSP Policy Builder

Generate a Content Security Policy based on your violations

Free CSP Policy Generator

Build secure Content Security Policies with our interactive tool. Get real-time security recommendations and best practices.

Policy Templates

Strict Security

Maximum security with minimal allowed sources

Balanced Security

Good security with common external sources allowed

Development Mode

Permissive policy for development (not recommended for production)

Generated Policy

Select a template or configure directives to generate a policy...

Configure Directives

Default source for all directives

JavaScript sources

CSS sources

Image sources

Network connections (AJAX, WebSocket)

Font sources

Plugin sources (Flash, Java)

Media sources (audio, video)

Frame sources (iframes)

Web worker sources

Web app manifest sources

Common Sources

script-src

style-src

img-src

connect-src

font-src

Implementation Guide

HTTP Header (Recommended)

Content-Security-Policy: your-policy-here

HTML Meta Tag

<meta http-equiv="Content-Security-Policy" content="your-policy-here">

Note: Start with report-only mode to test your policy before enforcing it:

Content-Security-Policy-Report-Only: your-policy-here

Need Help Monitoring Your CSP?

Don't just build CSP policies - monitor them! Get real-time alerts when your security headers change or violations occur.

Why Choose MetricPoints?

Complete CSP monitoring and security header management

24/7 Monitoring

Continuous monitoring of your security headers with instant alerts

Real-time Alerts

Get notified immediately when security headers change or violations occur

Detailed Analytics

Comprehensive reports and analytics on your security posture