Setup
Report URI supports a wide range of browser security standards and reporting mechanisms. Select a feature below to get started.
- Content Security Policy - collect and analyse CSP violation reports
- CSP Wizard - build a CSP policy step by step
- CSP Integrity - enforce Subresource Integrity via CSP
- Custom Integrity Hashes - label your own scripts in integrity reports
- Integrity Policy - require SRI on all scripts and stylesheets
- Script Watch - monitor changes to scripts loaded on your site
- Data Watch - detect unexpected data exfiltration
- Frame Watch - detect unexpected framing of your site
- Policy Watch - monitor changes to your security headers
- Network Error Logging - capture network-level errors from browsers
- Permissions Policy - control access to browser features
- Reporting API - configure reporting via the modern Reporting API
- Certificate Transparency - monitor CT logs for certificates issued for your domains
- DMARC - collect DMARC aggregate and forensic reports
- Cross-Origin Embedder Policy - isolate your document's browsing context
- Cross-Origin Opener Policy - control cross-origin window interactions
- SMTP TLS - monitor TLS reporting for your mail domains
- Sampling - reduce report volume with server-side sampling
- Single Sign-On (SAML) - log your team in through your own Identity Provider
- IP Allow List - restrict account and API key access to known IP ranges
Working towards PCI DSS 4.0? See the Compliance guides for putting these features together to meet Requirements 6.4.3 and 11.6.1.
Running on a named platform such as Adobe Commerce, Shopify or Google Tag Manager? The Platforms guides cover what each one supports and where the reporting endpoint goes. Emitting the header from your own application? The Frameworks guides cover Django, Rails, Laravel, Express, Next.js and more.