New: export PCI DSS v4 evidence from real browser traffic.

Chrome extension

Build CSP right in your browser.

Watch live CSP violations, rewrite the policy on the fly, or auto-build a strict header, against real production pages, with no deploys.

5.0600+ users on the Chrome Web Store

One extension, three ways to work a policy.

Pick the mode that matches where you are, from watching what breaks to shipping a locked-down header.

Observe

Stream every violation from the site's existing CSP into the popup and DevTools panel, mapped line by line to the policy that broke, without changing a thing.

Rewrite

Swap in your candidate policy on the fly. Choose Enforce or Report-Only, Replace or Append, reload, and watch violations stream in as parsed and raw JSON.

Build

Start from a strict report-only base, browse the site normally, and let the extension classify violations by directive and assemble a working policy from real page loads.

See the extension in action.

The loop

A five-second feedback loop.

Edit the policy, reload, and see exactly what breaks, against the real page and its real third-parties. No staging, no deploy.

install

One click from the Chrome Web Store. The extension stays inactive until you switch it on for a site.

pick a mode

Choose Observe, Rewrite, or Build depending on whether you're watching, testing, or authoring.

iterate

Edit the policy and reload. Each pass gives you five-second feedback against real third-parties.

ship

Refine the assembled policy, then ship it Report-Only first, then Enforce.

Everything you need to get a policy right.

A full CSP toolkit in the toolbar, from live rewriting to a copy-ready header.

Rewrite live headers

Replace or append the CSP on any response, in Enforce or Report-Only, without touching the server.

Real-time violations

Every violation streamed the instant it fires, with the parsed report and the raw JSON side by side.

Auto-build policies

Turn observed traffic into a strict policy, classified by directive and grounded in real page loads.

Copy-ready headers

Generate a clean, deploy-ready Content-Security-Policy header you can paste straight into your config.

Fully local

No accounts, no telemetry, no outbound calls. Everything runs and stays inside your browser.

Works on production

Test against the real page and its real third-parties. A CSP you can't test against the real page is a guess.

Beyond the browser

The extension builds the policy. The platform keeps it honest.

Author in the browser, then monitor the same policy in production around the clock.

From one-off testing to continuous protection

The extension is where you author and debug. The CentralCSP platform then watches that policy in production, around the clock, across every visitor's browser.

Start free trial
Continuous client-side monitoring dashboard

Continuous collection

24/7 CSP report collection from your real users' browsers, not a single local session.

Script inventory

Every script on every page, fingerprinted with SHA-256/384/512 hashes and checked for known CVEs.

Alerts and PCI evidence

Real-time Slack and webhook alerts on new origins and scripts, plus auditor-ready PCI DSS v4 evidence.

FAQ

Extension questions, answered

The essentials on installing, privacy, and how the extension fits with the platform.

Start building your CSP in the browser.

Add the extension in one click. It's free, local, and needs no signup.