More
More
Server Config Generator: Redirects & Security Headers
Redirect rules and security headers for Apache, Nginx, Netlify and Vercel.
Free. Runs in your browser: nothing you enter or open is uploaded.
Write the pattern for the path, for example ^/blog/(.*)$, and use $1 in the new address for the first group: /news/$1.
Test on a staging copy or a single page first. A strict Content-Security-Policy can break analytics, chat widgets and embeds until you add their hosts, which is what report-only mode is for. HSTS with a long max-age is hard to undo, so start short.
How to use it
- Choose your server or host at the top: Apache, Nginx, Netlify, Vercel or Cloudflare.
- On Redirects, enter one old and new address or paste a list, and pick 301 for a permanent move or 302 for a temporary one. On Security headers, tick the headers you want and adjust their values.
- Copy or download the result and add it to your server configuration, .htaccess, _redirects, _headers or vercel.json, then test a few addresses.
Questions
301 or 302: which redirect should I use?
Use 301 when a page has moved for good: search engines pass its standing to the new address and update their index. Use 302 for a short-term move, such as a page under maintenance. 308 and 307 are the same but also keep the request method, which matters for forms and APIs.
Where do I put the Nginx rules?
Inside the server block for your site, usually in a file under /etc/nginx/conf.d or sites-available. Run nginx -t to check the syntax, then reload Nginx.
Will a Content-Security-Policy break my site?
It can, if it blocks a script or style your pages need. Start with report-only mode, open your pages and look for blocked items in the browser console, add the hosts you trust, and only then switch to the enforcing header.
Do I still need X-Frame-Options?
The frame-ancestors directive in Content-Security-Policy replaces it in all current browsers. Sending X-Frame-Options as well only helps very old browsers, so it is optional.