CSP Header Builder
Visually configure Content-Security-Policy directives and get a ready-to-use header.
Directives
Policy Value
HTTP Header
About Content Security Policy
Content Security Policy (CSP) is an HTTP response header that helps prevent XSS, clickjacking, and other code injection attacks. It specifies which dynamic resources are allowed to load.
Other Tools
Encode or decode text with multiple encoding and output format options.
Encode or decode URLs with different modes for different situations.
Encode or decode HTML special characters using named, decimal, or hex formats.
Convert any image file to a Base64 data URI for embedding in HTML or CSS.
Convert text to hex representation and back, with configurable separator and case.
Encode or decode URL components with configurable encoding modes.
Generate cryptographic hashes from any text. Optional HMAC secret.
Decode and inspect JWT tokens without a secret key. Header, payload, and expiry at a glance.