Headrule
Guide · Updated September 2026

Add an Authorization header to every request in Chrome

Short answer. Add one request rule: set Authorization to Bearer <your token> and scope it to your API's domain. Chrome then sends it on every request to that domain, both from your page's fetch calls and when you open an API URL in the address bar.

Every result on this page was checked on 2026-09-28 by an automated test that loads Headrule in Chromium 141 and makes real requests: test/guides.mjs.

Always set a URL filter. A rule with an empty URL filter applies to every site you visit, which would send your token to all of them. Scope it to the one API that should receive it.

On this page: The rule Basic auth Calling it from another origin What we tested FAQ

The rule

Open Headrule, click + Add rule, and fill in one row:

TypeActionHeaderValueURL filter
RequestSetAuthorizationBearer eyJhbGciOi...||api.staging.example.com

The rule applies from the next request. Nothing needs a reload of the extension. Use Set, not Append: Chrome allows Append only on a short list of request headers, and Authorization is not on it. Headrule shows an error under the rule if you try.

To switch between users or environments, edit the value, or keep one profile per environment (more than one profile is a Pro feature). The switch in the popup, or Alt+Shift+H, pauses every rule at once.

Basic auth instead of a token

Basic auth is the same header with a different value: the word Basic and then user:password in Base64. You can produce the value in any DevTools console:

"Basic " + btoa("user:password")

Paste the result into the Value field.

Calling the API from another origin

If your page runs on localhost and the API is elsewhere, two things are worth knowing.

What we tested

SituationResult
fetch from another origin, with an Allow-Origin ruleToken received
Preflight caused by the extension's headerNone sent
API URL opened in the address barToken received

Questions

Where is the token stored?

In the extension's local storage in your browser. Headrule has no account and no server, so it is not sent anywhere except in the header you configured. If you turn on sync (Pro), your rules are copied through your own Chrome account.

Will my app's own Authorization header be overwritten?

Yes. Set replaces whatever the page sent for that header. Pause the rule if you want to test your app's own login flow.

Do I need Pro for this?

No. Unlimited rules and domain filters are free.

Related guides

Try it on your own API

Free to install. Every rule on this page works in the free version.