# Security header builder & SRI — no upload

> Build recommended security headers (CSP, HSTS, and more) and Subresource Integrity hashes in your browser. Nothing is uploaded.

Build recommended HTTP security headers — Content-Security-Policy, HSTS, X-Frame-Options, and more — and generate Subresource Integrity (SRI) hashes. Everything is generated in the browser, with nothing uploaded.

A handful of security headers meaningfully harden a site — CSP against XSS, HSTS to enforce HTTPS, frame options against clickjacking. Building them correctly is fiddly, and this tool composes valid values plus SRI hashes for CDN assets.

See the HTTP header reference for the full header landscape and the robots.txt generator for crawler control.

## How to

1. **Choose headers.** Pick the security headers you want to configure.
2. **Set values.** Tune directives like CSP sources and HSTS max-age.
3. **Copy.** Add the headers (and any SRI hash) to your server or tags.

## FAQ

### What is Content-Security-Policy?

A header that restricts which sources scripts, styles, and other resources can load from, mitigating XSS. The builder helps you compose a policy without syntax mistakes.

### What is Subresource Integrity?

An integrity hash on a <script> or <link> so the browser refuses a file that's been tampered with — important when loading assets from a CDN. The tool generates the hash locally.

### Is anything uploaded?

No. Header text and SRI hashes are generated in the browser, so nothing leaves the tab.


## Related tools

- [HTTP headers](https://www.safepaper.app/dev/http-headers)
- [robots.txt](https://www.safepaper.app/dev/robots-txt)
- [HTTP status codes](https://www.safepaper.app/dev/http-status-codes)
- [Hash & checksum](https://www.safepaper.app/security/hash-verify)

---

Canonical HTML: https://www.safepaper.app/dev/security-headers
Markdown: https://www.safepaper.app/dev/security-headers.md

There is no upload endpoint — your files are processed in this browser tab. Open your network tab and check.
