Security Header Generator

Designed for devops engineers and webmasters who need to rapidly assemble secure HTTP headers without memorizing RFC syntax, minimizing deployment errors caused by malformed directives.

This tool helps you construct a Content-Security-Policy (CSP) header and generate Subresource Integrity (SRI) hashes. Specifically, the SRI integrity hashes use `sha384` as per the W3C Subresource Integrity specification, providing a robust security measure.

CSP & SRI Header Builder

Content-Security-Policy (CSP) Builder

Toggle directives and enter sources to build your CSP header.

Subresource Integrity (SRI) Hash Generator

Paste the full text of your JavaScript or CSS file below. SRI integrity hashes use sha384 per the W3C Subresource Integrity spec.

Generated CSP Header:

Content-Security-Policy: default-src 'self';

Generated SRI Attribute:

integrity="sha384-..."

How to Use This Tool

  1. Toggle on the specific directives required for your application.
  2. Enter allowed domains or keywords into the source fields next to each directive.
  3. Watch the generated header preview update instantly.
  4. Paste the full text of your JS or CSS file into the SRI input box below.
  5. Click the Copy buttons to capture the final headers for your server config.

FAQ

Q: What does default-src 'self' mean in a CSP?
A: It establishes a fallback policy requiring all resources to load strictly from the same origin where the site is served, blocking any external scripts, styles, or images unless explicitly overridden by child directives.
Q: Why does this tool default to sha384 for SRI?
A: According to the W3C Subresource Integrity spec, sha384 offers the best balance of cryptographic strength and output length, ensuring broad browser compatibility while keeping the HTML attribute size manageable.
Q: Can I combine multiple sources in one CSP directive?
A: Yes, you can add multiple space-separated values to the source field, such as combining 'self' with a trusted CDN URL like https://cdn.example.com to allow scripts from both locations.
Q: Does adding a CSP header block malicious sites immediately?
A: While the header instructs the browser to enforce strict loading rules, attackers can still exploit vulnerabilities in third-party services; CSP acts as a mitigation layer rather than a complete prevention shield against all attacks.