HAR Analyzer & Viewer

Open a HAR file from Chrome, Firefox or Safari: sortable waterfall, request details, cURL, slow and failed requests, and a copy with cookies and tokens removed.

  • Runs in your browser
  • Your data never leaves your browser
  • Free · No Sign-Up
Drop a .har file here, or click to choose You can also paste HAR JSON with Ctrl+V (⌘V). The file is read on this device and never uploaded.
Chrome or Edge: open DevTools, go to the Network panel, reproduce the problem and click Export HAR (sanitized). Since Chrome 130 that export leaves out the Cookie, Set-Cookie and Authorization headers; to include them, turn on Settings > Preferences > Network > Allow to generate HAR with sensitive data, then long-click Export and choose Export HAR (with sensitive data). Firefox: right-click the request list and choose Save All As HAR. Safari: use the Export button in the Network tab of Web Inspector. A HAR is JSON with a log.entries array; log.version must be 1.x. Files up to 300 MB. A file that cannot be opened gets the reason: an empty file, the line and column of a JSON error, JSON that is not a HAR, or an unsupported version; the file on screen stays. Opening, the sensitive-data scan, redaction and cURL run in short steps, so the page keeps responding; Cancel stops opening a new file (the file on screen stays) or stops a running export. In Chrome on an Apple M1 Max, a 68 MB HAR with 13,253 requests opened in about 0.7 s and was redacted in about 2.7 s.

The file is read in this tab. Nothing is uploaded, and nothing is saved after you leave the page.

Examples, details and FAQ Worked examples, how it compares with other tools, and answers to common questions.

Example: Redacting a Login Capture

The sample HAR is a Chrome-style export with sensitive data. After redaction, its login request (request 5) reads:

set-cookie: session=[redacted]; Path=/; Secure; HttpOnly; SameSite=Lax
{"email":"shopper@example.com","password":"[redacted]","remember":true}
{"user":{"id":42,"name":"Demo Shopper"},"access_token":"[redacted]","expires_in":3600}

The cookie name and its Secure, HttpOnly and SameSite attributes stay, because they are often what a support engineer needs to see. The next request carries the token twice:

https://api.example.com/v1/orders?page=1&access_token=[redacted]
authorization: Bearer [redacted]

The same session id also appears in the account page HTML and in an analytics URL as sid=. Both are replaced, because the export searches the whole file for every value it removed. The report lists what was replaced and confirms that the saved file was parsed again with none of the removed values left.

What the Redacted Copy Removes

  • Values of Cookie, Set-Cookie and Authorization (the scheme word, such as Bearer, is kept), and every value in the cookies lists.
  • Headers, URL parameters (query and fragment), form fields, multipart parts and JSON keys at any depth whose names look like credentials: token, secret, password, session, api key, signature, csrf, code, sid and similar. token_type and Access-Control-Allow-Credentials are left alone.
  • Token-shaped strings anywhere else: JWTs, Bearer values and the provider key formats used by the Secret Redactor, such as GitHub, Stripe and AWS keys.
  • Optionally: all request bodies, all response bodies and WebSocket messages, and server IP addresses. Removing response bodies also makes the file much smaller.

Personal data such as an email address in a body is not a credential and is kept. The report says how many request and response bodies are still in the file; add field names like email to Also redact these names, or remove the bodies.

This matters because a HAR is a copy of a logged-in session. In October 2023, an attacker used a stolen credential to read HAR files uploaded to Okta’s support system; Okta wrote that such files “can also contain sensitive data, including cookies and session tokens” and recommends sanitizing them before sharing.

Reading the Waterfall

Each bar starts at the request’s startedDateTime and has up to seven parts taken from the HAR 1.2 timings object: queued or stalled (blocked), DNS, connect, TLS (ssl), send, wait (time to first byte) and receive. A value of -1 means the phase did not happen, for example on a reused connection, and is shown as N/A. Vertical lines mark DOMContentLoaded and load from the page timings.

Chrome and Safari count TLS inside connect, as the spec says, so the bar splits that part into TCP and TLS. Firefox measures them separately and adds both to time:

connect 18 ms + ssl 21 ms (time 151 ms = sum of all seven)

Without that check, Firefox captures would show bars 21 ms too short and a timing error on every HTTPS request. Chrome also writes _blocked_queueing; the Timing tab shows it as the queueing part of blocked. Transfer sizes come from _transferSize in Chrome and Safari, and from bodySize in Firefox, which stores the whole transfer there.

cURL Commands

Commands follow Chrome DevTools “Copy as cURL”: values in single quotes, $'…' when the value contains ' or !, HTTP/2 pseudo-headers such as :authority and Accept-Encoding left out, and the Cookie header passed with -b. In single quotes a body like {"note":"costs $5"} reaches the server unchanged; in double quotes a POSIX shell would expand $5. With Use redacted values on, the login request becomes:

curl --url 'https://api.example.com/v1/login' \
  -H 'accept: */*' \
  -H 'user-agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36' \
  -H 'content-type: application/json' \
  -H 'origin: https://shop.example.com' \
  -H 'x-csrf-token: [redacted]' \
  --data-raw '{"email":"shopper@example.com","password":"[redacted]","remember":true}'

To turn a command into Python or Go, paste it into cURL to Code. Single headers can be checked in the HTTP Header Analyzer and cookie strings in the Cookie Parser.

Compared with Other HAR Tools

On 2026-10-01 we loaded the same file into each tool and searched the redacted output for seven values: the sample HAR plus a request with an x-session-id header and a refresh_token nested in a JSON response after 3,200 characters.

ToolLeft in the output
Chrome DevTools, Export HAR (sanitized)Everything except the Cookie, Set-Cookie and Authorization headers: URL token, password, CSRF header, session id in HTML
Google Admin Toolbox HAR Analyzer, redact buttonPassword in the JSON body, x-session-id, the nested refresh_token, session id in HTML and in sid=
Cloudflare HAR Sanitizer, default ticksSession cookie, password, CSRF header, x-session-id, refresh_token; the JWT keeps its header and payload
This tool, default optionsNone of the seven; the email address is kept and the kept bodies are reported

None of the three uploaded the file in our test. Chrome’s rules are in devtools-frontend Log.ts; Google’s analyzer redacts top-level JSON keys and only the first 3,000 characters of other text.

FAQ

How do I export a HAR file?

In Chrome or Edge, open DevTools, go to the Network panel, reproduce the problem and click Export HAR (sanitized). Since Chrome 130 that default export leaves out Cookie, Set-Cookie and Authorization headers. To include them, turn on Settings > Preferences > Network > Allow to generate HAR with sensitive data, then long-click the Export button and choose Export HAR (with sensitive data). In Firefox, right-click the request list and choose Save All As HAR. In Safari, use the Export button in the Web Inspector Network tab.

Is Chrome's sanitized export safe to share?

Not always. Chrome removes three headers and the cookie lists, and nothing else. Tokens in URLs, passwords in request bodies, CSRF and API-key headers, and response bodies stay in the file. Load it here and check the Sensitive data card: it counts what is still there.

Is my HAR uploaded?

No. The file is read and parsed in this tab, and the page sends no request with its content. The tool does not save anything, and this page does not load Google Analytics or AdSense. Open another file or reload the page to drop it from memory.

Why does entry.time not match the sum of the timings?

HAR 1.2 says entry.time is the sum of blocked, dns, connect, send, wait and receive, with ssl counted inside connect. Firefox writes TCP time to connect and adds ssl separately, so its sum includes ssl. The tool checks which sum matches each entry and draws the bar to match. A difference larger than 1.5 ms is listed under Findings and in the Timing tab.

Which requests can I export or copy?

All of them, or only the ones shown in Requests after you filter by URL text, status class and resource type. The export is a HAR 1.2 file that DevTools can import again. Copy as cURL uses the same filter and uses redacted values unless you turn that off.