Domains

Domains control where your rules run. There are two separate things happening behind the Domains tab, and it helps to keep them apart:

  1. Scoping — which sites a profile's header, redirect, and mock rules apply to. Leave the list empty and rules apply everywhere.
  2. Permission — whether DevHeader is actually allowed to read and modify your browser traffic at all.

The one-time permission

The first time you turn on a rule, DevHeader shows a single "Allow access" banner. Click it once and approve the native Chrome prompt — that's it. DevHeader never asks again per domain, and it never asks again after that first grant, even if you add more domains later or switch profiles.

If you dismiss or deny the prompt, the banner just stays there so you can retry any time. Nothing else in the extension is blocked while you decide.

Scoping rules to specific sites

Add a domain from the Domains tab to restrict every rule in the current profile to that site (and any others you add). A few things worth knowing:

  • Empty list = everywhere. If you haven't added any domains, rules apply to all sites you've granted access to.
  • Toggling, reordering, and deleting apply instantly — there's no Save step for these.
  • Editing a domain's text is a draft until you click Save Changes, so you can fix a typo without it taking effect mid-edit.
  • Domains are per-profile. A "Staging" profile and a "Production" profile can be scoped to completely different sites — see Managing Profiles.

Why one grant instead of per-domain grants

Earlier versions of DevHeader asked for permission separately for each domain you added, which meant repeating the browser prompt over and over. Now it's a single, one-time grant that covers everything — it doesn't give DevHeader any more access than before, it just removes the repeated prompts.