How to set request headers in Chrome

Chrome has no built-in way to add a header to the requests a page makes. Here are the four ways developers do it, and which one fits.

Last updated 4 October 2026

You want every request to your staging API to carry an Authorization token, a feature flag to reach localhost, or a mobile User-Agent while you test. DevTools shows the headers a page sends, but it can't add one to them. These are the options, from built in to automated.

1. DevTools, for the two cases it covers

Chrome DevTools can change two things without an extension (Chrome DevTools docs):

  • The User-Agent: open the Network conditions panel and untick “Use browser default”.
  • Response headers: in the Network panel, right-click a request and choose Override headers. It needs a local folder for overrides, and only works while DevTools is open.

There's no way to add or change any other request header there.

2. curl, for one request

To check what an API does with a header, outside the browser, curl -H "Authorization: Bearer TOKEN" https://api.example.com/v1/orders sends it once. It doesn't help when you need the page itself, with its own requests and cookies, to send the header.

3. An extension, for everyday use

An extension can add, change or remove headers on every request to the sites you choose, while you browse normally. Since Manifest V3, extensions do this through Chrome's declarativeNetRequest API: the extension hands Chrome a rule (“on api.staging.example.com, set Authorization”) and Chrome applies it. Chrome only applies it on sites the extension has access to.

That last part is what to check before you install one:

  • Site access. Many header editors ask to “read and change all your data on all websites” at install. One that asks per site when you add a rule can only touch those sites.
  • Who it talks to. A header editor sits next to your auth tokens. Look for no analytics and a privacy section in its store listing that says it collects nothing, or only what a license check needs.
  • Who makes it, and how it's paid for. ModHeader, with about 1.6 million installs, was removed from Chrome and Edge in July 2026 after a hidden browsing-history collector was found in it (The Hacker News).

With Headerlane, step by step

Headerlane is the one we make, built around those three points. Setting a header takes four steps:

  • Open Headerlane's options (they open on install) and choose New rule.
  • Type the site in the pattern, such as api.staging.example.com. A path or a regular expression narrows it further; leave it empty for all sites.
  • Add the header: Authorization = Bearer …. Set sends it with that value; Remove strips it from the request.
  • Click Allow on api.staging.example.com and accept Chrome's prompt for that site. The rule is live.

Reload the page and check the request in DevTools' Network panel, or open an echo endpoint such as https://httpbin.org/headers after allowing that site too. Headerlane's toolbar badge shows how many rules apply on the current tab.

4. Playwright or Puppeteer, for automated tests

In end-to-end tests, set headers in code instead: Playwright's setExtraHTTPHeaders adds them to every request a browser context makes, and Puppeteer has a method of the same name on its page.

Which to use

ExtensionDevTools
Add or change any request headerYes, within Chrome's limitsUser-Agent only
Change response headersDepends on the extension (Headerlane: Pro)Yes, with Override headers
Works with DevTools closedYesNo
Per site, saved between sessionsYesOverrides are saved in a local folder
Install neededYesNo

Chrome itself limits what any extension can change: requests on chrome:// pages and the Chrome Web Store can't be touched, and an extension can't invent a response body (a mock), only change headers or redirect the request.

A header editor you don't have to trust blindly.

A Chrome extension that sets, changes or removes HTTP headers per URL pattern. No analytics, no server, and site access asked one site at a time. Imports ModHeader exports.