Illustration of directive rows assembling into a single Content-Security-Policy header string

CSP Builder

Fill in source lists per directive to build a Content-Security-Policy header value — or paste an existing policy below to load it into the fields. Runs entirely in your browser.

Load an existing policy

💻 Show API usage examples (cURL)
curl -sS -X POST https://devops.majbase.com/csp-builder/api -H "Content-Type: application/json" -d '{"action":"build","directives":{"default-src":"'"'"'self'"'"'","script-src":"'"'"'self'"'"' https://cdn.example.com"}}'
curl -sS -X POST https://devops.majbase.com/csp-builder/api -H "Content-Type: application/json" -d '{"action":"parse","policy":"default-src '"'"'self'"'"'; script-src '"'"'self'"'"' https://cdn.example.com"}'

Build returns {"result": "..."}. Parse returns {"directives": {...}}. directives values can be a space-separated string or an array.

🤖 Use this API as a Claude Skill

Want an AI agent (Claude Code, claude.ai, or anything else that supports the Agent Skills format) to use this tool for you on request? Download the skill below and add it:

⬇️ Download SKILL.md · View raw