PasteZap
🌐 English
Free · No account

FREE · NETWORK & IT INFRASTRUCTURE

HTTP Security Headers Generator.

Build Content-Security-Policy, HSTS, Referrer-Policy, Permissions-Policy and cross-origin headers for Nginx, Apache, Caddy, IIS, _headers and Express.

Limits & supported formats

CSP sources are validated for syntax, not reachability. Test the site after deploying; a strict policy can block resources you rely on. Everything is calculated in your browser; nothing is sent or probed on the network.

CALCULATED IN YOUR BROWSER · NOTHING IS UPLOADED

Strict-Transport-Security (HSTS)

Content-Security-Policy

Other headers

Headers7

Configuration

# Inside the server { } block. A location that has its own add_header does not inherit these.
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
add_header Content-Security-Policy-Report-Only "default-src 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; font-src 'self'; connect-src 'self'; frame-src 'none'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header Permissions-Policy "camera=(), microphone=(), geolocation=(), payment=(), usb=()" always;
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header X-Frame-Options "DENY" always;
server_tokens off;

Headers sent

HeaderValue
Strict-Transport-Securitymax-age=31536000; includeSubDomains
Content-Security-Policy-Report-Onlydefault-src 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; font-src 'self'; connect-src 'self'; frame-src 'none'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests
X-Content-Type-Optionsnosniff
Referrer-Policystrict-origin-when-cross-origin
Permissions-Policycamera=(), microphone=(), geolocation=(), payment=(), usb=()
Cross-Origin-Opener-Policysame-origin
X-Frame-OptionsDENY
  • Test the site after deploying: a strict CSP can block scripts, fonts or embeds you rely on. The browser console names each blocked resource.
  • Only send HSTS on HTTPS responses; browsers ignore it over plain HTTP.

How to use HTTP Security Headers Generator

Choose the server, switch headers on, list extra CSP sources (CDNs, fonts, analytics), start in report-only mode, then copy the configuration.

How it works

Selected options are assembled into header values, CSP keywords are quoted automatically, and the list is written in each server’s syntax with the escaping it needs.

Example

HSTS for one year, a report-only CSP, nosniff, strict-origin-when-cross-origin and disabled camera/microphone produce seven headers ready for Nginx.

Questions about HTTP Security Headers Generator

Is HTTP Security Headers Generator free, and do I need an account?

Yes. This tool is free to use in your browser without an account. Processing takes place on your device.

What are the limits and what should I check?

CSP sources are validated for syntax, not reachability. Test the site after deploying; a strict policy can block resources you rely on. Everything is calculated in your browser; nothing is sent or probed on the network. Review the result before using it in your work.

Is my input sent to a server?

Your input is processed in your browser and is not uploaded by this tool. Files and pasted text are cleared when the page is refreshed. Normal website requests are still required to load the page and its libraries. Read the privacy explanation.