5 items
Add, rewrite and remove HTTP request and response headers. Organise rules into profiles and scope them by URL. Headsmith modifies HTTP request and response headers — organised into profiles and scoped by domain, URL or regex. IT CANNOT SEE YOUR TRAFFIC Headsmith is built entirely on Chrome's declarativeNetRequest API. It hands the browser a list of rules and the browser applies them. Headsmith is never invoked for a request: it does not receive the URL, the headers, the body, or the response. This is not a policy — it is the shape of the API. Reading traffic would require the webRequest permission. Headsmith does not request it, and a check in its build pipeline fails if that ever changes. IT ASKS FOR NO SITES WHEN YOU INSTALL IT There is no "read and change all your data on all websites" prompt, because at install Headsmith is granted nothing at all. When a profile names a domain, Chrome asks about that domain and nothing else. Every site you have allowed is listed in the extension's settings and can be withdrawn there. Profiles scoped by URL text or a regular expression can match any site, so those ask for broader access — and say so before asking. FEATURES • Set, append and remove request and response headers • Profiles you can switch between, enable individually, or pause entirely • Scope by domain, URL substring, URL regex and resource type • Per-profile domain exclusions and a global never-modify list • Credentials stored separately from profiles — session-only by default, or in a passphrase-encrypted vault (AES-GCM, PBKDF2 at 600,000 iterations) • A credential-bearing profile must name where it applies, so a token cannot be attached to every request your browser makes • Site access granted per domain, listed and revocable at any time • Dark mode, import and export VERIFIABLE BUILDS The build is reproducible and every release carries a GitHub provenance attestation. You can rebuild from source and confirm byte-for-byte that the published extension matches. The bundle is not minified, so the shipped code can be read. Instructions are in the README. NO DATA COLLECTION No analytics. No telemetry. No network requests of any kind — this is enforced by a CI check that scans the built extension and fails the build if any network primitive or remote resource appears in it. Open source, MIT licensed.
Aug 16, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.