Error Reference › Browser / Network
Browser / Network
Refused by Content Security Policy
A Content-Security-Policy header blocked a script, style, image, or connection that isn't on its allow-list.
What it looks like
Refused to load the script 'https://cdn.example.com/lib.js' because it violates the following Content Security Policy directive: "script-src 'self'".
What does "Refused by Content Security Policy" mean?
Shown in the DevTools console when a page’s Content-Security-Policy header (or <meta> tag) does not allow a resource. The browser blocks it before it runs, so the feature that depended on it silently breaks.
What causes "Refused by Content Security Policy"?
- Inline script/style without a nonce or hash.
- A resource from a domain not listed in the CSP.
- eval() or inline event handlers under a strict policy.
How do I confirm the cause?
- Read the directive the message quotes — it names the rule (script-src, style-src, img-src, connect-src…) that needs the new source.
- Find where the policy is set: a server header, a framework default or a <meta http-equiv> tag. More than one can apply at once.
- Temporarily switch the header to Content-Security-Policy-Report-Only to see every violation without anything being blocked.
How do I fix "Refused by Content Security Policy"?
- Add the source to the matching CSP directive (script-src, style-src, connect-src…).
- Use a nonce or hash for required inline code, or move it to a file.
- Read the console — it names the directive that blocked it.
How do I stop it happening again?
- Keep the policy in one place and review it whenever you add a third-party script, font or API.
- Prefer external files and nonces over inline scripts and event handlers, so the policy can stay strict.