HTTP & WebLOCALRuns in your browser
CSP Builder
Compose a Content-Security-Policy field value from common directives and source expressions in your browser.
This tool handles input and primary processing in your browser and is designed not to send the input to QuickKit’s server.
CSP field value
How it works
Choose only the directives and source expressions you intend to send. The result is a syntactically formatted CSP field value, not a security review or a guarantee that a policy fits your application. No nonce, hash, secret, or network request is generated; all editing stays in this browser.