HAR Analyzer & Viewer
Open a HAR file from Chrome, Firefox or Safari: sortable waterfall, request details, cURL, slow and failed requests, and a copy with cookies and tokens removed.
- Runs in your browser
- Your data never leaves your browser
- Free · No Sign-Up
Scan with WeChat to share this tool
Examples, details and FAQ Worked examples, how it compares with other tools, and answers to common questions.
Example: Redacting a Login Capture
The sample HAR is a Chrome-style export with sensitive data. After redaction, its login request (request 5) reads:
set-cookie: session=[redacted]; Path=/; Secure; HttpOnly; SameSite=Lax
{"email":"shopper@example.com","password":"[redacted]","remember":true}
{"user":{"id":42,"name":"Demo Shopper"},"access_token":"[redacted]","expires_in":3600}
The cookie name and its Secure, HttpOnly and SameSite attributes stay, because they are often what a support engineer needs to see. The next request carries the token twice:
https://api.example.com/v1/orders?page=1&access_token=[redacted]
authorization: Bearer [redacted]
The same session id also appears in the account page HTML and in an analytics URL as sid=. Both are replaced, because the export searches the whole file for every value it removed. The report lists what was replaced and confirms that the saved file was parsed again with none of the removed values left.
What the Redacted Copy Removes
- Values of
Cookie,Set-CookieandAuthorization(the scheme word, such asBearer, is kept), and every value in thecookieslists. - Headers, URL parameters (query and fragment), form fields, multipart parts and JSON keys at any depth whose names look like credentials: token, secret, password, session, api key, signature, csrf,
code,sidand similar.token_typeandAccess-Control-Allow-Credentialsare left alone. - Token-shaped strings anywhere else: JWTs,
Bearervalues and the provider key formats used by the Secret Redactor, such as GitHub, Stripe and AWS keys. - Optionally: all request bodies, all response bodies and WebSocket messages, and server IP addresses. Removing response bodies also makes the file much smaller.
Personal data such as an email address in a body is not a credential and is kept. The report says how many request and response bodies are still in the file; add field names like email to Also redact these names, or remove the bodies.
This matters because a HAR is a copy of a logged-in session. In October 2023, an attacker used a stolen credential to read HAR files uploaded to Okta’s support system; Okta wrote that such files “can also contain sensitive data, including cookies and session tokens” and recommends sanitizing them before sharing.
Reading the Waterfall
Each bar starts at the request’s startedDateTime and has up to seven parts taken from the HAR 1.2 timings object: queued or stalled (blocked), DNS, connect, TLS (ssl), send, wait (time to first byte) and receive. A value of -1 means the phase did not happen, for example on a reused connection, and is shown as N/A. Vertical lines mark DOMContentLoaded and load from the page timings.
Chrome and Safari count TLS inside connect, as the spec says, so the bar splits that part into TCP and TLS. Firefox measures them separately and adds both to time:
connect 18 ms + ssl 21 ms (time 151 ms = sum of all seven)
Without that check, Firefox captures would show bars 21 ms too short and a timing error on every HTTPS request. Chrome also writes _blocked_queueing; the Timing tab shows it as the queueing part of blocked. Transfer sizes come from _transferSize in Chrome and Safari, and from bodySize in Firefox, which stores the whole transfer there.
cURL Commands
Commands follow Chrome DevTools “Copy as cURL”: values in single quotes, $'…' when the value contains ' or !, HTTP/2 pseudo-headers such as :authority and Accept-Encoding left out, and the Cookie header passed with -b. In single quotes a body like {"note":"costs $5"} reaches the server unchanged; in double quotes a POSIX shell would expand $5. With Use redacted values on, the login request becomes:
curl --url 'https://api.example.com/v1/login' \
-H 'accept: */*' \
-H 'user-agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36' \
-H 'content-type: application/json' \
-H 'origin: https://shop.example.com' \
-H 'x-csrf-token: [redacted]' \
--data-raw '{"email":"shopper@example.com","password":"[redacted]","remember":true}'
To turn a command into Python or Go, paste it into cURL to Code. Single headers can be checked in the HTTP Header Analyzer and cookie strings in the Cookie Parser.
Compared with Other HAR Tools
On 2026-10-01 we loaded the same file into each tool and searched the redacted output for seven values: the sample HAR plus a request with an x-session-id header and a refresh_token nested in a JSON response after 3,200 characters.
| Tool | Left in the output |
|---|---|
| Chrome DevTools, Export HAR (sanitized) | Everything except the Cookie, Set-Cookie and Authorization headers: URL token, password, CSRF header, session id in HTML |
| Google Admin Toolbox HAR Analyzer, redact button | Password in the JSON body, x-session-id, the nested refresh_token, session id in HTML and in sid= |
| Cloudflare HAR Sanitizer, default ticks | Session cookie, password, CSRF header, x-session-id, refresh_token; the JWT keeps its header and payload |
| This tool, default options | None of the seven; the email address is kept and the kept bodies are reported |
None of the three uploaded the file in our test. Chrome’s rules are in devtools-frontend Log.ts; Google’s analyzer redacts top-level JSON keys and only the first 3,000 characters of other text.
FAQ
How do I export a HAR file?
In Chrome or Edge, open DevTools, go to the Network panel, reproduce the problem and click Export HAR (sanitized). Since Chrome 130 that default export leaves out Cookie, Set-Cookie and Authorization headers. To include them, turn on Settings > Preferences > Network > Allow to generate HAR with sensitive data, then long-click the Export button and choose Export HAR (with sensitive data). In Firefox, right-click the request list and choose Save All As HAR. In Safari, use the Export button in the Web Inspector Network tab.
Is Chrome's sanitized export safe to share?
Not always. Chrome removes three headers and the cookie lists, and nothing else. Tokens in URLs, passwords in request bodies, CSRF and API-key headers, and response bodies stay in the file. Load it here and check the Sensitive data card: it counts what is still there.
Is my HAR uploaded?
No. The file is read and parsed in this tab, and the page sends no request with its content. The tool does not save anything, and this page does not load Google Analytics or AdSense. Open another file or reload the page to drop it from memory.
Why does entry.time not match the sum of the timings?
HAR 1.2 says entry.time is the sum of blocked, dns, connect, send, wait and receive, with ssl counted inside connect. Firefox writes TCP time to connect and adds ssl separately, so its sum includes ssl. The tool checks which sum matches each entry and draws the bar to match. A difference larger than 1.5 ms is listed under Findings and in the Timing tab.
Which requests can I export or copy?
All of them, or only the ones shown in Requests after you filter by URL text, status class and resource type. The export is a HAR 1.2 file that DevTools can import again. Copy as cURL uses the same filter and uses redacted values unless you turn that off.