HeaderlaneChrome extension
Coming soon

A header editor you don't have to trust blindly.

A Chrome extension that sets, changes or removes HTTP headers per URL pattern. No analytics, no server, and site access asked one site at a time. Imports ModHeader exports.

See Pro
Request header rules: an Authorization token and a feature flag for api.staging.acme.test, a tenant header and a removed Cookie for localhost:3000
Set or remove request headers per host, path or regular expression.
The toolbar popup over an API response: the staging rule is active on this tab, and the response shows the authorization and x-feature-flag headers arriving
The popup shows what applies on this tab. The headers arrive.
Import & export: a ModHeader export previewed as 2 profiles, 3 rules and 6 headers before anything is added
Drop in a ModHeader export and check the preview first.
Pro profiles in dark mode: Staging, Prod debug and Local, with Prod debug's trace headers
Pro: profiles for staging, prod debug and local.
Pro response header rules: CORS headers for localhost:5173, and Cache-Control set and Content-Security-Policy removed for the staging API
Pro: change what the server sends back.

What it does

Request header rules

Set or remove any header Chrome allows on requests to a host, a path, or a regular expression. Add an Authorization token for staging, a feature flag for localhost, or a mobile User-Agent. No limit on rules beyond Chrome's own.

A switch for everything

Every rule and every header has its own switch, and Pause all turns everything off at once.

See what applies here

The toolbar badge counts the rules active on the tab you're on, and the popup lists them so you can switch one off.

ModHeader import

Drop a ModHeader export file in and check the preview: profiles, rules and headers come across, and anything Headerlane can't do yet is named, not dropped silently.

Export and import

All your rules as one JSON file, to copy to another browser or a teammate. There's no sync server; the file is the sync.

Profiles Pro

Keep staging, prod debug and local setups apart and switch in one click, from the popup, or with Alt+Shift+P.

Response headers Pro

Change what the server sends back, such as CORS headers for a local frontend, or remove Content-Security-Policy while testing.

Redirects Pro

Send a request somewhere else before it leaves the browser, such as production JavaScript to localhost. Regular expressions with capture groups work.

Coming soon

Free for the core job. Pay once for more.

The core job

Free

No account, no time limit, no card.

  • Request header rules
  • A switch for everything
  • See what applies here
  • ModHeader import
  • Export and import

Pro, pay once

₹299₹799

One payment. No subscription, no account. One license activates on up to 3 browsers. Every Pro feature is on for the first 3 days after install, with no card or email.

  • Everything in Free
  • Profiles
  • Response headers
  • Redirects

Checkout opens when Headerlane launches.

Checkout by Lemon Squeezy. Lost your key? Email us.

Privacy and permissions

Sends nothing about you

Headerlane has no server and no analytics, and it can't read your traffic: Chrome applies the rules. The only request it makes is the Pro license check: when you activate a key, when you press Check now, and at most once a week after, it sends the key to Lemon Squeezy (who sells it) to confirm it's still valid. Free use sends nothing at all. Its Buy buttons open aisssoftware.com/go/headerlane/buy, which counts the click (where in Headerlane, and whether the trial was on; no cookie, no ID) and forwards you to checkout. If Headerlane is removed, Chrome opens a short "what went wrong?" page on this site.

Rules, profiles and the license state are kept in Chrome's storage for the extension, on that computer. Export them as JSON any time. Removing the extension removes them.

What it asks Chrome for, and why

  • Site access, one site at a time. Chrome only changes headers on sites an extension can access. Headerlane asks for each rule's site when you add the rule. Nothing is granted for all sites at install.
  • Declarative net request. Hands your rules to Chrome, which applies them. Headerlane never reads your requests, responses or pages.
  • Active tab. When you click the toolbar icon, reads the tab's address to show which rules match it. Nothing is read from the page.
  • Storage. Keeps your rules, profiles, the trial start date and the license state in the browser.
  • Alarms. Pauses Pro rules the moment the 3-day trial ends, even with no Headerlane page open.
  • api.lemonsqueezy.com. Asked only when you activate a Pro key, to check it. Free use never contacts it.

What it can’t do

  • Chrome 121 or later, on a computer.
  • Chrome caps an extension at 1,000 pattern (regular expression) rules, so that's the most Headerlane can apply at once.
  • It can't return a made-up response body (a mock). Chrome's extension API doesn't allow it.
  • Chrome doesn't let extensions change requests on chrome:// pages or the Chrome Web Store.
  • From a ModHeader export, exclude-URL filters, cookie headers, and tab, time and resource-type filters aren't imported yet. The preview names any it skipped.

Questions

Something else? Support has the email, lost keys and refunds.

General

Privacy

Buying