Migrating from ModHeader

A ModHeader alternative that keeps your headers local. There are two ways to bring your header profiles to HeaderVault: import a JSON export you already saved, or recreate the rules by hand.

Before you start

  1. Install HeaderVault from your browser's add-on store.
  2. Click the HeaderVault icon. When you enable your first header, the browser asks for access to all sites — allow it, otherwise rules have no effect.

Which path fits you: if you have a .json file exported from ModHeader earlier (for example, a backup or a file shared by your team), use path 1. If you have no export, use path 2.

Path 1: import a saved export

  1. Click the HeaderVault icon and choose Import / Export. The editor opens in a tab.
  2. Under Import, choose your .json file.
  3. Review the summary: the number of profiles and header rows, every URL filter with its type, and every setting that was skipped or marked, with the reason.
  4. Click Import. The profiles are added next to your existing ones; a name that already exists gets “(2)”.
  5. Imported profiles are not activated automatically. Check them, then click a profile tab to make it active.

What is imported

In your exportIn HeaderVault
Request and response headersHeader rows with their on/off state
Header with an empty valueA Remove row (or a Set row marked “Value required” if the export asked to send empty headers)
Append modeAppend rows where the browser allows it, joined with a separator
URL filters and exclude filtersInclude and exclude filters. Values starting with | or || become Patterns, others Regex. Regex the browser cannot run is imported disabled, with an error
Old-format URL filtersRegex anchored to the start of the URL, as older versions matched
Resource type filtersResource types of the profile
Request cookiesAppend rows for the Cookie header

What is not imported

Comments, profile colors, “always on”, URL redirects, the CSP editor, Set-Cookie modifiers, regex cookies, request method filters, tab, window and time filters, and values defined as functions. Each one appears in the import summary with a reason, so you can see what to recreate by hand.

Path 2: recreate your rules by hand

Most setups are a handful of headers and one or two URL filters, so this takes a few minutes. Write down the headers you used (names and values come from your own services, documentation or team notes), then:

  1. Click the HeaderVault icon. Rename Profile 1 to something like “Staging”.
  2. Under Request headers, click Add header, pick an operation and enter the name and value:
    • Set sends the header with your value, replacing the original;
    • Remove drops the header;
    • Append adds your value to the existing one (for request headers, only where the browser allows it, such as Cookie or Accept).
  3. Add response headers the same way under Response headers.
  4. Open URL filters and resource types to limit the profile to your sites, for example the Pattern ||api.example.com^. Without include filters, the profile applies to all URLs.
  5. Create more profiles with + and switch between them with one click.
  6. When you are done, export your profiles to a JSON file as a backup.

Concepts side by side

You usedIn HeaderVault
ProfileProfile tab; one profile is active at a time
Header row with a checkboxHeader row with a switch and an explicit Set, Remove or Append
Empty value to remove a headerThe Remove operation
URL filterInclude filter: Pattern (browser URL syntax) or Regex (RE2)
Exclude URL filterExclude filter
PausePause switch at the top of the popup

Differences to know

  • Header values are fixed text; values computed per request are not possible with the browser's header engine.
  • In Firefox, rows that change page security response headers (Content-Security-Policy, X-Frame-Options, Access-Control-* and similar) are kept but not applied, as required by add-on policy.
  • Nothing is synced. Use export and import to move profiles between computers.

HeaderVault is an independent project, not affiliated with or endorsed by ModHeader.