← All headersResponse header

What is a Content-Security-Policy header?

Declares which sources of scripts, styles, images, and other content the browser is allowed to load, mitigating XSS.

Content-Security-Policy is one of the most powerful security headers a website can deploy - by explicitly whitelisting where scripts, styles, and other resources are allowed to load from, it can shut down entire categories of cross-site scripting attack even if a vulnerability slips into the code elsewhere. It's also one of the easiest headers to misconfigure, since an overly strict policy can silently break legitimate functionality (a third-party widget, an inline script) in a way that looks like a completely unrelated bug, which is why testing it thoroughly rather than just deploying and hoping matters.

Common use case

A site restricts script-src to its own domain and a specific trusted analytics provider, so even if an attacker manages to inject a malicious inline script through a vulnerability, the browser refuses to execute it.

Example

Content-Security-Policy: default-src 'self'; script-src 'self' https://analytics.example.com

History

Developed at Mozilla starting around 2004, first standardised as a W3C Candidate Recommendation (CSP Level 1) in 2012, with CSP Level 2 and 3 adding significant capability since.

Did you know?

It supports a report-only mode and a report-uri/report-to destination, letting a site monitor what a strict policy would have blocked in production before actually enforcing it - a safe way to roll out a major policy change.