How to use this developer tool
- Paste or upload the expected source text.
- Review any options shown below the input.
- Select Merge Policies or press Ctrl/Cmd + Enter.
- Check the notes, then copy or download the output.
Merge two CSP drafts into one normalized policy for editing and comparison. Enter the policies above and below the separator line. Directives from both sides are combined and duplicate source expressions are removed while their first-seen order is retained. The result is a union, which can be less restrictive than either original policy. Treat it as a drafting aid and review every added origin before deployment.
Content Security Policy Merger turns the entered source into a structured or generated result that can be inspected before use.
Input stays in this browser tab. Always remove live secrets before sharing screenshots or downloaded results.
default-src 'self'; script-src 'self' https://cdn.example.com --- default-src 'self'; img-src 'self' data:; script-src https://analytics.example.com
Running the sample produces output that reflects the parsed fields and reports any unsupported or security-sensitive detail.
Parses both policies by directive, unions their source lists, keeps flag directives, and serializes directives with semicolons. Processing is deterministic except where cryptographic random values are intentionally generated.
This browser tool does not execute remote requests, expand shell variables, inspect server behavior, or replace application-specific security review.
No. Processing runs in the browser and the page does not transmit the entered text.
Paste two CSP policies separated by --- using the syntax shown in the sample.
Use it as a reviewed starting point. Environment-specific security, authentication, and error handling still need verification.
The parser handles documented common syntax and reports constructs that would require shell, browser, or server context.
Compare the parsed URL, headers, body, directives, or origins with the source and test the final configuration in a non-production environment.
| Field | Meaning |
|---|---|
| Output | Generated or parsed text |
| Summary | Counts and completion state |
| Notes | Warnings and review guidance |
Browse more tools in this developer category.
Open category hub