Skip to content
We use cookies to improve the site and measure traffic. See our Cookie Policy. You can accept or reject non-essential cookies.
  • Free
  • No signup
  • Fast
  • Privacy-friendly

Back to Category

CSP Policy Evaluator

Paste a Content-Security-Policy string to flag unsafe-inline/eval, missing default-src, and reporting gaps.

Waiting for bot check… this usually takes a second.

What next?

Keep going with CSP Policy Evaluator

Finish this check in the browser, then pick the path that matches how you work — another related tool, REST for apps, or MCP for agents.

  1. 1. Related check

    After this result, run Security headers analyzer for the next signal.

    Security headers analyzer
  2. 2. Automate with API

    Same job from your server with X-Api-Key. Free tier includes 500 credits/month.

    Create free account
  3. 3. Hand off to an agent

    Connect Cursor or Claude to ToolYour MCP — plan → run → verify.

    MCP setup

What is CSP Policy Evaluator?

Author or review a CSP before deploying. ToolYour CSP Policy Evaluator parses directives and scores unsafe tokens, missing default-src, and report-to/report-uri. Pair with <a href="/security-tools/security-headers-analyzer">Security Headers Analyzer</a> on a live URL and <a href="/digital-tools/mixed-content-checker">Mixed Content Checker</a> for http:// assets. REST/MCP: /api/v1/security-apis/csp-policy-evaluator.

What are common questions about CSP Policy Evaluator?

What does CSP Policy Evaluator do?

Paste a Content-Security-Policy string to flag unsafe-inline/eval, missing default-src, and reporting gaps.

Is this available via API and MCP?

Yes. Same route under /api/v1/security-apis/{slug} with one ToolYour API key.

What are the key features of CSP Policy Evaluator?

Free browser access

Use CSP Policy Evaluator without subscription or registration.

Cross-device support

Runs on desktop, tablet, and mobile browsers.

Privacy-focused

Inputs are processed to produce output and not kept longer than needed.

How do you use CSP Policy Evaluator?

Open the tool

CSP Policy Evaluator loads instantly — no signup required.

Provide input

Paste, type, or upload the input the tool expects.

Copy or download

Use the result in your workflow — outputs are yours to keep.

Related hardening tools

After you fix CSP text, re-check live headers, Subresource Integrity, Cookie Security, and CORS Policy.
Free · API · MCPToolYour platform

Use CSP Policy Evaluator three ways

The free CSP Policy Evaluator on this page works in your browser. The same workflow is available via REST API for apps and via the remote MCP server for Cursor, Claude, and other agents — one API key, one plan, one quota. This tool is part of the security-apis module under Security Tools.

  1. 1Create a free accountGet an API key for REST and MCP — 500 credits/month on the free tier.
  2. 2Connect or callPaste the MCP URL into Cursor/Claude, or call REST with X-Api-Key.
  3. 3Same key & creditsBrowser smoke-checks stay free; API-backed runs share one monthly credit quota.

Which web-hardening tools sit in this cluster?

Where does this job fit on ToolYour?

Which SEO or privacy tools pair with this security check?

Where do you browse more security tools tools?

Which toolkits include CSP Policy Evaluator?