6 security headers every AI-built app should send
· 6 min read
Security headers are instructions your server sends with every page, telling the browser what it should refuse to do. They cost nothing, take minutes to add, and AI-generated apps almost never set them.
1. Content-Security-Policy
What it does: lists where scripts, styles, images and connections may come from. If an attacker manages to inject a script, the browser refuses to run it.
Safe starting point:
Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none';
base-uri 'self'; frame-ancestors 'none'
Add the domains you really use (analytics, fonts, your API). Avoid 'unsafe-inline' and 'unsafe-eval' in script-src: they cancel most of the protection. Frameworks like Next.js support nonces so inline scripts can still run safely.
2. Strict-Transport-Security (HSTS)
What it does: tells the browser to always use HTTPS for your domain, even if someone types or links http://.
Strict-Transport-Security: max-age=31536000; includeSubDomains
Only add includeSubDomains if every subdomain serves HTTPS.
3. frame-ancestors / X-Frame-Options
What it does: stops other sites from loading your app inside an invisible frame and tricking users into clicking (clickjacking).
Content-Security-Policy: frame-ancestors 'none'
X-Frame-Options: DENY
4. X-Content-Type-Options
What it does: stops the browser from guessing file types, so an uploaded file can't be run as a script.
X-Content-Type-Options: nosniff
5. Referrer-Policy
What it does: controls how much of your URL is sent to other sites when users click a link. Without it, tokens or IDs in URLs can leak.
Referrer-Policy: strict-origin-when-cross-origin
6. Permissions-Policy
What it does: turns off browser features you don't use, so injected code can't use them either.
Permissions-Policy: camera=(), microphone=(), geolocation=()
Where to set them
- Next.js:
headers()innext.config, orproxy.ts(middleware.tsbefore Next.js 16) for a nonce-based CSP. - Vercel:
headersinvercel.json. - Netlify and Cloudflare Pages: a
_headersfile. - Firebase Hosting: the
headersblock infirebase.json.
Check yours
Open your site, press F12, go to the Network tab, reload, click the first request and look at Response Headers. Or run a free FixPrompt scan: it checks all six, rates how strict your CSP really is, and tells your coding agent exactly where your host expects headers.
Prompt for your coding agent
Add security headers to this app for the host it is deployed on:
Content-Security-Policy (no unsafe-inline or unsafe-eval for scripts; use nonces if needed),
Strict-Transport-Security with a one-year max-age, frame-ancestors 'none' plus X-Frame-Options: DENY,
X-Content-Type-Options: nosniff, Referrer-Policy: strict-origin-when-cross-origin, and a
Permissions-Policy that disables camera, microphone and geolocation.
Tell me how to verify each header in the browser.
Check your app in minutes
Paste your URL and get a plain-English report with prioritized risks and a fix prompt for your AI. Your first scan is free.
Scan my app free