Server Config Generator: Redirects & Security Headers

Redirect rules and security headers for Apache, Nginx, Netlify and Vercel.

Free. Runs in your browser: nothing you enter or open is uploaded.

Rules

    

    Test on a staging copy or a single page first. A strict Content-Security-Policy can break analytics, chat widgets and embeds until you add their hosts, which is what report-only mode is for. HSTS with a long max-age is hard to undo, so start short.

    How to use it

    1. Choose your server or host at the top: Apache, Nginx, Netlify, Vercel or Cloudflare.
    2. On Redirects, enter one old and new address or paste a list, and pick 301 for a permanent move or 302 for a temporary one. On Security headers, tick the headers you want and adjust their values.
    3. Copy or download the result and add it to your server configuration, .htaccess, _redirects, _headers or vercel.json, then test a few addresses.

    Questions

    301 or 302: which redirect should I use?

    Use 301 when a page has moved for good: search engines pass its standing to the new address and update their index. Use 302 for a short-term move, such as a page under maintenance. 308 and 307 are the same but also keep the request method, which matters for forms and APIs.

    Where do I put the Nginx rules?

    Inside the server block for your site, usually in a file under /etc/nginx/conf.d or sites-available. Run nginx -t to check the syntax, then reload Nginx.

    Will a Content-Security-Policy break my site?

    It can, if it blocks a script or style your pages need. Start with report-only mode, open your pages and look for blocked items in the browser console, add the hosts you trust, and only then switch to the enforcing header.

    Do I still need X-Frame-Options?

    The frame-ancestors directive in Content-Security-Policy replaces it in all current browsers. Sending X-Frame-Options as well only helps very old browsers, so it is optional.