HeaderLock help.
Most answers are below. If yours isn’t, email us; a person reads every message.
Email [email protected]Getting started
How do I open HeaderLock?
Click the HeaderLock icon in the toolbar (pin it from the puzzle-piece menu first), or press Alt+Shift+H. Import, export, variables and your licence live in its settings: the sliders icon at the top of the popup.
How do I add a header?
Press N (or click Request header), type the name and value, and choose Set, Append or Remove. Shift+N adds a response header on Pro. Add a URL filter with F so it only applies where you want.
How do URL filters work?
* matches any text, || means the domain and its subdomains, and | anchors the start or end. So ||api.example.com covers that host and its subdomains, and localhost:3000 covers your dev server. "Only on" filters narrow where a profile runs; "Not on" filters exclude. A profile with no filters applies to every URL.
Why does it ask for access to a site?
Chrome only applies header rules on sites an extension may access. The popup asks for exactly the hosts in your profile's URL filters, when you need them. Nothing is granted at install.
Keyboard shortcuts
N new request header · Shift+N new response header · F new filter · P pause · [ ] switch profile · Enter next field · Cmd/Ctrl+Backspace delete row · Alt+Shift+H open · Alt+Shift+P pause from anywhere.
When a header doesn’t apply
My header isn’t being sent
Check that the profile and the header are switched on, that the extension isn’t paused (P), and that the request URL matches the profile’s filters. Then check the popup for an Allow access button: Chrome won’t apply rules on a site until HeaderLock may access it. The popup flags any header or filter it can’t run, with the reason.
It works on the site but not for requests it sends to an API
Chrome needs access to both the host the request goes to and the page that sent it. When that is missing, the popup shows "Requests sent from this page keep their headers until you allow it", with an Allow button.
"Chrome only allows Append on a few request headers"
Chrome’s declarativeNetRequest can only append to a short list of request headers, such as Accept, Cookie and User-Agent. Use Set for anything else.
"Chrome can’t use this regex"
Chrome uses the RE2 engine, which has no lookarounds or backreferences. Rewrite the pattern without them, or use a wildcard filter.
A profile says "Not running"
HeaderLock never widens where headers go. If an exclude filter can’t be used, or none of a profile’s URL filters can, the profile stays off rather than matching pages you didn’t mean. Fix or remove the flagged filter and it runs.
Browser pages
Chrome doesn’t let any extension change requests on its own pages (chrome://, the Chrome Web Store).
ModHeader import
How do I import my ModHeader profiles?
Export your profiles from ModHeader as JSON. In HeaderLock’s settings, paste the JSON or drop the file under Import. Old v1 files work too. Tick "Replace my profiles" to replace instead of add.
I can’t export from ModHeader any more
Chrome switched ModHeader off in July 2026, so it can’t open to export. The modheader-export-backup tool (linked from HeaderLock’s Import section) can read your profiles from disk into an export file.
Why was one of my profiles imported switched off?
It used a filter HeaderLock can’t apply safely, such as a time, tab or window filter. Dropping it would make the profile run on pages you didn’t mean, so it is imported off. Check its URL filters, then switch it on.
What isn’t carried over?
URL redirects and cookie rules: HeaderLock changes headers only. The import report lists everything that was skipped.
Free and Pro
What does Free include?
1 profile with 5 active request headers, wildcard URL filters, tab-only rules, and ModHeader import and export. Pro adds unlimited profiles and headers, response headers, regex filters and {{variables}}.
What happens to headers over the limit?
They are saved and shown as locked, never deleted. They run as soon as Pro is on.
How do I activate Pro?
Open settings (the sliders icon in the popup), go to Licence, paste the licence key from your Freemius receipt and press Activate. You can also paste it into the upgrade sheet under "Have a licence key?".
Cancel, find my key, or move to another browser
See the Manage plan page. It covers the Freemius customer portal, cancelling, and moving a key between browsers.
Billing and licences: Manage plan. Data handling: Privacy policy.