The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Use Puppeteer, Playwright, or the Chrome DevTools Protocol (CDP) to add custom HTTP headers. A plain google-chrome --headless command selects an unattended browser mode, but Chrome’s documented command-line options do not provide a general switch for arbitrary request headers. Set the headers before navigation when they must reach the first document request.
What “custom headers” means in headless Chrome
An HTTP header is metadata sent with a request. Authentication tokens, tenant identifiers, API keys, locale preferences, and tracing IDs are common examples. In a headless browser, the important distinction is between:
- Page-request headers: headers added to requests made by a page, including the document and normally its subresources.
- Browser-control headers: headers used only while connecting your automation client to a remote CDP endpoint.
These scopes are not interchangeable. A header on the CDP connection does not automatically become a header on the website request.
Use Puppeteer for page-wide headers
Puppeteer’s page.setExtraHTTPHeaders() API adds headers to every request initiated by that page. Set it before page.goto() so the initial document request receives the values.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Intel Celeron N4120: 4 Cores & Threads, 1.1GHz Base Clock, Up to 2.6GHz Boost Clock, 4MB Cache, Intel UHD Graphics 600. The perfect combination of performance, power consumption, and value helps your device handle multitasking smoothly and reliably with four processing cores to divide up the work.
- 14" HD Display: 14.0-inch diagonal, HD (1366 x 768), micro-edge, anti-glare. See your digital world in a whole new way. Enjoy movies and photos with the great image quality and high-definition detail of 1 million pixels.
- Memory & Storage: 4 GB LPDDR4x & 64 GB eMMC Storage. Adequate high-bandwidth RAM to smoothly run multiple applications and browser tabs all at once. An embedded multimedia card provides reliable flash-based storage.
- Ports:2 x USB 3.0 Type-A,1 x USB 3.0 Type-C,1 x HDMI,1 x Headphone Jack
- Chrome OS: Chromebook is a computer for the way the modern world works, with thousands of apps. Enjoy the seamless simplicity that comes with Google Chrome and Android apps, all integrated into one laptop. It’s fast, simple, and secure.
import puppeteer from 'puppeteer';
const token = process.env.API_TOKEN;
if (!token) throw new Error('API_TOKEN is required');
const browser = await puppeteer.launch({ headless: true });
try {
const page = await browser.newPage();
await page.setExtraHTTPHeaders({
authorization: `Bearer ${token}`,
'x-tenant-id': 'acme'
});
const response = await page.goto('https://example.com', {
waitUntil: 'networkidle2',
timeout: 90_000
});
console.log('status:', response?.status());
console.log('title:', await page.title());
} finally {
await browser.close();
}
Puppeteer documents that extra headers are sent with every request the page initiates. It also lowercases header names and does not guarantee their order. Header values must be strings, so convert numeric IDs or other values explicitly.
When Puppeteer headers do not work as expected
- Call
setExtraHTTPHeadersbefore navigation; setting it aftergotocannot change a request already sent. - Inspect the server’s logs or use request interception to verify what left the browser. A header shown in JavaScript is not proof that it was sent over the network.
- Redirects can change the destination origin. The browser may apply extra headers according to the automation framework, but the destination server can reject, strip, or ignore credentials. Do not assume a bearer token is safe to forward across origins.
- Subresources such as scripts, images, and XHR requests can have different server-side authentication and CORS requirements. Test the exact resource types your page needs.
Use Playwright for context-wide headers
Playwright takes the same idea to the browser-context level. Every page created in that context inherits extraHTTPHeaders, which is useful when several pages share authentication or tenant metadata.
import { chromium } from 'playwright';
const token = process.env.API_TOKEN;
if (!token) throw new Error('API_TOKEN is required');
const browser = await chromium.launch({ headless: true });
try {
const context = await browser.newContext({
extraHTTPHeaders: {
authorization: `Bearer ${token}`,
'x-tenant-id': 'acme'
}
});
const page = await context.newPage();
const response = await page.goto('https://example.com', {
waitUntil: 'networkidle',
timeout: 90_000
});
console.log('status:', response?.status());
console.log('title:', await page.title());
await context.close();
} finally {
await browser.close();
}
Playwright’s extraHTTPHeaders option is an object of additional headers sent with every request. Because the setting belongs to the context, create a separate context when different pages need different credentials.
Choosing a Chrome executable
Playwright can launch branded Chrome channels such as chrome, chrome-beta, and chrome-canary. An arbitrary executable path is supported at your own risk: the installed browser may not match the Playwright version or its expected protocol behavior. Pin and test the browser and Playwright versions together in CI.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Use CDP when you need low-level control
Chrome DevTools Protocol exposes a direct command for page traffic:
await client.send('Network.enable');
await client.send('Network.setExtraHTTPHeaders', {
headers: {
authorization: `Bearer ${process.env.API_TOKEN}`,
'x-tenant-id': 'acme'
}
});
The exact connection and session setup depends on your CDP client. You must attach to the correct page or browser context, enable the Network domain, and issue the command before navigation. CDP offers fine-grained control, but you must manage sessions, lifecycle, and protocol errors yourself.
Rank #2
- Storage: 16GB Flash Memory
- OS: Chrome OS
- Screen Size: 11.6"
CDP connection headers are different
When Playwright attaches to an existing browser with connectOverCDP(endpointURL, options), the headers option authenticates or identifies the CDP connection. Those values are not website HTTP headers. To affect page requests, configure extraHTTPHeaders on a context or send CDP’s Network.setExtraHTTPHeaders command in the page session.
What native Chrome Headless does—and does not do
Chrome Headless runs without a visible user interface on Linux, macOS, and Windows. Chrome’s documentation describes it as running “without chrome.” The --headless flag chooses that runtime mode; it is not documented as a general arbitrary-header mechanism.
Free tools Windows power users keep installed
One-click scans. No signup required.
Since Chrome 132.0.6793.0, the old headless implementation is distributed separately as chrome-headless-shell; current Headless is unified with the regular Chrome implementation. This version distinction matters if a deployment still relies on older shell-specific behavior.
If you start Chrome yourself, use a supported automation library or CDP after launch rather than searching for an undocumented command-line header flag.
Header scope, timing, and security checklist
Set headers at the right scope
- One page with unique credentials: Puppeteer’s
page.setExtraHTTPHeaders. - Several related pages: Playwright context
extraHTTPHeaders. - Existing browser or custom protocol integration: CDP Network domain.
- Remote browser authentication: CDP connection headers, separately from page headers.
Set them before the first request
Create the page or context, configure headers, then navigate. If a site redirects immediately, verify the final origin and whether credentials are accepted there. A later API call made by page JavaScript may also need its own application-level authentication logic.
Protect secrets
- Read tokens from environment variables or a secret manager, not source control.
- Do not print authorization values in request logs, screenshots, CI artifacts, or error reports.
- Use the narrowest token scope and rotate credentials when a build worker is decommissioned.
- Confirm the receiving server’s CORS, authentication, and CSRF policy. A browser automation header does not override those policies.
Common failures and fixes
The first page request lacks the header
Cause: the header was configured after goto or after a navigation began.
Rank #3
- Intel Processor Up to 2.80GHz, 4GB DDR4, 128GB Storage
- 15" FHD IPS Display, Intel UHD Graphics
- 1x USB Type C, 1 x USB Type A, 1x Headphone/Microphone Combo Jack, HDMI
- Fast WiFi and Bluetooth, Integrated Webcam
- Chrome OS, AC Charger Included, Pastel Silver
Fix: configure the page or context immediately after creation and before any navigation, popup, or resource-triggering script.
The server says “unauthorized” even though the code contains a token
Cause: the environment variable is empty, the token format is wrong, the server expects a different header name, or a redirect reaches another origin.
Fix: fail fast when the variable is missing, send the exact scheme such as Bearer, inspect response status and redirect targets, and verify server-side logs without exposing the secret.
A header appears in CDP logs but not on the website request
Cause: it was supplied as a CDP connection header rather than a page-network header.
Recommended Free Tools
Fix: use Playwright context headers, Puppeteer page headers, or CDP’s Network.setExtraHTTPHeaders command.
Only some resources load
Cause: subresources may use other origins, CORS rules, signed URLs, or authentication schemes that differ from the document.
Rank #4
- THE BETTER WAY TO LAPTOP – Imagine a Chromebook that’s as flexible as your day: thin and lightweight with built-in Google apps and stress-free security.
- TAKE HITS KEEP MOVING – Sleek, light, and built to last- the Chromebook 2-in-1 is just 0.69” thick and 3.3lbs. Enjoy long-lasting battery life, fast charging, and military-grade durability for nonstop productivity wherever life takes you.
- PERFORMANCE THAT MATCHES YOUR HUSTLE – Fuel your ideas with an Intel Core processor and 128GB storage. Boot up in under 10 seconds to start the day powerfully efficient.
- FLEX YOUR CREATIVITY ANYWHERE, ANYTIME – Create, work, or unwind your way with a versatile 2-in-1 design. Flip easily between laptop, tent, and tablet modes with a responsive touchscreen built for flexibility.
- BRILLIANT VIEWS AND IMMERSIVE AUDIO – See, hear, and create with awesome clarity. The WUXGA display brings rich detail to your work and play, while audio tuned by Waves MaxxAudio provides immersive, balanced sound.
Fix: capture request and response events, identify the failing origin and resource type, and configure the application or server for that request rather than blindly forwarding credentials everywhere.
Header casing or order causes a test failure
Cause: HTTP header names are case-insensitive, but Puppeteer lowercases names and does not promise ordering.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Fix: make tests case-insensitive and validate header presence and value, not capitalization or order.
The browser crashes or behaves differently in CI
Cause: mismatched Chrome and automation-library versions, an unsupported executable path, sandbox restrictions, or an old headless implementation.
Fix: record the installed versions, use the browser bundled or explicitly supported by your framework, and reproduce the same launch flags and user permissions in CI and locally.
Performance and reliability considerations
Adding a few headers has negligible cost compared with launching Chrome and loading a page. The expensive parts are browser startup, DNS, TLS, JavaScript execution, and network idle waits. Reuse a browser process when safe, but isolate credentials in separate pages or contexts.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesBest Value
- FOR HOME, WORK, & SCHOOL – With an Intel processor, 14-inch display, custom-tuned stereo speakers, and long battery life, this Chromebook laptop lets you knock out any assignment or binge-watch your favorite shows..Voltage:5.0 volts
- HD DISPLAY, PORTABLE DESIGN – See every bit of detail on this micro-edge, anti-glare, 14-inch HD (1366 x 768) display (1); easily take this thin and lightweight laptop PC from room to room, on trips, or in a backpack.
- ALL-DAY PERFORMANCE – Reliably tackle all your assignments at once with the quad-core, Intel Celeron N4120—the perfect processor for performance, power consumption, and value (2).
- 4K READY – Smoothly stream 4K content and play your favorite next-gen games with Intel UHD Graphics 600 (3) (4).
- MEMORY AND STORAGE – Enjoy a boost to your system’s performance with 4 GB of RAM while saving more of your favorite memories with 64 GB of reliable flash-based eMMC storage (5).
- Use a realistic timeout and report whether failure occurred during launch, navigation, or a subresource request.
- Prefer
domcontentloadedwhen you only need the document; usenetworkidleornetworkidle2only when background activity has settled sufficiently for your task. - Retry transient network failures with a bounded backoff, never an authentication failure caused by an invalid token.
- Record status, final URL, and a redacted request summary so failures can be diagnosed without leaking credentials.
- Test redirects, popups, downloads, service workers, and API calls separately if your workflow depends on them.
Or skip the browser setup
If your goal is a clean screenshot or PDF rather than browser automation itself, ScreenshotNeo accepts custom headers through one API request and handles the headless browser for you. The API supports authorization and other request headers, plus options such as cookies, user agents, custom JavaScript and CSS, waits, device presets, full-page capture, PDFs, element screenshots, blocking rules, caching, asynchronous jobs, and bulk capture.
For a direct image request, see the ScreenshotNeo documentation and use:
curl -G "https://api.screenshotneo.com/v1/shot"
-d access_key=YOUR_API_KEY
--data-urlencode url=https://stripe.com
-o shot.webp
Python:
import requests
r = requests.get(
"https://api.screenshotneo.com/v1/shot",
params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
timeout=90,
)
r.raise_for_status()
open("shot.webp", "wb").write(r.content)
Node.js:
const q = new URLSearchParams({
access_key: 'YOUR_API_KEY',
url: 'https://stripe.com'
});
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot failed: ${res.status}`);
ScreenshotNeo removes cookie-consent banners, newsletter popups, and chat widgets before capture. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server lets Claude, Cursor, and other MCP clients call take_screenshot, get_page_info, and capture_pdf. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 screenshots. Create a free ScreenshotNeo account.
Decision guide
| Requirement | Best fit | Reason |
|---|---|---|
| One page in a Node script | Puppeteer | Simple page-level API with setExtraHTTPHeaders. |
| Many pages sharing credentials | Playwright | Context-wide extraHTTPHeaders keeps configuration centralized. |
| Attach to an existing browser | Playwright over CDP or a CDP client | Separates connection authentication from page-network headers. |
| Direct screenshot/PDF service | ScreenshotNeo | Clean shots, only clean shots billed, and a $5 paid plan. |
Frequently Asked Questions
Can I pass an Authorization header to every Chrome request?
Configure it with Puppeteer page headers, Playwright context headers, or CDP’s Network.setExtraHTTPHeaders before navigation; a plain –headless flag does not provide this documented capability.
Are custom headers visible to page JavaScript?
Not necessarily. A header configured for browser network traffic is sent by the browser’s request layer; it is not automatically exposed through document scripts or fetch interception.
Should I use a page or context header setting?
Use a page setting for one Puppeteer page and a Playwright context setting when multiple pages should share the same values.
Why should header order not be tested?
HTTP header order is not a stable application contract, and Puppeteer explicitly does not guarantee it. Test case-insensitive names and values instead.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

