Paste a Content-Security-Policy string to flag unsafe-inline/eval, missing default-src, and reporting gaps.
- Free
- No signup
- Fast
- Privacy-friendly
What next?
Keep going with CSP Policy Evaluator
Finish this check in the browser, then pick the path that matches how you work — another related tool, REST for apps, or MCP for agents.
- 1. Related check
After this result, run Security headers analyzer for the next signal.
Security headers analyzer - 2. Automate with API
Same job from your server with
Create free accountX-Api-Key. Free tier includes 500 credits/month. - 3. Hand off to an agent
Connect Cursor or Claude to ToolYour MCP — plan → run → verify.
MCP setup
What is CSP Policy Evaluator?
Author or review a CSP before deploying. ToolYour CSP Policy Evaluator parses directives and scores unsafe tokens, missing default-src, and report-to/report-uri. Pair with <a href="/security-tools/security-headers-analyzer">Security Headers Analyzer</a> on a live URL and <a href="/digital-tools/mixed-content-checker">Mixed Content Checker</a> for http:// assets. REST/MCP: /api/v1/security-apis/csp-policy-evaluator.
What are common questions about CSP Policy Evaluator?
What does CSP Policy Evaluator do?
Paste a Content-Security-Policy string to flag unsafe-inline/eval, missing default-src, and reporting gaps.
Is this available via API and MCP?
Yes. Same route under /api/v1/security-apis/{slug} with one ToolYour API key.
What are the key features of CSP Policy Evaluator?
Free browser access
Cross-device support
Privacy-focused
How do you use CSP Policy Evaluator?
Open the tool
Provide input
Copy or download
Related hardening tools
Use CSP Policy Evaluator three ways
The free CSP Policy Evaluator on this page works in your browser. The same workflow is available via REST API for apps and via the remote MCP server for Cursor, Claude, and other agents — one API key, one plan, one quota. This tool is part of the security-apis module under Security Tools.
- 1Create a free accountGet an API key for REST and MCP — 500 credits/month on the free tier.
- 2Connect or callPaste the MCP URL into Cursor/Claude, or call REST with
X-Api-Key. - 3Same key & creditsBrowser smoke-checks stay free; API-backed runs share one monthly credit quota.
- Free in browserUse CSP Policy Evaluator here — no account required.
- REST APICall from your server with
X-Api-Key. - Remote MCP serverSame job from Cursor or Claude via the ToolYour remote MCP server — one API key with REST.
Which web-hardening tools sit in this cluster?
- Security headers analyzer
Live CSP, HSTS, XFO, and related headers.
- Cookie security analyzer
Secure, HttpOnly, and SameSite flags.
- CORS policy checker
ACAO wildcards and Origin reflection.
- Subresource integrity checker
Missing integrity= on third-party assets.
- security.txt checker
RFC 9116 disclosure file presence.
Where does this job fit on ToolYour?
Which SEO or privacy tools pair with this security check?
Where do you browse more security tools tools?
- Security Tools tools
Browse the full Security Tools category on ToolYour.
- Developer Tools tools
Format JSON, encode Base64/URL, mint UUIDs, convert timestamps, and test regex in the browser. REST and MCP sh
- Marketing Tools tools
Build UTM links, check ads copy limits, QA email subjects, and calculate ROAS/CPC/CTR — free in the browser; R
Which toolkits include CSP Policy Evaluator?
- Security Toolkit
HTTP security headers, TLS, cookies, CORS, redirects, DNS, secrets, JWT, passwords, hashes, HMAC, bcrypt, security.txt, SRI, and email auth — plus agent playbooks for full audits and ship gates.
- Developer Toolkit
JSON/XML/SQL formatters, encoders, UUID/timestamp/regex, JSON codegen, JWT minting, HTTP headers, request builders, cron, minifiers, and color conversion — plus security and text peers.
