How to use this developer tool
- Paste or upload the expected source text.
- Review any options shown below the input.
- Select Parse CSP or press Ctrl/Cmd + Enter.
- Check the notes, then copy or download the output.
Parse a Content-Security-Policy header into directives and source tokens. The output distinguishes flag-style directives from directives with values, flags duplicates, and highlights several common policy concerns such as missing default-src or permissive script sources. It performs a static text review only; it does not prove that a policy is safe for a particular application or account for headers delivered on other responses.
Content Security Policy Parser turns the entered source into a structured or generated result that can be inspected before use.
Input stays in this browser tab. Always remove live secrets before sharing screenshots or downloaded results.
default-src 'self'; script-src 'self' https://cdn.example.com 'nonce-abc123'; img-src 'self' data:; object-src 'none'; upgrade-insecure-requests
Running the sample produces output that reflects the parsed fields and reports any unsupported or security-sensitive detail.
Splits semicolon-delimited directives, normalizes directive names, preserves source token order, and runs conservative lint checks. Processing is deterministic except where cryptographic random values are intentionally generated.
This browser tool does not execute remote requests, expand shell variables, inspect server behavior, or replace application-specific security review.
No. Processing runs in the browser and the page does not transmit the entered text.
Paste a CSP header value using the syntax shown in the sample.
Use it as a reviewed starting point. Environment-specific security, authentication, and error handling still need verification.
The parser handles documented common syntax and reports constructs that would require shell, browser, or server context.
Compare the parsed URL, headers, body, directives, or origins with the source and test the final configuration in a non-production environment.
| Field | Meaning |
|---|---|
| Output | Generated or parsed text |
| Summary | Counts and completion state |
| Notes | Warnings and review guidance |
Browse more tools in this developer category.
Open category hub