Content Security Policy (CSP) Guide for Developers
How to write Content Security Policy headers: directives, nonces, hashes, reporting, and common CSP mistakes.
Basic CSP
Content-Security-Policy: default-src 'self'; script-src 'self' 'nonce-abc123'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self' https://api.example.comKey Directives
default-src: Fallback for all resource typesscript-src: JavaScript sourcesstyle-src: CSS sourcesconnect-src: API/fetch/WebSocket targetsframe-src: iframe sources
Try It Free
Use our free online tool — 100% client-side, no data leaves your browser.
Open SSL Checker