Certificate Decoder
Decode X.509 / PEM certificates - SANs, expiry, and chain hints locally.
OpenBuild and risk-score Content-Security-Policy headers visually. - runs entirely in your browser. Free, fast and private.
Enable default-src, script-src, connect-src, and more.
Use self, none, CDN presets, or custom hosts.
unsafe-inline and wildcards raise warnings automatically.
Paste Content-Security-Policy into your server or meta tag.
A blank Content-Security-Policy is easy to paste and hard to get right. CSP Builder lets you toggle directives, apply a stricter preset, and see a risk-oriented score before you copy the header into nginx, a CDN, or meta http-equiv experiments.
Start strict, then add only the hosts your real scripts, styles, and images need. unsafe-inline and overly broad * sources are the usual score killers; prefer nonces or hashes in production apps when you can.
Pitfall: shipping a Report-Only policy you never read, or a forcing policy that breaks the admin SPA on day one. Roll out Report-Only first when the site is large.
Security Headers and CORS Generator cover adjacent response headers. Misconfig Detector can skim pasted header blocks for other common gaps.
Policy text is assembled in the UI from your checkbox and host fields. We do not crawl your site to invent a CSP from this builder.
Related: Security Headers · CORS Generator
Processes data instantly with no server round-trips.
Your data never leaves your browser. Nothing is uploaded.
Works in any modern browser. Nothing to download or install.
No limits, no sign-up, no credit card required.
Works on desktop, tablet and mobile devices.
Beautiful in both themes. Your preference is saved.
Keyboard shortcut
Build a CSP string with visible directive controls.
See which sources weaken the policy before you deploy.
Copy a starter policy into edge or origin configs.
Answers for this tool. For site-wide help, open the FAQ hub.
Generators and hashers run locally. Still, never paste production secrets into any site if your security policy forbids it.
Results live in page memory until you leave or clear. Favourites/history do not save password fields unless you explicitly store them in Vault.
When applicable, tools rely on Web Crypto or well-known libraries. Read on-page notes for exact algorithms (SHA-256, bcrypt-style notes, etc.).
After load, crypto helpers typically work offline. Confirm network independence for your threat model.
Browser CSPRNG (crypto.getRandomValues) powers secure generators when the tool states so.
Treat generated secrets like passwords - share only through approved password managers, never chat apps.
OneDevToolkit aids technical workflows; it is not a certification product. See Compliance for processing model language.
Always check you are on your real OneDevToolkit domain before entering sensitive material.
Contact us via Contact with responsible-disclosure details - do not include live production secrets.