Policy Studio

Security headers, made editable

Content Security Policy

Manage your allowed sources

Import an existing policy, then refine each directive and the origins it can trust.

Import current policy

Paste a policy, or paste the header output from the command below.

Get headers from a live URL

This app never fetches URLs itself. Run the command below in your own terminal, then paste the output into the box above — it works for internal hosts and anything needing your VPN, cookies, or client certificates.

3 directives

Fallback policy for all resource types

'self'

Controls JavaScript sources

'self' https://cdn.example.com

Controls image sources

'self' data: https://images.example.com