Your existing Web DevToolkit
inside a browser extension

Modify live HTTP Requests. Team Collaboration. Work Offline.

View on GitHub
No account · Zero telemetry · Free. No catches. · Free to self-host

What it does — use cases, paradigm, and FAQ

Open Headers chrome-extension://ablaikadpbfblkmhpmbbnbbfjoibeejb/workbench.html
Workspace No environment
DeveloperQA

Test on production. Skip the deploy.

Reshape what your live site sends and receives, straight from the browser. No staging queue, no release train, no rounds of deployment approvals — point a rule at production and see the result on the very next request.

  • Changes exist only in your browser — real users and prod itself stay untouched
  • One toggle off and the page is back to reality
yourapp.com production visible only to you
Inject auth headers headers
GET api.yourapp.com/v2/account
+Authorization: Bearer {{vault.prod_token}}
+X-Feature-Flag: checkout-v2
Injected before the request leaves the tab — secrets stay in the vaultlive
Workspace System status ◑ Auto v2026.5.0
why openheaders

One install.
Three categories replaced.

The request-shaping power of a desktop proxy, the rule library of a cloud API platform, and the always-on surface of a header extension — sharing a single store, back-end included. No one else on the market ships this in an extension.

OpenHeaders Free Cloud API platforms Desktop proxies Header-only extensions
Architecture & Reach
Runs entirely in your browser back-end included Their cloud + app Separate binary No real back-end
No proxy port or CA certificate CA cert required
Works fully offline Internet required
Privacy & Ownership
No account or sign-in Login wall License key
Your data stays on your machine Their servers
Zero telemetry Collected Varies Varies
Open source Open core — UI, shell & core MIT Varies
Capability
Header rewriting Nine rule types Limited One rule type
Mock, body edits, inject, delay Paid tiers
API client — OAuth 2.0, GraphQL, scripts
Workflows — chained, scheduled requests Runs locally Paid cloud runners
Socket protocols in the client — gRPC, MQTT SoonVia desktop app Their desktop app
AI agent integration SoonLocal MCP server Their cloud AI
Sync & Resilience
Conflict-free concurrent edits Field-level merge Last-write-wins No sync No sync
Team sync without a vendor server SoonVia infra you control Cloud only
what's next

Local-only today.
Everywhere you work, next.

Everything below is the same engine — the Oracle — in new packaging. The local-first shape never breaks: sync ships through infrastructure you control, never a vendor cloud.

Roadmap

Team workspaces

Live collaboration runs on the sync engine itself — Git joins as a durable back-end, so new devices bootstrap from the repo state instead of syncing from zero. Enterprise-ready tiers on your LAN or self-hosted: SSO, RBAC user management, audit logs.

Roadmap

Desktop app

A native binary running the same workspace store — picking up where the browser stops: socket-level protocols like gRPC and MQTT, system-level traffic shaping, deeper filesystem reach.

Roadmap

Local / LAN daemon

One daemon on your machine or LAN; extension, desktop, and CLI become clients of the same workspaces across every device you use.

Roadmap

CLI

Headless scripting and CI — list rules, toggle environments, send a saved request from the shell.

Roadmap

Self-hosted web app

The same UI as a web bundle on your own origin — for locked-down browsers or branded deployments under your domain.

Roadmap

More importers

Insomnia collections, OpenAPI specs, and full HAR request imports — bring your work across in one step.

pricing

Free to use & self-host. No catches.

Open core — UI, shell & core MIT
$ 0

everything included

  • All nine rule types, unlimited rules
  • Full API client — OAuth 2.0, GraphQL, scripts
  • Workflows — chained & scheduled requests
  • DevTools panel + all four surfaces
  • Unlimited workspaces & environments
  • Encrypted vault for secrets and tokens
  • Personal and commercial use
  • Self-hosting included — on every roadmap tier too
  • No account, no telemetry, no data collection
enterprise / custom

Need something more?

Enterprise team tiers — SSO, RBAC user management, audit logs — are on the roadmap, shaped by real developer feedback. Custom features, priority support, or a private deployment: reach out.

Start a discussion
get started

Install OpenHeaders

One extension, no account, no setup. Installed and working in under a minute.

your browser

Browser Extension

The whole toolbox — rule engine, API client, and live request tracking — inside the browser you already use.

Install the Extension Detecting browser…
all browsers

Pick your store

Published on every major extension store.