Security Header Generator
Designed for devops engineers and webmasters who need to rapidly assemble secure HTTP headers without memorizing RFC syntax, minimizing deployment errors caused by malformed directives.
This tool helps you construct a Content-Security-Policy (CSP) header and generate Subresource Integrity (SRI) hashes. Specifically, the SRI integrity hashes use `sha384` as per the W3C Subresource Integrity specification, providing a robust security measure.
CSP & SRI Header Builder
Content-Security-Policy (CSP) Builder
Toggle directives and enter sources to build your CSP header.
Subresource Integrity (SRI) Hash Generator
Paste the full text of your JavaScript or CSS file below. SRI integrity hashes use sha384 per the W3C Subresource Integrity spec.
Generated CSP Header:
Content-Security-Policy: default-src 'self';
Generated SRI Attribute:
integrity="sha384-..."
How to Use This Tool
- Toggle on the specific directives required for your application.
- Enter allowed domains or keywords into the source fields next to each directive.
- Watch the generated header preview update instantly.
- Paste the full text of your JS or CSS file into the SRI input box below.
- Click the Copy buttons to capture the final headers for your server config.
FAQ
- Q: What does
default-src 'self'mean in a CSP? - A: It establishes a fallback policy requiring all resources to load strictly from the same origin where the site is served, blocking any external scripts, styles, or images unless explicitly overridden by child directives.
- Q: Why does this tool default to
sha384for SRI? - A: According to the W3C Subresource Integrity spec,
sha384offers the best balance of cryptographic strength and output length, ensuring broad browser compatibility while keeping the HTML attribute size manageable. - Q: Can I combine multiple sources in one CSP directive?
- A: Yes, you can add multiple space-separated values to the source field, such as combining
'self'with a trusted CDN URL likehttps://cdn.example.comto allow scripts from both locations. - Q: Does adding a CSP header block malicious sites immediately?
- A: While the header instructs the browser to enforce strict loading rules, attackers can still exploit vulnerabilities in third-party services; CSP acts as a mitigation layer rather than a complete prevention shield against all attacks.