Security Headers Generator

Runs in your browserSEO & Web#Security#DevOps

Generate CSP, HSTS and other security headers for Nginx, Apache, Vercel, Netlify or Cloudflare Pages.

HeadersTurn on what you need; each line says what it does

Allow these services

Start short if you are unsure: browsers keep forcing HTTPS for the whole period.

Turn off

Leave Payment Request allowed if you take payments with Razorpay, UPI or Google Pay.

Configuration

add_header Content-Security-Policy-Report-Only "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self'; connect-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'" always;
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always;
add_header Cross-Origin-Opener-Policy "same-origin-allow-popups" always;

Paste inside the server { } block. A location block with its own add_header drops all of these, so repeat them there.

After deploying, check the response headers in your browser's DevTools (Network tab) and test the pages that use payments, maps, videos or logins.

How to use, limits & privacy

About Security Headers Generator

Generate HTTP security headers for Nginx, Apache, Vercel, Netlify or Cloudflare Pages: Content-Security-Policy, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy and the cross-origin policies. The CSP builder adds the sources that Google Analytics 4, Google Fonts, YouTube embeds and Razorpay need, and starts in Report-Only mode so nothing breaks while you test. It runs in your browser.

How to Use

1

Choose the headers

Switch each header on or off; every one has a line saying what it does. Under Content-Security-Policy, tick the services your site uses, such as Google Analytics 4 or Razorpay Checkout.

2

Pick safe settings

Leave Report-Only mode on at first. For HSTS, choose how long browsers should remember HTTPS, and turn on Include subdomains or Preload only if every subdomain works over HTTPS.

3

Copy for your server

Choose Nginx, Apache, Vercel, Netlify or Cloudflare Pages above the code, then click Copy or Download and follow the note under it.

4

Test, then enforce

Deploy, open your site with the browser's DevTools console open and fix any reported violations. Then turn off Report-Only mode and deploy again.

Privacy & Processing

  • Mode: local
  • Files Leave Browser: Local tool processing; review details below
  • Max Input Size: Device memory limits
  • Account Required: No
  • Data Stored Locally: Nothing is saved; reloading the page restores the default settings.
  • Network Processing: Assets or models may require an initial download

Headers are generated in your browser. Nothing is uploaded.

Rules & Limitations

  • The CSP is a starting point. Sites with inline scripts, other CDNs or chat widgets need those sources added under Edit sources.
  • HSTS preload is hard to undo: removal from browser lists takes months. Never preload while any subdomain still needs plain HTTP.
  • Nginx: an add_header inside a location block replaces all server-level add_header lines for that location. Apache needs mod_headers.
  • For Vercel, merge the headers block into your existing vercel.json. For sites proxied by Cloudflare (not Pages), use a Response Header Transform Rule.

Top Suggestions

  • Fixing missing-header warnings from securityheaders.com or Mozilla Observatory
  • Adding a Content-Security-Policy to a site that uses GA4 and Razorpay
  • Setting up HSTS before submitting a domain to the preload list
  • Hardening a static site on Netlify, Vercel or Cloudflare Pages

Security Headers Generator FAQ

How do I add security headers to my website?

Choose the headers, pick your server or host above the code, and copy the snippet. Paste it into the server block (Nginx), .htaccess (Apache), vercel.json (Vercel) or a _headers file (Netlify, Cloudflare Pages), then redeploy.

What is Content-Security-Policy-Report-Only?

It is the same policy in test mode: browsers report what would be blocked in the console but block nothing. Use it until no important violations appear, then switch to the enforced header.

Will a CSP break Google Analytics or Razorpay?

It can, if their domains are missing. Tick Google Analytics 4 / Tag Manager or Razorpay Checkout to add the sources they document. The GA4 snippet is inline, so it also needs Allow inline scripts or a nonce or hash.

What is the difference between X-Frame-Options and frame-ancestors?

Both stop other sites framing your pages. frame-ancestors in the CSP is the modern version; X-Frame-Options is kept for older browsers. The tool sets them to match.

Should I turn on HSTS preload?

Only when every subdomain works over HTTPS and you plan to keep it that way. Preload needs includeSubDomains and a max-age of at least one year, and getting removed takes months.

Is my configuration sent anywhere?

No. The headers are generated in your browser and nothing is uploaded.