Error Reference › Browser / Network
Browser / Network

Refused by Content Security Policy

A Content-Security-Policy header blocked a script, style, image, or connection that isn't on its allow-list.

What it looks like

Refused to load the script 'https://cdn.example.com/lib.js' because it violates the following Content Security Policy directive: "script-src 'self'".

What does "Refused by Content Security Policy" mean?

Shown in the DevTools console when a page’s Content-Security-Policy header (or <meta> tag) does not allow a resource. The browser blocks it before it runs, so the feature that depended on it silently breaks.

What causes "Refused by Content Security Policy"?

  • Inline script/style without a nonce or hash.
  • A resource from a domain not listed in the CSP.
  • eval() or inline event handlers under a strict policy.

How do I confirm the cause?

  1. Read the directive the message quotes — it names the rule (script-src, style-src, img-src, connect-src…) that needs the new source.
  2. Find where the policy is set: a server header, a framework default or a <meta http-equiv> tag. More than one can apply at once.
  3. Temporarily switch the header to Content-Security-Policy-Report-Only to see every violation without anything being blocked.

How do I fix "Refused by Content Security Policy"?

  • Add the source to the matching CSP directive (script-src, style-src, connect-src…).
  • Use a nonce or hash for required inline code, or move it to a file.
  • Read the console — it names the directive that blocked it.

How do I stop it happening again?

  • Keep the policy in one place and review it whenever you add a third-party script, font or API.
  • Prefer external files and nonces over inline scripts and event handlers, so the policy can stay strict.
Got a different error? Paste it into the Explain This Error tool → Identifies the family and the fix — runs locally, nothing uploaded.

Related errors