Paste a Content-Security-Policy string to flag unsafe-inline/eval, missing default-src, and reporting gaps.
- Free
- No signup
- Fast
- Privacy-friendly
Use CSP Policy Evaluator three ways
The free CSP Policy Evaluator on this page works in your browser. The same workflow is available via REST API for apps and via MCP for Cursor, Claude, and other agents — one API key, one plan, one quota. This tool is part of the security-apis module under Security Tools.
- Free in browserUse CSP Policy Evaluator here — no account required.
- REST APICall from your server with
X-Api-Key. - MCP for agentsConnect Cursor or Claude to ToolYour MCP with the same key.
- 1. Get an API keySign in and open Dashboard → API Keys (works for REST and MCP).
- 2. Call or connectUse the REST API from your server, or paste the MCP URL into your agent config.
- 3. Same qualityOutput matches the free web tool across all three surfaces.
What is CSP Policy Evaluator?
Author or review a CSP before deploying. ToolYour CSP Policy Evaluator parses directives and scores unsafe tokens, missing default-src, and report-to/report-uri. Pair with <a href="/security-tools/security-headers-analyzer">Security Headers Analyzer</a> on a live URL and <a href="/digital-tools/mixed-content-checker">Mixed Content Checker</a> for http:// assets. REST/MCP: /api/v1/security-apis/csp-policy-evaluator.
What are common questions about CSP Policy Evaluator?
What does CSP Policy Evaluator do?
Paste a Content-Security-Policy string to flag unsafe-inline/eval, missing default-src, and reporting gaps.
Is this available via API and MCP?
Yes. Same route under /api/v1/security-apis/{slug} with one ToolYour API key.
What are the key features of CSP Policy Evaluator?
Free browser access
Cross-device support
Privacy-focused
How do you use CSP Policy Evaluator?
Open the tool
Provide input
Copy or download
Related hardening tools
Which web-hardening tools sit in this cluster?
- Security headers analyzer
Live CSP, HSTS, XFO, and related headers.
- Cookie security analyzer
Secure, HttpOnly, and SameSite flags.
- CORS policy checker
ACAO wildcards and Origin reflection.
- Subresource integrity checker
Missing integrity= on third-party assets.
- security.txt checker
RFC 9116 disclosure file presence.
Which SEO or privacy tools pair with this security check?
Where do you browse more security tools tools?
- Security Tools tools
Browse the full Security Tools category on ToolYour.
- File Converter tools
Convert PDF↔Word, compress images, and change formats online. Free in browser · REST · MCP. No signup for typi
- Business Tools tools
GST/VAT calculators, EMI and margin math, invoices, resumes, and unit converters. Free in the browser; formula
Related tools
security tools
Webhook Signature Verifier
Timing-safe HMAC compare for GitHub sha256=, Stripe t=/v1=, and generic HMAC-SHA256 webhook signatures.
Freesecurity tools
JWT Signature Verifier
Verify HS*/RS*/ES* JWT signatures with a pasted secret, PEM public key, or JWK — complements decode-only JWT Decoder.
Freesecurity tools
Subresource Integrity Checker
Parse a page for script/link tags and report missing integrity attributes on third-party assets.
Freesecurity tools
Security.txt Checker
Discover and parse RFC 9116 security.txt (/.well-known/security.txt) including Contact and Expires.
Freesecurity tools
Password Hash Generator (bcrypt / Argon2)
Generate bcrypt or Argon2id password hashes for local auth testing — same URL, dual algorithms.
Freesecurity tools
HMAC Generator
Compute HMAC digests and optionally compare an expected signature (timing-safe when lengths match).
Freesecurity tools
DNS Lookup
Resolve A/AAAA/MX/TXT/NS/CNAME and report DNSSEC-related DS/DNSKEY/RRSIG presence (not full chain validation).
Freesecurity tools
HTTP Security Redirect Checker
HTTP→HTTPS upgrades, loops, long chains, and open-redirect-looking query params.
Freesecurity tools
CORS Policy Checker
Fetch a URL with a probe Origin and report Access-Control-Allow-* gaps, wildcards, and Origin reflection.
Freesecurity tools
Secret Leak Scanner
Heuristic scan of pasted env/config/log text for API keys, tokens, PEM keys, and JWTs.
Freesecurity tools
SPF / DKIM / DMARC Checker
Look up SPF, common DKIM selectors, and DMARC TXT records for a domain or URL hostname.
Freesecurity tools
Hash Generator
Compute MD5, SHA-1, SHA-256/384/512, or SHA-3 digests of text in one place — with legacy warnings for MD5/SHA-1.
Free
Popular in Security Tools
security tools
Webhook Signature Verifier
Timing-safe HMAC compare for GitHub sha256=, Stripe t=/v1=, and generic HMAC-SHA256 webhook signatures.
Freesecurity tools
JWT Signature Verifier
Verify HS*/RS*/ES* JWT signatures with a pasted secret, PEM public key, or JWK — complements decode-only JWT Decoder.
Freesecurity tools
Subresource Integrity Checker
Parse a page for script/link tags and report missing integrity attributes on third-party assets.
Freesecurity tools
Security.txt Checker
Discover and parse RFC 9116 security.txt (/.well-known/security.txt) including Contact and Expires.
Freesecurity tools
Password Hash Generator (bcrypt / Argon2)
Generate bcrypt or Argon2id password hashes for local auth testing — same URL, dual algorithms.
Freesecurity tools
HMAC Generator
Compute HMAC digests and optionally compare an expected signature (timing-safe when lengths match).
Freesecurity tools
DNS Lookup
Resolve A/AAAA/MX/TXT/NS/CNAME and report DNSSEC-related DS/DNSKEY/RRSIG presence (not full chain validation).
Free
