Content-Security-Policy · CSP3

CSP analyzer

Paste a Content-Security-Policy header and see what it actually says: every directive and source expression explained, values that browsers silently ignore, allowlist entries known to defeat the whole policy — and a URL tester that answers "would this load?", naming the directive and source expression that decide it. The matching logic is tested against real Chromium, not just the spec. Nothing you paste leaves your browser.

How CSP decides a load

For each load the browser picks one governing directive: the most specific one present, walking a fallback chain (a script tries script-src-elem, then script-src, then default-src). Only that directive's source list is consulted — lists never merge. If no directive in the chain exists, the load is allowed: CSP is allow-by-default. form-action, base-uri and frame-ancestors have no fallback, so default-src 'none' alone does not restrict form posts or framing. Within a list, a URL matches host sources by scheme, host (with a leading *. wildcard), port, and path prefix — an http: source also matches its https: counterpart on port 443. Nonces and hashes never match a URL by themselves: they admit specific elements, and with 'strict-dynamic' the host allowlist is ignored for scripts entirely.

When several policies are active at once, a load must pass every enforced policy — extra policies can only tighten, never loosen. Report-only policies never block anything.