CSP Header Inspector
Paste a Content-Security-Policy header and get a browser-local release review: missing default-src, unsafe-inline, unsafe-eval, wildcard sources, mixed-content gaps, frame/object risk, report-only rollout notes, a copyable CSP rollout checklist, a safe verification pack with a starter Node header test, plus Apache and Nginx snippets. Nothing is uploaded.
Runs in your browser
Nothing uploaded
Free, no signup
Ctrl + Enter to run · Recent brings back your last inputs · Everything stays in this browser
CSP Header Inspector: questions
What should I paste into CSP Header Inspector?
Paste a raw Content-Security-Policy or Content-Security-Policy-Report-Only header, or just the directive value. The tool parses directives and flags risky source patterns locally.
Does this replace a browser console test?
No. It is a release-readiness checklist. Test the policy in a real browser with your production pages because CSP depends on actual scripts, styles, frames, images, fonts, and third-party assets.
What is in the verification pack?
The pack includes .env.example placeholders, csp-assertions.json, and a starter verify-csp-header.mjs script. It copies directive requirements and risk checks, not raw pasted origins or report endpoints.
Should I start with report-only mode?
For existing sites, yes. Ship Content-Security-Policy-Report-Only first, review violation reports, then enforce once legitimate resources are covered.
Does this upload my policy?
No. Analysis, snippets, and verification pack generation run entirely in your browser.
Related tools
All 112 free tools
JSON Formatter & ValidatorPretty-print & validate JSON
Image Resize CalculatorCalculate new dimensions while preserving aspect ratio
Password Strength CheckerAnalyze password entropy and weaknesses
YAML ↔ JSON ConverterConvert between YAML and JSON
JSON to YAMLConvert JSON to YAML format
JSON Schema GeneratorInfer and validate API contracts
Made something with AI? Share it as a private link.
Drop in the HTML from Claude, ChatGPT or any editor and get a link your client can open anywhere — with a password, view tracking, comments and approval.