Add an Authorization header to every request in Chrome
Short answer. Add one request rule: set Authorization to Bearer <your token> and scope it to your API's domain. Chrome then sends it on every request to that domain, both from your page's fetch calls and when you open an API URL in the address bar.
Every result on this page was checked on 2026-09-28 by an automated test that loads Headrule in Chromium 141 and makes real requests: test/guides.mjs.
Always set a URL filter. A rule with an empty URL filter applies to every site you visit, which would send your token to all of them. Scope it to the one API that should receive it.
On this page: The rule Basic auth Calling it from another origin What we tested FAQ
The rule
Open Headrule, click + Add rule, and fill in one row:
| Type | Action | Header | Value | URL filter |
|---|---|---|---|---|
| Request | Set | Authorization | Bearer eyJhbGciOi... | ||api.staging.example.com |
The rule applies from the next request. Nothing needs a reload of the extension. Use Set, not Append: Chrome allows Append only on a short list of request headers, and Authorization is not on it. Headrule shows an error under the rule if you try.
To switch between users or environments, edit the value, or keep one profile per environment (more than one profile is a Pro feature). The switch in the popup, or Alt+Shift+H, pauses every rule at once.
Basic auth instead of a token
Basic auth is the same header with a different value: the word Basic and then user:password in Base64. You can produce the value in any DevTools console:
"Basic " + btoa("user:password")
Paste the result into the Value field.
Calling the API from another origin
If your page runs on localhost and the API is elsewhere, two things are worth knowing.
- The header does not trigger a preflight. Chrome decides whether to send a preflight from the headers your page's code sets. In our test the API received the extension's token and saw no
OPTIONSrequest. - The response still needs CORS headers. If the API does not send
Access-Control-Allow-Origin, your code cannot read the answer. See the CORS guide for the extra rule.
What we tested
| Situation | Result |
|---|---|
| fetch from another origin, with an Allow-Origin rule | Token received |
| Preflight caused by the extension's header | None sent |
| API URL opened in the address bar | Token received |
Questions
Where is the token stored?
In the extension's local storage in your browser. Headrule has no account and no server, so it is not sent anywhere except in the header you configured. If you turn on sync (Pro), your rules are copied through your own Chrome account.
Will my app's own Authorization header be overwritten?
Yes. Set replaces whatever the page sent for that header. Pause the rule if you want to test your app's own login flow.
Do I need Pro for this?
No. Unlimited rules and domain filters are free.
Related guides
Try it on your own API
Free to install. Every rule on this page works in the free version.