How to Use This Tool
Make long security policy strings readable without claiming to prove safety. Format a pasted Content-Security-Policy header locally into one directive per line for manual security review.
The failure CSP Formatter is designed to catch
Formatting reveals duplicates and omissions, but only application-specific testing can show whether a policy is both safe and functional. The boundary is the job stated in Put Every CSP Directive on Its Own Review Line; CSP Formatter is not intended to score or transform a different workflow.
The CSP Formatter input contract
The fields used for this specific operation are Input text, Unused option. Keep the source values beside the CSP Formatter result, because replacing the original would remove the evidence needed to reproduce or reverse the operation.
- For CSP Formatter, Input text starts at
default-src 'self'; img-src 'self' data:; object-src 'none'in the worked case; replace that example with the matching source value. - For CSP Formatter, Unused option starts at
in the worked case; replace that example with the matching source value.
Worked result for CSP Formatter
The executable case called Default browser-only example expects out: default-src: 'self' img-src: 'self' data: object-src: 'none'. Verify that observation before entering real material, and then change one CSP Formatter field at a time so an unexpected direction or formatting change can be traced to a specific input.
Reading the CSP Formatter output
No. The transform runs in browser JavaScript and the page does not call a processing API. Network extensions or a compromised device remain outside this page's control. Apply that answer only when Input text, Unused option describe the same scope and format as the worked operation. If the source uses different units, quoting, nesting, timing or account rules, a plausible-looking CSP Formatter output is not sufficient validation.
Assumptions attached to CSP Formatter
- CSP Formatter assumes that the pasted input uses the syntax described by the selected standard or page guidance.
- CSP Formatter assumes that the operation is intentionally narrow and does not infer private downstream schema rules.
If one of these CSP Formatter assumptions is false, keep the result as a diagnostic rather than production or decision data, and choose an implementation that explicitly supports the missing rule.
Evidence maintained for CSP Formatter
The recorded reference is IETF RFC 9110 — HTTP Semantics. Reopen that source when the definition, format, fee or policy behind CSP Formatter changes; private configuration and downstream acceptance still have to be checked in the user's own system.
Where CSP Formatter runs
The named operation executes in browser JavaScript without an ecech calculation API. For CSP Formatter, local execution reduces transmission but does not control browser extensions, device security or the destination where the result is pasted, so sensitive inputs still require the user's normal handling rules.
Sources & assumptions
Tool Spec v2 · verified 2026-08-19. Platform rules and fees can change; the editable inputs remain authoritative for your account.
Official references
- IETF RFC 9110 — HTTP Semantics (checked 2026-08-19)
Model assumptions
- The pasted input uses the syntax described by the selected standard or page guidance.
- The operation is intentionally narrow and does not infer private downstream schema rules.
