← All tools

CSP header parse (DQ)

Readable CSP audit from curl -I.

Client
• default-src 'self'
• script-src 'self' https://cdn.example.com

Nearby workflows on Toolcore

  • CSP header builderBuild a Content-Security-Policy header from directive fields—copy for nginx, Express, or CDN configs locally. when headers, identifiers, or reference tables need a sibling check.
  • HTTP headersCommon request and response header fields—names, direction, and short summaries—filterable client-side. when headers, identifiers, or reference tables need a sibling check.
  • HTTP fetch testSend GET/POST and other methods from your browser—see status and body; CORS limits apply. when headers, identifiers, or reference tables need a sibling check.
  • cURL command parserParse curl CLI snippets into method, URL, headers, and body—local best-effort helper for API debugging. when headers, identifiers, or reference tables need a sibling check.

Common use cases

  • CSP header parse (DQ) for quick local checks without uploading data.
  • Copy results into tickets, docs, or classroom notes.

Common mistakes to avoid

  • Unexpected input shape

    See the intro and how-to notes for accepted formats.

FAQ

Is processing local?

Yes—this runs entirely in your browser.

Agent prefill?

Use q or qb for the main text field when supported.

Related utilities you can open in another tab—mostly client-side.