Build robust Content Security Policy (CSP) headers. Protect your site from XSS and data injection with our interactive policy builder.
Use this in an HTTP response header.
Use this inside the HTML document head when headers are not available.
Each directive is broken into its individual source expressions.