6 items
Modify request & response HTTP headers and redirect URLs per domain. Multiple named profiles for dev, staging, and prod. DevHeader lets you add, edit, enable/disable, and remove HTTP request and response headers, and redirect request URLs, for the websites you choose. FEATURES • Set, append, or remove both request and response headers • Redirect request URLs via substring or regex find/replace, with a live preview • Scope rules to specific domains, or apply globally when no domain is set • Narrow any rule to specific resource types or request methods • Toggle rules on/off without deleting them, and reorder them with one click • Autocomplete for common header names and values as you type • Quick-add presets: CORS "Allow All", structured CSP / Permissions-Policy builders, and a Set-Cookie/Cookie attribute builder • Mock API responses: intercept a matching fetch()/XHR call and return a synthetic status, body, and headers instead of hitting the real backend — match by URL pattern (REST) or operation name (GraphQL) • A DevTools panel that captures live requests on the page you're inspecting, turns any of them into a Mock Rule in one click, and lets you edit a rule's full response — including a JSON editor that pretty-prints on open — right there • Named profiles: separate domains and rules per profile, with a one-click switcher and a master enable/disable toggle • Duplicate, export, and import profiles as JSON, individually or in bulk • Full UI in 30 languages, automatically matched to your browser's language — one-click toggle to English and back, right in Settings • Light and dark mode — follows your browser's (or DevTools') theme automatically, or set it manually from Settings • Built on Manifest V3 declarativeNetRequest - no blocking webRequest, no background snooping WHY DEVHEADER Built as a minimal, auditable alternative after a popular header-modification extension was pulled from the Edge store for containing dormant domain-harvesting code. DevHeader only requests host permission for the domains you approve, makes no network calls of its own, and ships no remote or dynamically fetched code - the entire codebase is small enough to read end to end. PERMISSIONS • storage: save your header rules, redirect rules, mock rules, profiles, and domain list locally • declarativeNetRequest: apply header and redirect rules to matching requests • scripting / userScripts: run your Mock Rules' synthetic responses on the page - built entirely from the bundled extension code plus your own locally-stored rules, never fetched remotely, never eval()'d • permissions: request host access with a single one-time "Allow access" grant, instead of asking again for every new domain - off by default, and you can revoke it anytime from chrome://extensions No data ever leaves your machine. SUPPORT Found a bug or want a feature? https://www.devheader.com/contact
Sep 11, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.