Content Security Policy generator

Pick the third-party services your site loads and get an Apache or nginx config back. The policy is built with the same package we use on our own Laravel projects, so a hand-configured server ends up sending exactly what a Laravel app would.

Services
ActiveCampaign
Adobe Fonts
Alchemer
Algolia
Basic
Bootstrap
Bunny Fonts
Chargebee
Clarity
Cloudflare Cdn
Cloudflare Turnstile
Cloudflare Web Analytics
Cookiebot
Fathom
Firebase
Google Analytics
Google Fonts
Google Looker Studio
Google Maps
Google Recaptcha
Google Tag Manager
Google TLDs
hCaptcha
Heap Analytics
Hireroad
Hotjar
Hub Spot
Intercom
jQuery
jsDelivr
Maze
Meta Pixel
New Relic
Plain
Plausible Analytics
PostHog
Rollbar
Sentry
Stripe
Survey Monkey
There There
Ticket Tailor
Tolt
TrackJS
Vimeo
Visual Website Optimizer
Whereby
YouTube
4 of 48 selected
Your domain Optional. Added to default-src alongside 'self'.
Other hosts One per line. Anything that is not a host is ignored.
Allow inline scripts and styles Most sites still need this. Without it, inline script and style tags stop working.
Allow data: images and fonts Needed for inlined SVGs and icon fonts.
for.duty project token Optional. Adds the reporting header so violations arrive in for.duty instead of only the browser console.
Report only An enforcing policy blocks whatever it does not list, which can break a live site. Report-only shows you what would break without blocking anything.

nginx

add_header Content-Security-Policy "base-uri 'self';connect-src 'self' *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net *.google.com pagead2.googlesyndication.com;default-src 'self';font-src 'self' fonts.gstatic.com data:;form-action 'self';frame-src 'self' *.googletagmanager.com *.googleadservices.com td.doubleclick.net;img-src 'self' *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net *.google.com pagead2.googlesyndication.com data:;media-src 'self';object-src 'none';script-src 'self' *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net *.google.com pagead2.googlesyndication.com 'unsafe-inline' 'unsafe-eval';style-src 'self' fonts.googleapis.com 'unsafe-inline'" always;

Apache

Header always set Content-Security-Policy "base-uri 'self';connect-src 'self' *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net *.google.com pagead2.googlesyndication.com;default-src 'self';font-src 'self' fonts.gstatic.com data:;form-action 'self';frame-src 'self' *.googletagmanager.com *.googleadservices.com td.doubleclick.net;img-src 'self' *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net *.google.com pagead2.googlesyndication.com data:;media-src 'self';object-src 'none';script-src 'self' *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net *.google.com pagead2.googlesyndication.com 'unsafe-inline' 'unsafe-eval';style-src 'self' fonts.googleapis.com 'unsafe-inline'"
Using Laravel or Statamic?
Install spatie/laravel-csp instead and list the same services as presets in config/csp.php. You get the identical policy, plus nonces and per-environment overrides.