CentralCSP
APIPolicy Builder

Build a recommended CSP

Builds a Content-Security-Policy for the website from the CSP violation reports browsers sent over the period, and returns the header value in policy.

Without a policy, it starts from the CentralCSP baseline. With one, it keeps that policy and adds the baseline directives and keywords it is missing. It then adds every source browsers reported that the policy does not allow yet, leaving out noise such as browser extensions and injected scripts. A nonce in your policy comes back as the placeholder 'nonce-{RANDOM}', to replace with a fresh nonce on every response, and a reported 'unsafe-inline' is left out where the policy uses a nonce.

The policy ends with report-uri <endpoint> and report-to centralcsp, where the endpoint is the website's endpointUrl. Send reportingEndpoints as the Reporting-Endpoints header alongside it: Chromium ignores report-uri when report-to is present, so without that header Chrome and Edge send no reports.

The period defaults to the last 7 days and covers up to 30. On very large websites it is held to the most recent 7 days. The policy is not graded here: pass it to the CSP evaluator (Analyze a policy value) for that.

Anyone who knows the reporting endpoint can send reports to it, so a source in the result is not proof that your pages load it. Review the added sources before deploying, especially new script origins, 'unsafe-inline' and 'unsafe-eval'.

Limited to 10 requests a minute for each person, after which it answers 429 with a Retry-After header.

Requires the viewer role on the website and the report:csp-violation plan feature.

POST
/v1/workspaces/{workspaceId}/websites/{websiteId}/csp/recommended-policy

Authorization

AuthorizationBearer <token>

An OpenID Connect access token from signing in to CentralCSP, acting as the signed-in user.

In: header

Path Parameters

workspaceId*string

The workspace's id.

websiteId*string

The website's id.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

The period of reports to learn from and, optionally, the policy to start from.

range?string

How far back to read reports, counted from now. Defaults to 7d and is ignored when from and to are given.

Value in

  • "24h"
  • "7d"
  • "14d"
  • "30d"
from?string

Start of a calendar period instead of range. It must fall within the last 30 days and comes with to.

Formatdate-time
to?string

End of the calendar period, exclusive. It comes with from.

Formatdate-time
policy?string

The policy to start from, as a Content-Security-Policy header value without the header name. Leave it out to start from the CentralCSP baseline.

Length1 <= length <= 65536

Response Body

application/json

curl -X POST "https://example.com/v1/workspaces/01936b7a-6f2e-7c31-9a4d-2f8e1c5b7d90/websites/01936b7a-6f2e-7c31-9a4d-2f8e1c5b7d90/csp/recommended-policy" \  -H "Content-Type: application/json" \  -d '{}'
{  "policy": "default-src 'self'; script-src 'self' 'report-sample' 'report-sha256'; script-src-elem 'self' 'report-sample' 'report-sha256' https://cdn.example.com; style-src 'self' 'report-sample'; object-src 'none'; form-action 'self'; frame-ancestors 'none'; base-uri 'self'; upgrade-insecure-requests; report-uri https://e0123456789abcdef0123.report.centralcsp.com; report-to centralcsp",  "reportingEndpoints": "centralcsp=\"https://e0123456789abcdef0123.report.centralcsp.com\", default=\"https://e0123456789abcdef0123.report.centralcsp.com\""}