Back

HAR viewer & sanitizer

Developer tools

Loading

Loading tool

The tool is loaded only when you open it.

All processing for this tool happens in your browser. Your input is not sent to a server.

About this tool

Open a HAR 1.2 file or paste its JSON to inspect a captured network session in your browser. Filter requests by domain or HTTP status, then read a request’s headers, body and timing breakdown as plain text. The tool does not upload your archive, replay requests, fetch recorded URLs or persist imported data. Export creates a separate, configurable redacted HAR; the original details remain visible while you inspect them. Redaction reduces exposure but is not complete anonymization, so review the entire exported file before sharing it.

Common uses

  • Investigate a slow API call by comparing its recorded connection, waiting and receive times without contacting the server again.
  • Find failed requests from a particular domain in an existing browser network capture.
  • Prepare a minimized HAR for a support ticket by removing common credentials and payloads, then reviewing remaining identifiers yourself.

How to use it

  1. 1.Export a HAR from your browser’s Network panel, then select the file or paste the complete JSON here. Inputs must be HAR 1.2, at most 5 MiB in UTF-8 and contain no more than 2,000 entries.
  2. 2.Filter the request list by domain or status and select an entry. Inspect its URL, headers, body and millisecond timings; missing timing data is not evidence of a zero-duration phase.
  3. 3.Choose the export redaction settings. Start with all query values and both bodies removed or redacted, change only what you need, and download the sanitized HAR. Review every exported entry before sharing; view filters do not limit the export.

Synthetic HAR examples

A 100 ms request with SSL inside connect

{"log":{"version":"1.2","creator":{"name":"Synthetic example","version":"1.0"},"entries":[{"startedDateTime":"2026-01-01T00:00:00.000Z","time":100,"request":{"method":"GET","url":"https://example.com/api/items","httpVersion":"HTTP/1.1","cookies":[],"headers":[],"queryString":[],"headersSize":-1,"bodySize":0},"response":{"status":200,"statusText":"OK","httpVersion":"HTTP/1.1","cookies":[],"headers":[],"content":{"size":0,"mimeType":"application/json"},"redirectURL":"","headersSize":-1,"bodySize":0},"cache":{},"timings":{"blocked":0,"dns":0,"connect":30,"ssl":10,"send":5,"wait":50,"receive":15}}]}}
GET example.com · 200
Total: 100 ms
Connect: 30 ms, including SSL: 10 ms
Send: 5 ms · Wait: 50 ms · Receive: 15 ms

This complete HAR uses only synthetic data. The phase sum is 0 + 0 + 30 + 5 + 50 + 15 = 100 ms. Adding SSL again would incorrectly produce 110 ms. Opening it makes no request to example.com.

Default export still needs review

GET https://example.com/users/demo-42?token=demo-token&page=2
Authorization: Bearer demo-token
Cookie: session=demo-session
X-Account: demo-42
Authorization and Cookie: removed
Query values: redacted
Domain and /users/demo-42 path: retained
X-Account value: review required

This is a synthetic request excerpt, not a complete importable HAR. Default redaction hides common credentials and all query values, but the path and an unrecognized identifying header can remain. Inspect the exported archive instead of assuming that a sanitizer guarantees anonymity.

Select a JSON key without hiding every value

Content-Type: application/json

{"TOKEN":"demo-token","customer":"demo-42","count":2}

Selected body key: token
TOKEN value: redacted
customer: demo-42
count: 2

This synthetic body excerpt illustrates supported JSON selective redaction, not a complete HAR file. Matching token also matches TOKEN. Other fields remain, so the customer identifier still needs review. Keep body removal enabled when there is no reason to retain payloads.

Common HAR inspection mistakes

  • Pasting only a request object or a JavaScript object literal: import a complete HAR JSON object with log.version and log.entries; JSON requires quoted keys and no trailing commas.
  • Opening a capture over 5 MiB or 2,000 entries: capture a smaller reproduction or reduce the archive using a trusted local workflow before importing.
  • Adding SSL to connect when estimating total duration: SSL is already part of connect.
  • Treating -1 or absent timing data as zero: the exporter may not have measured that phase.
  • Filtering down to one request and assuming only that request will be exported: export includes all imported entries.
  • Sharing the original file, or trusting a redacted file without inspection: review domains, paths, titles, remaining headers and any retained body or query values in the actual exported file.

Limits and notes

  • Only HAR 1.2 JSON up to 5 MiB (5,242,880 UTF-8 bytes) and 2,000 entries is accepted, with HTTP(S) request URLs. This is a bounded viewer, not a live recorder, complete HAR validator, packet analyzer or request-replay tool. Input is also limited to 64 nesting levels and 100,000 JSON values.
  • Timing values come from the archive, in milliseconds. A missing value or -1 means unavailable, not zero. SSL time is included in connect time and must not be added twice. Concurrent requests overlap, so summing entry durations does not give page-load time.
  • By default, export removes cookies, recognized authentication headers, request and response bodies, comments, and custom or unknown fields, and redacts all query values. Selective query or body key matching ignores case; it is not a general secret detector.
  • Selective body redaction supports the JSON and URL-encoded form representations recognized by the tool. In that mode, unsupported, malformed or base64-encoded bodies are omitted; choosing Keep can preserve them and their sensitive content. Export reconstructs known fields, discards page and unsupported metadata, and is not a byte-for-byte copy.
  • Every imported entry is exported regardless of the active domain or status filters. Retained domains, URL paths, header values and content you choose to keep can still reveal identities or secrets. Original HAR files can also contain identifying page titles. Plain-text display prevents embedded content from executing; it does not make that content safe to share. Recorded timestamps and IP addresses in URL hosts, paths or ordinary headers can also identify people.

Frequently asked questions

How do I get a HAR, and is a browser’s sanitized export enough?

Use the export option in your browser’s Network panel after capturing the relevant activity. Chrome offers a sanitized HAR export that excludes certain sensitive headers, but URLs and other captured content still need review. Prefer a short capture with synthetic test data whenever possible. This viewer applies its own export settings and cannot certify that a file is safe to disclose.

What is the difference between default and selected-key redaction?

The default hides all query values and omits both bodies. Selected-key modes let you redact named query or supported body fields, ignoring case, while other values may remain. List the keys relevant to your capture and inspect the result. An identifier in a path, an unfamiliar header or an unselected field can survive even when familiar credential keys are removed.

Why do the phase timings not add up the way I expect?

HAR records the exporter’s measurements. SSL is a subset of connect, unavailable phases can be -1 or absent, and multiple requests can run at once. A large wait value alone cannot prove that the server was solely responsible. Use the recorded phases as debugging evidence rather than a complete diagnosis.

Does filtering or exporting change the original HAR?

No. Filters only change the visible request list, and export builds a separate archive containing all imported entries. The original file is not overwritten and imported data is not saved as a history. Downloading does save the generated file to your device, where it needs the same care as any other potentially sensitive file.

Related tools