5 items
Add, rewrite, and remove HTTP request and response headers. Organise rules into profiles and scope them with URL filters. Add, rewrite, and remove HTTP request and response headers from your browser toolbar. Group rules into profiles, scope them to the URLs you care about, and flip the whole thing off with one keystroke. Headers/Cookies that carry credentials — `Authorization`, `Cookie`, API keys — are recognised on sight and handled apart from the rest of your configuration: encrypted behind a passphrase, or held in memory for a single session. Built on Manifest V3 for both Chromium and Firefox. No account, no telemetry, no network calls — everything stays on your machine. Features: Header editing: - Set, append, or remove headers on both requests and responses - Enable or disable any single header without deleting it - Attach a comment to any row as a note to yourself - Autocomplete for common request and response header names - Live count of active rules on the toolbar badge **Credential security** - `Authorization`, `Cookie`, API keys and common vendor variants are recognised as credentials automatically — and the shield button on any row marks a header no list would guess - Three storage modes: memory-only for the session (default), an encrypted vault behind a passphrase, or the original persistent plaintext if you need it - Credential headers/cookies stay inactive until their profile has a real URL or host filter, so a token can't be broadcast to every site you visit - A warning when a credential profile targets a plain `http://` host - Lock from the title bar or let it auto-lock — locking freezes only the profiles holding credentials - Exports and clipboard copies omit credentials unless you ask otherwise Cookie editor: - Edit individual cookies instead of hand-writing the whole `Cookie` header - Request cookies merge with what the browser already sends, or replace it entirely - Response cookies become `Set-Cookie` with full attribute control: Path, Domain, Max-Age, SameSite, Secure, HttpOnly Content-Security-Policy editor: - Leave CSP alone, strip it entirely, or replace it with a policy you compose - Build the policy one directive at a time with autocomplete for standard directive names - Live preview of the exact header that will be sent - Toggle between enforcing and `Report-Only` Redirects: - Send matching requests somewhere else — handy for pointing a CDN asset at localhost - Match by substring or regex, with `\\1` capture-group substitution in the target Profiles: - Unlimited independent header sets, each with its own name and colour - All enabled profiles apply at once, so you can layer an auth-token profile over a feature-flag profile - Duplicate, rename, recolour, and delete from the profile menu Filtering: - `URL contains` — plain substring match - `URL matches regex` — full regular expression - `Exclude URL containing` / `Exclude URL regex` — carve exceptions out of a match - `Exclude domains` — skip named domains and their subdomains - `Resource types` — restrict to `xmlhttprequest`, `main_frame`, `script`, and so on - `Tab` / `Window` — scope a profile to one tab or window, with a **Use current** button that fills in the id for you - Leave filters empty and the profile applies everywhere Everything else: - Global on/off switch, plus `Alt+Shift+H` from anywhere - Undo with `Ctrl+Z` (or the toolbar arrow) — 40 steps of history - Profile search once you have more than five profiles - Export and import profiles as JSON to share a setup or check it into a repo - Open the popup in a full browser tab when you're editing a lot at once - Follows your system light/dark theme - Warns you before saving a rule the browser will reject Update Changelogs can be seen here: https://github.com/Multivalence/OpenModHeader/releases
Aug 24, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.