Modify HTTP headers. Locally.

HeaderVault adds, changes and removes HTTP request and response headers in Chrome, Firefox and Opera. No network requests, no analytics, no account — your tokens stay in your browser.

Private by design

No network requests

The extension never contacts any server. Nothing is uploaded, synced or reported.

No analytics

No telemetry, no usage counts, no tracking of any kind.

Minimal permissions

Two permissions: header rules and local storage. Site access is optional and asked for only when you enable your first header.

Readable code

The store packages contain plain, unminified JavaScript — what reviewers read is what runs.

Features

Request and response headers

Set, Remove or Append any header; turn each row on or off with one click.

Profiles

Separate header sets for staging, production and local development. Switch with one click, pause everything with one switch.

URL filters

Limit a profile to URL patterns like ||api.example.com^ or RE2 regular expressions, exclude URLs, choose resource types.

Import and export

Move profiles between computers as JSON. Imports profiles exported from ModHeader.

Looking for a ModHeader alternative?

HeaderVault covers the everyday header work: auth tokens, feature flags, debug headers and response overrides, grouped in profiles and scoped by URL. If you have a JSON export of your ModHeader profiles, you can import it. Read the migration guide.

HeaderVault is an independent project, not affiliated with or endorsed by ModHeader.

FAQ

Why does HeaderVault ask for access to all sites?

The browser only applies header rules on sites the extension can access, and the sites you test can be any domain, including localhost. Access is optional: it is requested when you enable your first header, and you can limit it to selected sites in the browser's extension settings.

Does HeaderVault send my headers or tokens anywhere?

No. Profiles are stored in the browser's local extension storage and never leave it, except in a JSON export file that you create yourself.

Can a header value change per request, like a timestamp?

No. HeaderVault uses the browser's declarativeNetRequest engine, where header values are fixed text. Values cannot run scripts.

What happens with several rows for the same header?

The lowest Set or Remove row wins; Append rows are combined with it into one value. Rows that have no effect are marked in the editor.

Why are some response headers not applied in Firefox?

Firefox add-on policy does not allow relaxing page security headers. In the Firefox version, rows for headers such as Content-Security-Policy, X-Frame-Options or Access-Control-* are kept but not applied.

How do I move my settings to another computer?

Open HeaderVault in a tab, export your profiles to a JSON file, and import that file on the other computer. There is no cloud sync by design.

Is it free?

Yes. Every feature described here is free.