Skip to content

Quick Start

Get CSP reporting working in 5 minutes.

  1. Sign up at app.headerhawk.com
  2. Create a new site for your domain
  3. Copy your site’s reporting endpoint:
https://ingest.headerhawk.com/csp/YOUR_SITE_ID

Choose your platform:

We recommend starting with Content-Security-Policy-Report-Only to collect violations without breaking your site:

Content-Security-Policy-Report-Only: default-src 'self'; report-uri https://ingest.headerhawk.com/csp/YOUR_SITE_ID

This header tells browsers to:

  1. Check if resources violate the policy
  2. Report violations to Header Hawk
  3. Not block anything (report-only mode)

Visit your Header Hawk dashboard to see incoming CSP violations.

You’ll see:

  • Blocked resources - URLs that would be blocked by your policy
  • Violated directives - Which CSP rules were violated
  • Document URLs - Pages where violations occurred
  • Timestamps - When violations happened