HAR Analyzer & Sanitizer is a free tool for the HAR files support teams ask for when a website misbehaves. It shows every request the browser made — status, size, timing and errors — and it makes a cleaned copy with session cookies, Authorization headers, tokens and passwords removed, listing exactly what it took out. The file is read in your browser and never uploaded.
How to clean a HAR file before sharing it
- Drop your
.harfile onto the page, or choose it. - Switch to Clean for sharing. Cookies, credential headers, tokens in URLs and secrets in bodies are removed straight away.
- Read the list of what was removed. Tick Remove all response bodies if the pages you visited contain personal details.
- Choose Download cleaned HAR and send that file, not the original.
Why a HAR file is sensitive
A HAR (HTTP Archive) is a complete recording of a browser’s network traffic. To reproduce a problem, it keeps everything: the cookie that keeps you signed in, the Authorization: Bearer header your apps send, the one-time code in an OAuth login URL, and the access and refresh tokens a login response returns. With those, someone can often act as you until they expire. Attackers have used HAR files shared in support tickets to do exactly that.
What the sanitizer removes
- Credential headers: Authorization, Cookie, Set-Cookie, API key and CSRF headers, and the parsed cookie lists.
- Secrets in URLs: access tokens, OAuth codes, API keys and signatures in query strings, and tokens in the
#fragmentleft by some sign-in flows. - Secrets in bodies: fields such as password, access_token, refresh_token and client_secret in JSON and form data, requests and responses.
- Anything shaped like a JWT, whatever it is called.
- Every other copy of a value it removed. A token in a page’s address is repeated in the Referer header of every request that page makes afterwards; those copies go too.
It deliberately keeps what someone debugging needs: status codes, timings, error messages, and fields likecode in a JSON error response, which are error codes rather than secrets. Values are replaced with the word REDACTED, so the file stays a valid HAR that opens in any viewer.
Reading the analysis
The summary shows how many requests the page made, how much it downloaded, how long it took from the first request to the last, and how many failed. A status of failed means the request never got a response — blocked by an extension, cancelled, or cut off. Filter by URL or type, tick Failed only to find what broke, and choose a request to see its headers, bodies and a breakdown of where its time went: DNS, connecting, TLS, waiting for the server, or downloading. Long “waiting for server” time points at the backend; long downloads at size. To dig into a single header set, use the HTTP Header Checker, and for cookies the Cookie Parser.
Saving a HAR file
- Chrome and Edge: open DevTools with F12, choose the Network tab, reproduce the problem, then click the download arrow (Export HAR).
- Firefox: in the Network panel, right-click any request and choose Save All As HAR.
- Safari: enable the Develop menu, open the Web Inspector’s Network tab, and use Export.
Tick “Preserve log” first if the problem involves a redirect or a login, so earlier requests are kept.
Frequently asked questions
Why do HAR files need cleaning before sharing?
A HAR records everything your browser sent and received, including session cookies, Authorization headers, login codes in URLs and tokens in responses. Anyone with those can often sign in as you until they expire. Support teams usually only need timings, status codes and error messages.
Is my HAR file uploaded?
No. It is read and cleaned in your browser, and the cleaned copy is saved straight to your device. That matters here more than almost anywhere: the file you are cleaning is full of the secrets you are trying not to send.
Does the cleaned file contain nothing personal?
It has no cookies, tokens, keys or passwords that the rules could find, and every copy of those values is removed wherever else it appears. Names, email addresses and page content stay in the file. If those matter, tick “Remove all response bodies” too, and look through the file before sending it.
How do I save a HAR file?
In Chrome or Edge, open DevTools (F12), go to the Network tab, reproduce the problem, then use the download arrow (“Export HAR”). In Firefox, right-click any request in the Network panel and choose “Save All As HAR”. In Safari, use Export in the Network tab of the Web Inspector.
Last updated