CSPViolationReport: statusCode property

Baseline 2026
Newly available

Since March 2026, this feature works across the latest devices and browser versions. This feature might not work in older devices or browsers.

The statusCode property of the CSPViolationReport dictionary is a number representing the HTTP status code of the response to the request that triggered a Content Security Policy (CSP) violation (when loading a window or worker).

Value

A number representing the HTTP status code of the response to the request that triggered the CSP violation.

Examples

In this example we create a new ReportingObserver to observe content violation reports of type "csp-violation". Each time the callback function is invoked, we log the status code for the first entry of the reports array.

js
const observer = new ReportingObserver(
  (reports, observer) => {
    console.log(`statusCode: ${reports[0].body.statusCode}`);
    // For example: 200
  },
  {
    types: ["csp-violation"],
    buffered: true,
  },
);

observer.observe();

Note that while there might be multiple reports in the returned array, for brevity we only log the status code of the first report.

Specifications

Specification
Content Security Policy Level 3
# reporting

Browser compatibility

See also