Inline Code Utility

CSP Hash Generator

Generate a CSP hash for an inline script or style block. Paste its exact contents, choose an algorithm, and copy the hash into your policy. Calculation happens in your browser; this tool does not upload, run, or save the code you enter.

Scan a Website

Hash an inline block

Paste only the text inside one <script> or <style> element, without the tags. Spaces, capitalization, and leading or trailing newlines matter. Maximum: 64 KiB of UTF-8 text.

This editor uses LF line endings, as HTML parsing does for inline element text. No trimming or formatting is applied. Use the rendered element's contents when your build changes the source.

Enable JavaScript to calculate a hash locally.

The fragment permits this block only. It is not a complete CSP header or a replacement for your existing source list.

Add the hash to your policy

  1. Review the code before authorizing it. Copy the quoted hash source, including its single quotes.
  2. Add it to your existing script-src or style-src source list. If your policy uses script-src-elem or style-src-elem, update that more-specific directive instead. Avoid appending a duplicate directive.
  3. Test the complete policy with the report-only header, then inspect the delivered header and browser violations. Other enforced policies still apply.
  4. Regenerate the hash whenever that inline block changes, including changes from minification or templating.

For deployment syntax, use the CSP header examples. To discover sources across a site, use the CSP scanner.

Why does a hash fail to match?

Check for included HTML tags, changed indentation, an extra newline, or output rewritten by a build tool. Hash the exact inline text the browser receives. A nonce may be more suitable when the text varies with each response; see dynamic CSP generation.

Does this allow event handlers or style attributes?

This workflow targets script and style elements. Adding a hash alone does not authorize onclick handlers or style attributes. Prefer event listeners and stylesheets rather than broadening your policy to allow inline attributes.

Hash syntax and browser references