Sec-Fetch Metadata Request Isolation Policy Builder
Build Next.js & Express middleware using Sec-Fetch-Site, Mode, and Dest headers to eliminate CSRF and XS-Leaks.
Execution runs 100% locally inside the browser sandbox using HTML5 Canvas, Web Cryptography Subtle API, and Web Workers. No data is ever transmitted across the network.
Zero network latency. Operates completely offline with zero dependencies on third-party backend servers or cloud services.
Built according to official RFC specifications, cryptographic test vectors, and enterprise-grade data transformation standards.
How to Use Sec-Fetch Metadata Request Isolation Policy Builder
Toggle same-site only, top-level navigations, and image exemptions.
Review the TypeScript request isolation function.
Integrate into your Next.js middleware.ts or Express server.
Frequently Asked Questions
What is Sec-Fetch-Site?
Sec-Fetch-Site indicates the relationship between the initiator's origin and the target origin (same-origin, same-site, cross-site, none).
Does this replace CSRF tokens?
Resource isolation via Sec-Fetch metadata provides powerful defense-in-depth that can prevent unauthorized cross-origin requests at the gateway.
Related Security & Network Tools
View all →Split master passwords into M-of-N threshold shares with GF(256) math.
Generate cryptographically secure 12, 18, or 24-word seed phrases.
Calculate network address, broadcast, usable host IP range, and masks.
Derive secure keys with customizable iterations, salts, and SHA hashes.