CSP Policy Workbench
Compare one supplied CSP header value and request samples locally. See which directive applies and how nonce and strict-dynamic can change the outcome.
Key features
- Show the effective directive and fallback for each resource kind
- Keep the first duplicate directive and warn about later copies
- Evaluate a bounded set of nonce, strict-dynamic, self, host and scheme cases
- Mark unsupported sources for review instead of asserting a false block
- Export JSON/CSV results and a sample-based policy draft
How to use
- Paste the document URL and a single enforcing CSP policy.
- Add script, image and other request URLs, with optional nonce and script insertion type.
- Run the comparison and inspect each allow, block or review explanation.
- Review risk signals and test the draft separately on your real site.
Use cases
- Review a CDN change before a release
- Inspect nonce and strict-dynamic interactions
- Find duplicate directives and unsafe-eval exposure
- Compare reported blocked URLs against a policy draft
Frequently asked questions
Does this inspect a live site or apply CSP?
No. It calculates from the supplied policy and samples in your browser. It neither fetches input URLs nor changes headers.
Does “allow” guarantee execution in the browser?
No. This is a bounded model of one enforcing policy. Other CSP headers, redirects, SRI, browser behavior and the actual response need separate checks.
What does “review” mean?
An unsupported source expression, hash requiring content or opaque URL prevents a firm allow/block conclusion from this input.
Can I deploy the draft as-is?
No. It only sketches origins seen in the supplied samples. It does not cover every page, request or nonce lifecycle.
Are nonce values or URL queries exported?
The report omits the original policy and nonce values and strips URL query and fragment. Paths and directive names may still be sensitive, so inspect before sharing.
Privacy
Policy and request inputs remain in this browser tab. No request is sent to an input URL or stored. Inspect URL paths and directive names before sharing exports.
Comments & questions