Policy Studio
Security headers, made editable
Local draft
Content Security Policy
Manage your allowed sources
Import an existing policy, then refine each directive and the origins it can trust.
Import current policy
Paste a policy, or paste the header output from the command below.
Get headers from a live URL
This app never fetches URLs itself. Run the command below in your own terminal, then paste the output into the box above — it works for internal hosts and anything needing your VPN, cookies, or client certificates.
3 directives
Fallback policy for all resource types
'self'
Controls JavaScript sources
'self' https://cdn.example.com
Controls image sources
'self' data: https://images.example.com