Item logo image for HeaderHermit — Header Editor & API Mock

HeaderHermit — Header Editor & API Mock

ExtensionDeveloper Tools
Item media 5 (screenshot) for HeaderHermit — Header Editor & API Mock
Item media 1 (screenshot) for HeaderHermit — Header Editor & API Mock
Item media 2 (screenshot) for HeaderHermit — Header Editor & API Mock
Item media 3 (screenshot) for HeaderHermit — Header Editor & API Mock
Item media 4 (screenshot) for HeaderHermit — Header Editor & API Mock
Item media 5 (screenshot) for HeaderHermit — Header Editor & API Mock
Item media 1 (screenshot) for HeaderHermit — Header Editor & API Mock
Item media 1 (screenshot) for HeaderHermit — Header Editor & API Mock
Item media 2 (screenshot) for HeaderHermit — Header Editor & API Mock
Item media 3 (screenshot) for HeaderHermit — Header Editor & API Mock
Item media 4 (screenshot) for HeaderHermit — Header Editor & API Mock
Item media 5 (screenshot) for HeaderHermit — Header Editor & API Mock

Overview

Switch HTTP request and response headers by profile, and mock JSON APIs. Makes no network requests of its own.

HeaderHermit changes HTTP headers and fakes API responses on the sites you choose — and nothing else. It makes no network requests of its own. SWITCH ENVIRONMENTS IN ONE CLICK • Keep a profile for each environment — Local Dev, Staging, Production — and switch between them from the toolbar. • The toolbar badge shows which profile is on, so a forgotten header never costs you an afternoon. ONE-CLICK PRESETS • Start a profile with a preset: Allow CORS (the CORS response headers), Bearer token (an Authorization: Bearer header), Disable cache, Custom User-Agent, or Mock a JSON API — then edit it like any rule. EDIT REQUEST AND RESPONSE HEADERS • Set, append or remove any request or response header: Authorization, Cookie, CORS, Content-Security-Policy, feature flags and more — with suggestions for common header names and values. • Every mistake is shown right at the field that has it; an empty, unfinished row is simply ignored. • Scope each profile by URL filter or regex, excluded URLs, resource type, method, request domain or initiator domain. • Rules apply in list order and the top rule wins. Mistakes are flagged next to the rule before they reach the browser. • Header rules run on Chrome's built-in rule engine (declarativeNetRequest), inside the browser. MOCK APIS THAT AREN'T READY YET • Answer a URL with the JSON (or other text) body, status code and delay you choose. • Works for the page's own fetch() and XMLHttpRequest calls. The first matching mock wins, and a profile's excluded URLs are never mocked. • Honest limits: these are not mocked — requests a page makes before its first script runs, synchronous XMLHttpRequest, requests from service workers and web workers, image/script/stylesheet/iframe loads, sendBeacon and WebSockets. Pages that were already open need a reload after you turn mocks on. Mocked calls do not appear in DevTools' Network panel, because they never reach the network. BRING YOUR PROFILES WITH YOU • Export and import all profiles as a JSON file. • Also imports ModHeader profile exports, with a clear report of anything that works differently. HeaderHermit is an independent project and is not affiliated with its makers. PRIVATE BY DESIGN • Runs only on sites you allow. Turning a profile on asks Chrome for the site you are on; "Allow on all sites" is there if you want it. Remove access any time in the settings. • No network requests of its own, no account, no analytics, no remote code. Your profiles stay on this device. • The code in the package is readable, not minified. Made by Forgeline.

Details

  • Version
    1.0.0
  • Updated
    September 30, 2026
  • Offered by
    Forgeline
  • Size
    67.6KiB
  • Languages
    English
  • Developer
    Uzair Ali Murtaza
    House #1, Street #4, Bhatti Colony Link Road Lahore 54700 PK
    Email
    uamurtaza.apps@gmail.com
    Phone
    +92 316 1602776
  • Trader
    This developer has identified itself as a trader per the definition from the European Union and committed to only offer products or services that comply with EU laws.

Privacy

Manage extensions and learn how they're being used in your organization
The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, please open this page on your desktop browser

Google apps