CSP Generator

Content Security Policy Generator & CSP Scanner

Enter a public URL to see what your site loads and build an editable Content Security Policy header. Review the browser-based scanner's findings, copy your candidate, and test it in report-only mode. Premium monitoring helps you track changes after that first scan.

Run the free CSP scanner and Content Security Policy generator or learn how Content Security Policy works.

scan: chrome crawl: 3 free / 10 premium output: CSP header
Discover

Observe Browser Resources

Load selected public pages in Chrome and inspect the scripts, styles, images, fonts, frames, connections, and inline-code evidence observed during the scan.

Generate

Build and Review a CSP Candidate

Turn browser evidence into an editable policy, review broad or risky values, and optionally add SHA-256 sources for inline content observed on scanned pages.

Test

Move Through Report-Only First

Copy deployment-formatted headers, test representative application flows without blocking them, and review violation evidence before enforcement.

Monitor

Review CSP Drift Over Time

Verified-site monitors compare recurring scan evidence with an accepted baseline so new and removed sources remain visible during rollout and maintenance.