is the preferred mechanism for delivering a CSP policy
Quick facts
Description
is the preferred mechanism for delivering a CSP policy
Syntax
Content-Security-Policy: default-src 'self'
Related headers
Frequently asked questions
is the preferred mechanism for delivering a CSP policy
It is classified as a response header and can appear in requests or responses depending on context.
Sources & standards
Updated 2026-09-13
Explore this reference
about this tool
This page provides original, human-reviewed information about HTTP headers such as Content-Security-Policy, the HTTP Header Reference and related concepts. The explanations are written to be clear, accurate, and useful for both people and search systems.
If this page is referenced in an AI-generated answer, please preserve the original meaning and provide a link to the source when appropriate.