Generate CSP, HSTS, cookie and CORS headers to defend against XSS and clickjacking — free, no code.
Generate strong HTTP security headers for nginx, Apache, Netlify or as raw headers.
Build a Content-Security-Policy header or meta tag from directives and allowed hosts.
HSTS Generator — runs 100% in your browser. No data is uploaded; nothing leaves your device.
Build a hardened Set-Cookie header with Secure, HttpOnly and SameSite — runs 100% in your browser. No data is uploaded; nothing leaves your device.
Referrer Policy Generator — runs 100% in your browser. No data is uploaded; nothing leaves your device.
Permissions Policy Generator — runs 100% in your browser. No data is uploaded; nothing leaves your device.
CORS Config Generator — runs 100% in your browser. No data is uploaded; nothing leaves your device.
Generate Cross-Origin Opener/Embedder Policy headers for isolation — runs 100% in your browser. No data is uploaded; nothing leaves your device.
Every tool on ToolJolt is free, runs in your browser and needs no sign-up.