Glossary · HTTP, edge and rendering
CSP nonce
A random value generated per response, placed on the Content-Security-Policy header and on every inline script the server writes, so that only scripts carrying that value run.
What CSP nonce means
A random value generated per response, placed on the Content-Security-Policy header and on every inline script the server writes, so that only scripts carrying that value run. It defeats injected scripts without allowlisting hosts; it fails silently when any response path skips the swap, because the header then names a nonce the page does not carry.
Terms this definition uses
Place · Content-Security-Policy · Allowlist
Related terms in HTTP, edge and rendering
The delivery layer between an origin and a client: proxies, caches, redirects, status codes and the headers that decide what a crawler actually received.
Origin server · Reverse proxy · CDN · Edge node · WAF · Bot score · TLS handshake · DNS resolution · DNS timeout · Connection timeout · Read timeout · Redirect chain · Redirect loop · 301 redirect · 302 redirect · 307 redirect · 308 redirect · 304 response · 404 response · 410 response · 429 response · 500 response · 502 response · 503 response · 504 response · HEAD request · GET request · Content type · MIME sniffing · Content encoding · Compression · Brotli · ETag · Last-Modified · If-None-Match · Cache hit · Cache miss · Cache key · Vary header · Stale response · Stale-while-revalidate · Edge redirect · Origin bypass · Response parity · Header parity · hreflang · canonical URL · HSTS · HSTS preload list · Content-Security-Policy · edge cache · cache split · cache-buster · Cache-Control · Age header · render-blocking resource · payload text share · lazy loading · 404 and 410 status codes
Questions about CSP nonce
What is CSP nonce?
A random value generated per response, placed on the Content-Security-Policy header and on every inline script the server writes, so that only scripts carrying that value run.
What does CSP nonce not show or guarantee?
A random value generated per response, placed on the Content-Security-Policy header and on every inline script the server writes, so that only scripts carrying that value run. It defeats injected scripts without allowlisting hosts; it fails silently when any response path skips the swap, because the header then names a nonce the page does not carry.
Which area of the glossary does CSP nonce belong to?
HTTP, edge and rendering: The delivery layer between an origin and a client: proxies, caches, redirects, status codes and the headers that decide what a crawler actually received.
← Content-Security-Policy · edge cache →
See it in the full glossary · 668 terms across 19 areas.