Free tools
CSP tools
Small tools for the parts of a Content Security Policy that are fiddly to do by hand. No account, no email address, and no upload: each one is a script that runs in the page you are reading, so the policy you paste stays in your browser.
Nothing here is a lead magnet
A policy header describes what a site loads and from where, which is not something anyone should paste into a form in exchange for an email address. These tools do their work in JavaScript on this page — you can confirm that in your browser's network tab, which stays empty while you use them. What HeaderHawk sells is the other half of the problem: the violation reports that say what a policy is doing to real traffic, which no amount of reading the header can tell you.