report-uri is widely supported but deprecated. report-to works in Chrome; partial/no support in Firefox and Safari.
Each asks the browser for one more Reporting API type, sent to an endpoint named default. Every policy is report-only except document policy's, which restates Chrome's default.
Trigger Violations
Before You Start
A report can be sent and still never reach the dashboard. For each type you test, check that:
The type is switched on in the site's report type settings (Settings › Sites). A type that is off is dropped at ingestion.
Deprecations and interventions are at 100%. They default to a 5% sample rate, so most are dropped and counted as ReportsSampledOut.
The site's domain matches this page's host. Ingestion answers 204 and stores nothing for a report from any other host. The NEL DNS-failure report names a made-up subdomain, so add a wildcard for this host as well.
A person, or a headed browser, sends it. A report whose user agent says HeadlessChrome is stored as known noise, and the dashboard's pages leave known noise out.
You give it a minute. Chrome batches deliveries, so a report can take a minute to leave the browser. DevTools › Application › Reporting API shows each one queued, pending or sent.
Every stored report also appears in the Explorer, whichever page its trigger names.
Trigger Other Report Types
Fires every enabled trigger that is safe to fire together: not the crashes, and not the reloads.
Fires on load, not on a click: a click is the user activation that lets navigator.vibrate through, so each load with this type on calls it first (NavigatorVibrate). Scrolling the page with a mouse wheel or trackpad sends a second one (PreventDefaultPassive), from a wheel listener that tries to cancel a scroll Chrome treats as passive.
Both kill this tab. Chrome sends the report once the tab is gone, to an endpoint named crash-reporting if the page declares one and to default otherwise. The out-of-memory crash arrives with no reason; the hang, ended with Exit page, arrives as unresponsive.
Enforced, and still harmless: js-profiling=?0 is Chrome's default, so the header only names where to report. Chrome 153 sends nothing for document-write=?0, which it no longer recognises, nor for a report-to that is not a parameter on the feature.
Serves Report-To + NEL · sends network-error · look in Browser signals › Reliability
Chrome 154 sent nothing for the DNS failure: the lookup fails (ERR_NAME_NOT_RESOLVED) under an include_subdomains policy, and no report left the browser, headless or headed, in a fresh profile or a real one. The trigger stays for a Chrome that does. Its report would name the made-up subdomain, so the site's hosts would need a wildcard for this host as well as the host itself.
The page loads an image from outside the allowlist as it is served, the one case Chrome queues a report for. Chrome queues it before the page's endpoints are registered and delivers it only once this origin loads again, so the report arrives after a reload (task 316's first measurement never reloaded, and saw nothing).
A type's triggers are enabled once it is ticked above and applied.
Script Integrity
Enable integrity above, then click Apply Settings to load an external script for hash reporting.
Hash reports are delivered over the Reporting API, so they need the report-to mechanism — report-uri carries violation reports only and has no way to convey a hash report. Enabling integrity therefore selects report-to for you.
Browser support: Chromium 133+ implements report-sha256; WebKit is in progress; Firefox does not support it. Verified against Chrome 152 in September 2026: a freshly fetched, executed script produced no csp-hash report under either mechanism or either mode, while csp-violation reports were produced normally. Treat the absence of hash reports as expected for now rather than as a misconfiguration. Check Application > Reporting API in DevTools.
Endpoint not usable — Endpoint still has the placeholder your-ingest-code. Replace it with your site's ingest code. No reporting directive is being served, and triggers are disabled until you fix it and click Apply Settings.