Refused to load the script because it violates the following Content Security Policy directive
The page’s Content-Security-Policy doesn’t allow that script, style, image or connection source.
Seen on:
JavaScript
Meaning
CSP headers whitelist sources. New third-party scripts (analytics, ads, fonts), inline scripts or eval are blocked until added to the policy.
Common causes
- Third-party domain not in script-src/connect-src
- Inline script without nonce/hash
- eval/new Function blocked by missing unsafe-eval
- Images/fonts from unlisted domains
⚡ Quick fix
- Add the domain to the right directive
- Use nonces/hashes for inline scripts
- Test with Content-Security-Policy-Report-Only first
Detailed fix by platform
Nginx
add_header Content-Security-Policy "script-src 'self' https://www.googletagmanager.com" always;
How to diagnose
- Directive — Which directive is violated?
- Source — Which URL was blocked?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026