Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Chrome’s --headless flag selects an unattended browser mode; it is not a documented switch for arbitrary HTTP headers. To send an Authorization, X-API-Key, or tenant header with page traffic, set it through Puppeteer, Playwright, or the Chrome DevTools Protocol (CDP)—and do so before navigation if it must accompany the first document request.

Choose the right way to set headers

The best option depends on how you launch Chrome and which requests need the headers. Puppeteer sets extra headers on a page; Playwright sets them on a browser context; CDP gives low-level control or lets you configure an existing browser session. In each case, these are page-request headers, not headers that configure the headless runtime itself.

Method Header scope Use it when Important distinction
Puppeteer Requests initiated by one page Your application already uses Puppeteer and you want to configure a page directly Header names are lowercased; ordering is not guaranteed. Puppeteer API reference
Playwright Requests initiated by pages in a browser context You use Playwright and want a shared context configuration Its extraHTTPHeaders setting is distinct from headers used to connect to a CDP endpoint. Playwright API reference
CDP Depends on the protocol command and target session You need direct protocol control or are attaching to an existing Chrome instance Connection headers do not automatically become page-request headers. Playwright CDP connection reference

A bare Chrome command such as google-chrome --headless starts Chrome without a visible UI, but Chrome’s documented headless options do not provide a general arbitrary-header flag. Add a browser automation layer or send the appropriate CDP command instead.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Send headers with Puppeteer

Install Puppeteer in a Node.js project, then set headers on the page before calling goto. Puppeteer documents that extra HTTP headers are sent with every request the page initiates. Header values must be strings, names are lowercased, and header order is not guaranteed.

#1 Best Overall
HP 14" HD Chromebook Laptop for Students, Intel Quad-Core N4120(> N4020), 4GB RAM, 64GB eMMC, WiFi, Webcam, HDMI, USB-A&C, 14 Hours Battery Life, Zoom, Chrome OS, CUE Accessories
  • Intel Celeron N4120: 4 Cores & Threads, 1.1GHz Base Clock, Up to 2.6GHz Boost Clock, 4MB Cache, Intel UHD Graphics 600. The perfect combination of performance, power consumption, and value helps your device handle multitasking smoothly and reliably with four processing cores to divide up the work.
  • 14" HD Display: 14.0-inch diagonal, HD (1366 x 768), micro-edge, anti-glare. See your digital world in a whole new way. Enjoy movies and photos with the great image quality and high-definition detail of 1 million pixels.
  • Memory & Storage: 4 GB LPDDR4x & 64 GB eMMC Storage. Adequate high-bandwidth RAM to smoothly run multiple applications and browser tabs all at once. An embedded multimedia card provides reliable flash-based storage.
  • Ports:2 x USB 3.0 Type-A,1 x USB 3.0 Type-C,1 x HDMI,1 x Headphone Jack
  • Chrome OS: Chromebook is a computer for the way the modern world works, with thousands of apps. Enjoy the seamless simplicity that comes with Google Chrome and Android apps, all integrated into one laptop. It’s fast, simple, and secure.
import puppeteer from 'puppeteer';

const token = process.env.API_TOKEN;
if (!token) throw new Error('Set API_TOKEN in the environment');

const browser = await puppeteer.launch({ headless: true });
try {
  const page = await browser.newPage();
  await page.setExtraHTTPHeaders({
    authorization: `Bearer ${token}`,
    'x-tenant-id': 'acme'
  });

  const response = await page.goto('https://example.com', {
    waitUntil: 'domcontentloaded'
  });
  console.log('HTTP status:', response?.status());
} finally {
  await browser.close();
}

Run it with API_TOKEN provided by your environment or secret manager, rather than embedding the credential in source code. For example, on a Unix-like shell: API_TOKEN='your-token' node capture.mjs. This example uses an illustrative token and tenant value; replace them and the target URL with values authorized for your service.

Scope and behavior

  • Call setExtraHTTPHeaders before goto so the initial document request is made with the configured headers.
  • The documented scope covers requests initiated by that page, which can include subresources. Test the actual redirects and resource origins your page uses; receiving servers may enforce different authentication or cross-origin policies.
  • Header names are case-insensitive in HTTP, and Puppeteer sends their names in lowercase. Do not rely on a particular header order.
  • Pass values as strings. Keep bearer tokens and API keys out of logs and source control.

Send headers with Playwright

Playwright’s extraHTTPHeaders option is configured when creating the browser context. Pages in that context use the additional headers for their requests. Set the option before opening the page and navigating.

import { chromium } from 'playwright';

const token = process.env.API_TOKEN;
if (!token) throw new Error('Set API_TOKEN in the environment');

const browser = await chromium.launch({ headless: true });
try {
  const context = await browser.newContext({
    extraHTTPHeaders: {
      authorization: `Bearer ${token}`,
      'x-tenant-id': 'acme'
    }
  });
  const page = await context.newPage();
  const response = await page.goto('https://example.com', {
    waitUntil: 'domcontentloaded'
  });
  console.log('HTTP status:', response?.status());
} finally {
  await browser.close();
}

Install the Playwright package and its browser as appropriate for your project, then provide the credential in the environment, for example API_TOKEN='your-token' node capture.mjs. The chromium.launch call uses Playwright’s managed Chromium by default. Playwright can also control branded Chrome channels such as chrome, chrome-beta, and chrome-canary; its documentation cautions that using an arbitrary executable path is at your own risk. Check the Playwright browser documentation for current installation and channel details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Page headers are not CDP connection headers

When using Playwright’s connectOverCDP(endpointURL, options), the headers option supplies headers for the connection to the CDP endpoint. It does not configure the HTTP requests that a page makes to websites. Configure the page’s browser context with extraHTTPHeaders, or use the CDP page command described below.

Set page headers directly through CDP

CDP is useful when you need to control Chrome at protocol level, including when attaching to an existing browser. The Page.setExtraHTTPHeaders command sets extra HTTP headers for requests from the page target. It is separate from any headers used to establish a WebSocket or other connection to the debugging endpoint.

In a CDP client, create or attach to the relevant page target, create a protocol session for it, and send Page.setExtraHTTPHeaders with an headers object before navigation. Protocol session and target-management details depend on the CDP client and whether Chrome is locally launched or remote. Consult the protocol command reference for the supported command and parameters: CDP Page.setExtraHTTPHeaders.

Rank #3
ASUS 2026 15" FHD IPS Chromebook, Intel Processor Up to 2.80GHz, 4GB DDR4, 128GB Storage, HDMI, Super-Fast WiFi, Chrome OS, Pastel Silver (Renewed)
  • Intel Processor Up to 2.80GHz, 4GB DDR4, 128GB Storage
  • 15" FHD IPS Display, Intel UHD Graphics
  • 1x USB Type C, 1 x USB Type A, 1x Headphone/Microphone Combo Jack, HDMI
  • Fast WiFi and Bluetooth, Integrated Webcam
  • Chrome OS, AC Charger Included, Pastel Silver

For ordinary application code, Puppeteer or Playwright is generally simpler because each wraps target and session management. Use CDP directly when your integration already speaks the protocol or requires low-level browser control. Whichever client you choose, verify that the command is sent to the page target that will navigate—not merely to the browser connection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What Chrome Headless does—and does not do

Chrome Headless runs Chrome without a visible UI in an unattended environment. Google’s documentation says current Headless mode is unified with the regular Chrome implementation. Since Chrome 132.0.6793.0, the old implementation is distributed separately as chrome-headless-shell; the Chrome for Developers page describing this was last updated 2024-10-21 UTC. These details concern the browser mode and implementation, not a header-setting feature. Chrome Headless documentation.

In practice, keep the responsibilities separate: launch Chrome in headless mode, then configure request headers using your automation framework or CDP. A command-line browser invocation alone does not replace that second step.

Rank #4
Lenovo Chromebook 2-in-1 - Lightweight Laptop - Google Gemini - Intel® N150 CPU - 14" WUXGA IPS Touchscreen Display - 4GB RAM - 128GB UFS Storage - Integrated Intel® Graphics - Luna Grey
  • THE BETTER WAY TO LAPTOP – Imagine a Chromebook that’s as flexible as your day: thin and lightweight with built-in Google apps and stress-free security.
  • TAKE HITS KEEP MOVING – Sleek, light, and built to last- the Chromebook 2-in-1 is just 0.69” thick and 3.3lbs. Enjoy long-lasting battery life, fast charging, and military-grade durability for nonstop productivity wherever life takes you.
  • PERFORMANCE THAT MATCHES YOUR HUSTLE – Fuel your ideas with an Intel Core processor and 128GB storage. Boot up in under 10 seconds to start the day powerfully efficient.
  • FLEX YOUR CREATIVITY ANYWHERE, ANYTIME – Create, work, or unwind your way with a versatile 2-in-1 design. Flip easily between laptop, tent, and tablet modes with a responsive touchscreen built for flexibility.
  • BRILLIANT VIEWS AND IMMERSIVE AUDIO – See, hear, and create with awesome clarity. The WUXGA display brings rich detail to your work and play, while audio tuned by Waves MaxxAudio provides immersive, balanced sound.

Credentials, origins, redirects, and server policy

A configured header does not guarantee that every destination will accept it or that sending it is appropriate. Authentication and cross-origin behavior are determined by the browser, the destination server, and any intervening redirects or resources.

  • Protect secrets: read tokens from environment variables or a secret manager. Avoid committing them, printing them, or exposing them in error reports.
  • Check the target and redirects: test the initial URL and any redirect chain. A request-wide setting should not be treated as permission to disclose credentials to unrelated origins; validate what your framework sends and what the destination receives.
  • Do not confuse browser navigation with CORS authorization: for browser JavaScript to read cross-origin responses, the receiving server must satisfy the browser’s CORS rules. Adding an authentication header does not bypass those rules.
  • Consider CSRF separately: if the endpoint changes state, follow the server’s authentication and CSRF requirements. A header is not, by itself, proof that a request is safe.
  • Use the correct API contract: some services require a particular header name, token format, or audience. Confirm those details with the service rather than assuming that a generic bearer header will work.

Troubleshoot missing or rejected headers

Symptom Likely cause What to check
The first page request has no header The header was set after navigation began, or on a different page/context/target Configure it before goto; confirm the navigating page belongs to the configured context or CDP session.
The CDP endpoint accepts credentials, but the site does not Connection metadata was supplied instead of page-request headers Use Playwright context extraHTTPHeaders or CDP Page.setExtraHTTPHeaders for website traffic.
The server returns 401 or 403 Invalid, expired, or incorrectly formatted credentials, wrong endpoint, or server policy Check the required header name and value format, token validity and permissions, and server-side authentication logs.
The document works but an API call or subresource fails The requests may reach a different origin or have distinct server/CORS requirements Inspect the failing request’s destination and response. Verify its authentication and CORS policy separately.
A custom executable does not behave like expected Chrome The selected binary, browser channel, or framework version differs from the documented setup Check installed Puppeteer or Playwright versions, the Chrome version, the selected channel/path, and the matching framework documentation.
Header casing or order differs HTTP header names are case-insensitive; Puppeteer explicitly lowercases names and does not promise order Make the receiver compare header names case-insensitively and do not depend on ordering.

For diagnosis, inspect the actual network request in the browser’s DevTools or a controlled test server, and compare its destination, status, redirect path, and request headers with the server’s requirements. Avoid dumping live credentials into shared logs.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your goal is a website screenshot rather than browser automation, ScreenshotNeo can return an image or PDF from one GET request. Its screenshot request supports custom headers, including authentication headers; see the ScreenshotNeo API documentation for the available parameters.

Best Value
HP Chromebook 14 Laptop, Intel Celeron N4120, 4 GB RAM, 64 GB eMMC, 14" HD Display, Chrome OS, Thin Design, 4K Graphics, Long Battery Life, Ash Gray Keyboard (14a-na0226nr, 2022, Mineral Silver)
  • FOR HOME, WORK, & SCHOOL – With an Intel processor, 14-inch display, custom-tuned stereo speakers, and long battery life, this Chromebook laptop lets you knock out any assignment or binge-watch your favorite shows..Voltage:5.0 volts
  • HD DISPLAY, PORTABLE DESIGN – See every bit of detail on this micro-edge, anti-glare, 14-inch HD (1366 x 768) display (1); easily take this thin and lightweight laptop PC from room to room, on trips, or in a backpack.
  • ALL-DAY PERFORMANCE – Reliably tackle all your assignments at once with the quad-core, Intel Celeron N4120—the perfect processor for performance, power consumption, and value (2).
  • 4K READY – Smoothly stream 4K content and play your favorite next-gen games with Intel UHD Graphics 600 (3) (4).
  • MEMORY AND STORAGE – Enjoy a boost to your system’s performance with 4 GB of RAM while saving more of your favorite memories with 64 GB of reliable flash-based eMMC storage (5).
curl -G "https://api.screenshotneo.com/v1/shot" 
  -d access_key=YOUR_API_KEY 
  --data-urlencode url=https://stripe.com 
  -o shot.webp

Replace the example target with the page you are authorized to capture. A header parameter can be added according to the API documentation. ScreenshotNeo accepts cookie/consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each of these steps can be turned off. Bot checks/CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and responses identify page verdict and billing status in X-Page-Verdict and X-Billed headers. It also offers an MCP server with take_screenshot, get_page_info, and capture_pdf tools for AI agents. The Free plan includes 1,000 screenshots per month without a card; paid plans start at $5 for 3,000 shots.

Sign up for ScreenshotNeo’s free plan: 1,000 screenshots a month, no card required.

Frequently Asked Questions

Can I use Chrome’s –headless flag to set an Authorization header?

No general arbitrary-header switch is documented for the flag. Use Puppeteer, Playwright, or CDP to set page-request headers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do CDP connection headers become headers on website requests?

No. Headers supplied for the CDP connection apply to that connection; configure page traffic separately.

Should I capitalize custom header names?

HTTP header names are case-insensitive. Puppeteer lowercases them, so application logic should not rely on capitalization.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.