hsb.horse · Developer Tools
5 items
Capture HTTP response headers and relay fixed or captured headers to matching browser requests. Header Relay helps developers verify browser-based HTTP request behavior when an API or web app depends on custom headers, gateway headers, session tokens, trace IDs, or environment-specific request metadata. Create a profile, choose target origins, configure fixed request headers, and list response headers to capture. When a matching response includes a configured captured header, Header Relay keeps that value in memory for the current browser session and uses Chrome declarativeNetRequest session rules to attach it to later matching requests. Main features: - Origin-scoped header relay for local, staging, internal, and test environments. - Fixed request headers for values that should always be attached. - Captured response headers for values such as session tokens, trace IDs, or gateway headers. - Excluded path glob patterns for assets or endpoints that should not receive relay-managed headers. - Excluded-path tester for checking glob matching rules before saving. - URL Probe to check whether a URL is matched, excluded, and which headers would be attached — works on unsaved drafts. - Full-page settings with section-based navigation for profiles, origins, headers, excluded paths, URL Probe, and audit logs. - Multiple profiles can stay enabled at once, while individual profiles can be deleted when no longer needed. - Comfortable and compact display modes shared by the popup and settings page. - iOS-style UI across popup and settings for a consistent, native feel. - Compact popup status view for active headers, captured values, session state, and DNR rule count. - Local audit logs with automatic retention; request URLs are never persisted. - Japanese and Korean localization. Privacy and security: - Header Relay does not send profile settings, audit logs, usage events, analytics identifiers, browsing data, or captured headers to the developer, analytics providers, or unrelated servers. Configured header values are attached only to matching Target Origins. - Captured values are kept only in in-memory session storage, cleared on browser restart, extension disable/reload/update, profile disable, rule changes, host-access revocation, or manual clear, and masked by default in the UI. - Sensitive header names show a warning. `Cookie` remains available for development workflows with an explicit browser-state warning; response-only and transport-owned headers are rejected. - Audit logs do not persist request URLs: URLs are processed in memory for origin matching only and discarded when the browser closes. - HTTP localhost access is included for the default local-development workflow. Every other host is requested only when you add its Target Origin and optional access can be revoked anytime from Chrome's extension settings. This extension is intended for developers and QA workflows. Do not use it to store production credentials unless that is acceptable for your local browser profile. v0.8.0: - Added a Chrome Web Store review link and a feedback form link to the bottom of the sidebar - Updated website links - Updated dependencies v0.7.1 (Improved background performance): - Restricted unconditional DNR rule rebuilding and storage read/write operations for every matched HTTP response so they only occur when values actually change. - Significantly reduced CPU and I/O load on high-traffic origins by adding a RegExp cache and introducing an in-memory cache to the session store.
Aug 20, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.