Security & Web Utilities Developer Tools

Analyze HTTP security headers, generate Content Security Policy (CSP), compute SRI subresource hashes, inspect CORS, and build Basic Auth credentials.

Security & Web Utilities

HTTP Header Analyzer

Inspect and evaluate HTTP response headers for security flaws, missing CORS policies, and caching headers.

Security & Web Utilities

CSP Header Generator

Generate Content-Security-Policy (CSP) headers with custom script, style, image, and font directives.

Security & Web Utilities

SRI Hash Generator

Generate Subresource Integrity (SRI) SHA-256, SHA-384, and SHA-512 hashes for secure CDN script and stylesheet tags.

Security & Web Utilities

Basic Auth Header Generator

Create standard Authorization: Basic headers by encoding username and password credentials to Base64.

Security & Web Utilities

Bearer Token Generator

Format Bearer Token authorization headers for JWT, OAuth 2.0, and REST API testing.

Security & Web Utilities

CORS Header Generator

Configure Cross-Origin Resource Sharing (CORS) headers for Express, Nginx, Apache, and Cloudflare.

Security & Web Utilities

Set-Cookie Header Builder

Build secure Set-Cookie headers with Secure, HttpOnly, SameSite, Max-Age, and Path flags.

Security & Web Utilities

Cache-Control Header Generator

Generate HTTP Cache-Control headers with max-age, s-maxage, immutable, no-cache, and stale-while-revalidate directives.

Security & Web Utilities

MIME Type Lookup

Search and inspect standard MIME types, file extensions, and Content-Type headers.

Security & Web Utilities

HTTP Status Code Reference

Browse, search, and understand HTTP response status codes (1xx, 2xx, 3xx, 4xx, 5xx) with RFC explanations.

Security & Web Utilities

Port Number Reference

Search common network and developer ports (HTTP, HTTPS, SSH, MySQL, PostgreSQL, Redis, MongoDB).

Web Security Headers & CSP Guide

Web security protects your users and website from common attacks. Browser security headers tell web browsers what scripts, styles, and connections are allowed to run.

1. Content Security Policy (CSP)

CSP headers control where resources can be loaded from: - `default-src 'self'`: Only allows loading assets from your own domain. - `script-src 'self' https://trusted.com`: Prevents untrusted scripts from running. - `frame-ancestors 'none'`: Protects your site from clickjacking attacks.

2. Subresource Integrity (SRI)

SRI lets browsers check that scripts loaded from CDNs have not been modified. You include a cryptographic hash in your script tag: ```html <script src="https://cdn.example.com/lib.js" integrity="sha384-..." crossorigin="anonymous"></script> ``` If the file changes, the browser will block it immediately.

3. Essential Security Headers

Key headers for every website: - **Strict-Transport-Security (HSTS):** Enforces HTTPS connections. - **X-Content-Type-Options: nosniff:** Blocks MIME-type sniffing bugs. - **Referrer-Policy:** Controls what URL details are shared with external links.

Engineering Best Practices & Guidelines

✓

Test CSP rules in Report-Only mode before enforcing them.

✓

Always generate SRI hashes for third-party CDN scripts.

✓

Check your security headers using our free HTTP Header Analyzer.

Frequently Asked Questions

Q1. What happens if an SRI hash does not match?

The browser will refuse to run the script or load the style sheet, keeping your site safe from tampered files.