Start strict where possible
Use `'self'`, explicit provider origins, `object-src 'none'`, and `base-uri 'self'` before adding broader exceptions.
Security headers · CSP builder · deployment snippets
Build CSP, HSTS, Referrer-Policy, Permissions-Policy, nosniff, and frame headers in this browser. Export HTTP header text plus Cloudflare Pages, Netlify, Apache, and Nginx snippets, then verify the deployed response with the live checker.
No sample CSP, security score, compliance badge, vulnerability result, ranking benefit, or manufactured header report appears before you choose policy settings.
Use `'self'`, explicit provider origins, `object-src 'none'`, and `base-uri 'self'` before adding broader exceptions.
Use report-only mode for discovery when a production site has unknown third-party scripts, then move to enforcement after fixes.
Cloudflare Pages, Netlify, Apache, and Nginx snippets are formatted differently. Review the selected output against the platform that will serve the final response.
