---
title: "Security.nonce ViewHelper <f:security.nonce>"
manual: "Fluid ViewHelper Reference"
version: "14.3"
permalink: "https://docs.typo3.org/permalink/t3viewhelper:typo3-fluid-security-nonce@14.3"
source: "Global/Security/Nonce.rst"
rendered: "2026-09-27T06:57:21+00:00"
---

# Security.nonce ViewHelper `<f:security.nonce>` {#typo3-fluid-security-nonce}

<!-- TODO: no Markdown rendering for "versionchanged" -->

CSP nonce sources set via the {f:security.nonce()} ViewHelper are no
longer incorrectly considered negligible. The newly introduced directive
and scope arguments allow TYPO3 to correctly assign that nonce to the
appropriate CSP directive, whereas previously the nonce could be silently
discarded due to missing context.

The `{f:security.nonce()}` ViewHelper generates a CSP
([Content Security Policy](https://docs.typo3.org/m/typo3/reference-coreapi/14.3/en-us/ApiOverview/ContentSecurityPolicy/Index.html#content-security-policy))
nonce and registers it for inclusion in the CSP header.

> [!TIP]
> **Hint**
>
> The `{f:security.nonce()}` view-helper is meant as a compatibility
> fallback. It is suggested to use more specific ViewHelpers like
> [Asset.css ViewHelper \<f:asset.css>](https://docs.typo3.org/permalink/t3viewhelper:typo3-fluid-asset-css@14.3)
> or [Asset.script ViewHelper \<f:asset.script>](https://docs.typo3.org/permalink/t3viewhelper:typo3-fluid-asset-script@14.3).

Go to the source code of this ViewHelper: [Security\\NonceViewHelper.php (GitHub)](https://github.com/TYPO3/typo3/blob/main/typo3/sysext/fluid/Classes/ViewHelpers/Security/NonceViewHelper.php).

**Table of contents**

-   [Examples of security.nonce ViewHelper usage](https://docs.typo3.org/permalink/t3viewhelper:examples-of-security-nonce-viewhelper-usage@14.3)
-   [Arguments of the <f:security.nonce> ViewHelper](https://docs.typo3.org/permalink/t3viewhelper:arguments-of-the-f-security-nonce-viewhelper@14.3)

## Examples of security.nonce ViewHelper usage {#typo3-fluid-security-nonce-example}

**Basic usage**

```html
<script nonce="{f:security.nonce()}">const inline = 'script';</script>
```

The optional arguments `directive` and `scope` can be used to explicitly
declare how the generated nonce should be applied to the Content Security
Policy. This avoids ambiguity and allows TYPO3 to assign the nonce to the
correct CSP directive.

### Inline script (default scope) {#typo3-fluid-security-nonce-example-inline-script}

Inline scripts require the nonce to be registered for the
`script-src` CSP directive. The `inline` scope is the default and may be
omitted.

**Inline script with explicit directive**

```html
<script nonce="{f:security.nonce(directive: 'script-src')}">
    const test = true;
</script>
```

### External script (static scope) {#typo3-fluid-security-nonce-example-external-script}

When a nonce is applied to an external script, the `static` scope should
be used. This allows TYPO3 to correctly associate the nonce with a static
script element.

**External script with nonce**

```html
<script
    src="{scriptUri}"
    nonce="{f:security.nonce(directive: 'script-src', scope: 'static')}"></script>
```

### Inline styles with nonce attribute {#typo3-fluid-security-nonce-example-inline-style}

The ViewHelper can also be used for inline styles by specifying the
corresponding style directive.

**Inline style block**

```html
<style nonce="{f:security.nonce(directive: 'style-src')}">
    body {
        background-color: #f5f5f5;
    }
</style>
```

## Arguments of the `<f:security.nonce>` ViewHelper {#typo3-fluid-security-nonce-arguments}

<!-- TODO: no Markdown rendering for "versionadded" -->

The arguments directive and scope were introduced.

Parameter `directive` can be one of `default-src`, `script-src`,
`script-src-elem`, `style-src`, or `style-src-elem` (referring to a CSP directive).

-   **directive**

    -   *Type:* string

    Value of the CSP directive

-   **scope**

    -   *Type:* string
    -   *Default:* 'inline'

    \`inline\` or \`static\`
