CSP Resource Evaluator
Paste a Content-Security-Policy header value and test whether a specific resource URL or block of inline script/style would be allowed or blocked, with the matching source expression and a weaknesses report.
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Body
CSP header value
Page origin (optional)
What do you want to test?
url, inline-script, inline-style Resource type
script, style, image, font, connect, frame, media, object, worker, manifest, formAction, baseUri, frameAncestors Resource URL
Inline content
Response
Tool output
The tool's slug, echoing the {slug} in the request path.
Output-contract version for this tool.
Credits this call consumed, after any settlement refund. 0 when metering is disabled.
Credits left in the current monthly allowance, or null when metering is disabled.
Correlation id, also sent as x-request-id.