Security Headers Generator
Generate CSP, HSTS and other security headers for Nginx, Apache, Vercel, Netlify or Cloudflare Pages.
HeadersTurn on what you need; each line says what it does
Allow these services
Fallback for the types below that are left empty
JavaScript
Stylesheets
Images
Web fonts
fetch, XHR and analytics beacons
Embedded iframes
Audio and video
Plugins; keep 'none'
The <base> tag
Where forms may post
Who may show your pages in a frame
Start short if you are unsure: browsers keep forcing HTTPS for the whole period.
Turn off
Leave Payment Request allowed if you take payments with Razorpay, UPI or Google Pay.
Configuration
add_header Content-Security-Policy-Report-Only "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self'; connect-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'" always; add_header Strict-Transport-Security "max-age=31536000" always; add_header X-Content-Type-Options "nosniff" always; add_header X-Frame-Options "SAMEORIGIN" always; add_header Referrer-Policy "strict-origin-when-cross-origin" always; add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always; add_header Cross-Origin-Opener-Policy "same-origin-allow-popups" always;
Paste inside the server { } block. A location block with its own add_header drops all of these, so repeat them there.
After deploying, check the response headers in your browser's DevTools (Network tab) and test the pages that use payments, maps, videos or logins.
Security Headers Generator FAQ
How do I add security headers to my website?
Choose the headers, pick your server or host above the code, and copy the snippet. Paste it into the server block (Nginx), .htaccess (Apache), vercel.json (Vercel) or a _headers file (Netlify, Cloudflare Pages), then redeploy.
What is Content-Security-Policy-Report-Only?
It is the same policy in test mode: browsers report what would be blocked in the console but block nothing. Use it until no important violations appear, then switch to the enforced header.
Will a CSP break Google Analytics or Razorpay?
It can, if their domains are missing. Tick Google Analytics 4 / Tag Manager or Razorpay Checkout to add the sources they document. The GA4 snippet is inline, so it also needs Allow inline scripts or a nonce or hash.
What is the difference between X-Frame-Options and frame-ancestors?
Both stop other sites framing your pages. frame-ancestors in the CSP is the modern version; X-Frame-Options is kept for older browsers. The tool sets them to match.
Should I turn on HSTS preload?
Only when every subdomain works over HTTPS and you plan to keep it that way. Preload needs includeSubDomains and a max-age of at least one year, and getting removed takes months.
Is my configuration sent anywhere?
No. The headers are generated in your browser and nothing is uploaded.