Migrating from ModHeader
A ModHeader alternative that keeps your headers local. There are two ways to bring your header profiles to HeaderVault: import a JSON export you already saved, or recreate the rules by hand.
Before you start
- Install HeaderVault from your browser's add-on store.
- Click the HeaderVault icon. When you enable your first header, the browser asks for access to all sites — allow it, otherwise rules have no effect.
Which path fits you: if you have a .json file exported from ModHeader earlier (for example, a backup or a file shared by your team), use path 1. If you have no export, use path 2.
Path 1: import a saved export
- Click the HeaderVault icon and choose Import / Export. The editor opens in a tab.
- Under Import, choose your
.jsonfile. - Review the summary: the number of profiles and header rows, every URL filter with its type, and every setting that was skipped or marked, with the reason.
- Click Import. The profiles are added next to your existing ones; a name that already exists gets “(2)”.
- Imported profiles are not activated automatically. Check them, then click a profile tab to make it active.
What is imported
| In your export | In HeaderVault |
|---|---|
| Request and response headers | Header rows with their on/off state |
| Header with an empty value | A Remove row (or a Set row marked “Value required” if the export asked to send empty headers) |
| Append mode | Append rows where the browser allows it, joined with a separator |
| URL filters and exclude filters | Include and exclude filters. Values starting with | or || become Patterns, others Regex. Regex the browser cannot run is imported disabled, with an error |
| Old-format URL filters | Regex anchored to the start of the URL, as older versions matched |
| Resource type filters | Resource types of the profile |
| Request cookies | Append rows for the Cookie header |
What is not imported
Comments, profile colors, “always on”, URL redirects, the CSP editor, Set-Cookie modifiers, regex cookies, request method filters, tab, window and time filters, and values defined as functions. Each one appears in the import summary with a reason, so you can see what to recreate by hand.
Path 2: recreate your rules by hand
Most setups are a handful of headers and one or two URL filters, so this takes a few minutes. Write down the headers you used (names and values come from your own services, documentation or team notes), then:
- Click the HeaderVault icon. Rename Profile 1 to something like “Staging”.
- Under Request headers, click Add header, pick an operation and enter the name and value:
- Set sends the header with your value, replacing the original;
- Remove drops the header;
- Append adds your value to the existing one (for request headers, only where the browser allows it, such as
CookieorAccept).
- Add response headers the same way under Response headers.
- Open URL filters and resource types to limit the profile to your sites, for example the Pattern
||api.example.com^. Without include filters, the profile applies to all URLs. - Create more profiles with + and switch between them with one click.
- When you are done, export your profiles to a JSON file as a backup.
Concepts side by side
| You used | In HeaderVault |
|---|---|
| Profile | Profile tab; one profile is active at a time |
| Header row with a checkbox | Header row with a switch and an explicit Set, Remove or Append |
| Empty value to remove a header | The Remove operation |
| URL filter | Include filter: Pattern (browser URL syntax) or Regex (RE2) |
| Exclude URL filter | Exclude filter |
| Pause | Pause switch at the top of the popup |
Differences to know
- Header values are fixed text; values computed per request are not possible with the browser's header engine.
- In Firefox, rows that change page security response headers (Content-Security-Policy, X-Frame-Options, Access-Control-* and similar) are kept but not applied, as required by add-on policy.
- Nothing is synced. Use export and import to move profiles between computers.
HeaderVault is an independent project, not affiliated with or endorsed by ModHeader.