Item logo image for Header Forge

Header Forge

ExtensionDeveloper Tools
Item media 1 (screenshot) for Header Forge

Overview

Locally manage HTTP request and response header rules.

Need to change HTTP headers while testing a website or API? Header Forge lets you set, append or remove request and response headers locally in Chrome. What it does - Set, append or remove request and response headers. - Restrict rules with Chrome URL filters. - Keep separate profiles for different sites or tasks. - Pause individual rules or all changes at once. - Export and restore profiles as JSON. How to use it 1. Install Header Forge and open the extension popup. 2. Choose an existing profile or select "New". 3. Enter a URL filter: - `*` — all HTTP and HTTPS requests - `||example.com/` — `example.com` and its subdomains - `|https://example.com/` — URLs beginning with this exact prefix 4. Add a request or response header. 5. Choose "Set", "Append" or "Remove", then enter the header name and value. 6. Select "Apply changes", then reload the target page. Only the selected profile is active. Use the main switch to pause all rules. Import and export - Select "Export redacted" to download `header-forge-redacted.json` with sensitive header values removed. - Select "Backup" to download `header-forge-backup.json` with every header value. The file may contain credentials, so store it carefully. - Select "Import" to replace the current settings with a valid Header Forge JSON file. Export your settings before importing if you may need to restore them. Privacy Header Forge handles profile names, URL filters, header names and header values entered by the user. Header values can contain authentication information and should be treated as sensitive. Settings remain in Chrome's local extension storage until they are changed, reset or the extension is uninstalled. Chrome applies enabled rules through its Declarative Net Request API. Configured request header values are sent only to sites matching the user's URL filters; Header Forge does not read request or response bodies. Access to all URLs is required so enabled rules can work on any site. Settings are not sent to the developer or an analytics service. Backups are created only when requested; full backups can contain credentials, while redacted exports remove recognised sensitive values. The extension has no accounts, analytics, advertising, remote scripts or external API calls. Information received through Chrome APIs is used only for Header Forge's stated purpose and in accordance with the Chrome Web Store User Data Policy, including the Limited Use requirements. The privacy policy was last updated on 26 July 2026. [Contact the developer](https://nicholasgriffin.dev/contact) with privacy questions. Limitations - Chrome protects or specially handles some headers, so not every change is permitted. - Service workers, `CacheStorage` and cached responses can hide changes. Disable the cache in Chrome DevTools when testing if necessary. - Chrome only permits "Append" for a defined set of request headers. Header Forge flags unsupported request headers in the popup. - Chrome 120 or later is required.

Details

  • Version
    1.1.0
  • Updated
    July 29, 2026
  • Size
    21.74KiB
  • Languages
    English (United Kingdom)
  • Developer
    Website
    Email
    support@nicholasgriffin.co.uk
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization
The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes
Google apps