HttpArmor
Load Preset
Modern SPA
Static Site
WordPress
Secure Default
Generated Configuration
Copy
Content-Security-Policy
default-src
'i'
script-src
'i'
style-src
'i'
img-src
'i'
object-src
'i'
frame-ancestors
'i'
base-uri
'i'
Permissions-Policy
accelerometer
'i'
ambient-light-sensor
'i'
attribution-reporting
'i'
autoplay
'i'
bluetooth
'i'
Browse-topics
'i'
camera
'i'
compute-pressure
'i'
cross-origin-isolated
'i'
display-capture
'i'
encrypted-media
'i'
fullscreen
'i'
gamepad
'i'
geolocation
'i'
gyroscope
'i'
hid
'i'
identity-credentials-get
'i'
idle-detection
'i'
local-fonts
'i'
magnetometer
'i'
microphone
'i'
midi
'i'
otp-credentials
'i'
payment
'i'
picture-in-picture
'i'
publickey-credentials-create
'i'
publickey-credentials-get
'i'
screen-wake-lock
'i'
serial
'i'
speaker-selection
'i'
storage-access
'i'
usb
'i'
web-share
'i'
window-management
'i'
xr-spatial-tracking
'i'
Cross-Origin Policies
Cross-Origin-Opener-Policy
'i'
same-origin
same-origin-allow-popups
unsafe-none
Cross-Origin-Embedder-Policy
'i'
require-corp
credentialless
unsafe-none
Cross-Origin-Resource-Policy
'i'
same-origin
same-site
cross-origin
Strict-Transport-Security
max-age (seconds)
'i'
includeSubDomains
'i'
General & Legacy Headers
X-Content-Type-Options
'i'
nosniff
X-Frame-Options
'i'
DENY
SAMEORIGIN
Referrer-Policy
'i'
strict-origin-when-cross-origin
no-referrer
same-origin
Cache-Control
'i'
no-store, no-cache, must-revalidate
private, max-age=3600