/web local tool
CSP Builder
Edit practical defaults and copy an enforced or report-only CSP header.
Local execution receiptinput path disclosedTool content stays out of MonoTools URLs and API requests.
- Working input
- Browser memory
- Cross-tool handoff
- Session only · 10 min
- URL payload
- Never
- Export
- Explicit action
Verify it: open DevTools Network, clear the log, use the tool, then inspect fetch/XHR requests. Page assets and optional aggregate analytics may use the network; tool input is not included.
Full privacy modelLoading tool...
01
How to use
- 01Edit each CSP directive source list.
- 02Toggle enforced or report-only mode.
- 03Copy the complete HTTP header.
02
FAQ
- Should I deploy CSP directly in enforced mode?
- Usually start with Report-Only in production, inspect violations, then enforce once legitimate resources are covered.
- Does this validate every possible CSP directive?
- No. It focuses on the directives most teams need first.
03
Related tools
- →/webHTTP Headers InspectorInspect HTTP syntax, policy conflicts and trust boundaries.
- →/webMagic PasteDetect pasted developer data and open the right tool.
- →/webcURL ConverterConvert cURL and match requests to local OpenAPI contracts.
- →/webStack Trace AnalyzerFind actionable frames in JavaScript and Python stacks.