CrawlCheck

Glossary · HTTP, edge and rendering

CSP nonce

A random value generated per response, placed on the Content-Security-Policy header and on every inline script the server writes, so that only scripts carrying that value run.

What CSP nonce means

A random value generated per response, placed on the Content-Security-Policy header and on every inline script the server writes, so that only scripts carrying that value run. It defeats injected scripts without allowlisting hosts; it fails silently when any response path skips the swap, because the header then names a nonce the page does not carry.

Terms this definition uses

Place · Content-Security-Policy · Allowlist

Related terms in HTTP, edge and rendering

The delivery layer between an origin and a client: proxies, caches, redirects, status codes and the headers that decide what a crawler actually received.

Origin server · Reverse proxy · CDN · Edge node · WAF · Bot score · TLS handshake · DNS resolution · DNS timeout · Connection timeout · Read timeout · Redirect chain · Redirect loop · 301 redirect · 302 redirect · 307 redirect · 308 redirect · 304 response · 404 response · 410 response · 429 response · 500 response · 502 response · 503 response · 504 response · HEAD request · GET request · Content type · MIME sniffing · Content encoding · Compression · Brotli · ETag · Last-Modified · If-None-Match · Cache hit · Cache miss · Cache key · Vary header · Stale response · Stale-while-revalidate · Edge redirect · Origin bypass · Response parity · Header parity · hreflang · canonical URL · HSTS · HSTS preload list · Content-Security-Policy · edge cache · cache split · cache-buster · Cache-Control · Age header · render-blocking resource · payload text share · lazy loading · 404 and 410 status codes

Questions about CSP nonce

What is CSP nonce?

A random value generated per response, placed on the Content-Security-Policy header and on every inline script the server writes, so that only scripts carrying that value run.

What does CSP nonce not show or guarantee?

A random value generated per response, placed on the Content-Security-Policy header and on every inline script the server writes, so that only scripts carrying that value run. It defeats injected scripts without allowlisting hosts; it fails silently when any response path skips the swap, because the header then names a nonce the page does not carry.

Which area of the glossary does CSP nonce belong to?

HTTP, edge and rendering: The delivery layer between an origin and a client: proxies, caches, redirects, status codes and the headers that decide what a crawler actually received.

← Content-Security-Policy  ·  edge cache →

See it in the full glossary · 668 terms across 19 areas.