thoughtasylumTOOLBOX Preview

Tools › Developer

HAR Viewer & Redactor

Open a HAR file (a browser's saved network log) to see its requests, then save a copy with cookies, sign-in headers, tokens, passwords and response bodies removed, safe to send to a support team.

About this tool What it's for, how to use it and an example

What it's for

Look inside a HAR file, the network log a browser saves from its developer tools, and make a copy that’s safe to share. Support teams often ask for a HAR to diagnose a problem, but it holds everything the browser sent and got back, including session cookies and sign-in tokens that would let someone act as you.

For example, when a vendor asks for a HAR of a failing sign-in, open it here, check the failing request is in it, and send the redacted copy instead of the original.

How to use it

Choose a .har file, or drop it on the page. The table lists every request with its method, status, address, type, size and time; failed requests (status 400 or over, or 0) are in red. Type in Filter to show only requests containing that text.

Save the redacted HAR saves a copy named like capture-redacted.har, where each of these values becomes REDACTED:

  • Headers whose names suggest secrets, such as Authorization, Cookie, Set-Cookie, CSRF and API key headers.
  • Every cookie.
  • Query string and form values, and keys in JSON request bodies, named like tokens, passwords, codes, keys, sessions, signatures or SAML messages, in the address as well as the parsed lists.
  • Any JSON Web Token (JWT) found anywhere in addresses, headers or bodies.
  • With Remove response bodies when saving ticked (remembered in this browser), the content of every response.

The message line counts what will be redacted. The original file isn’t changed.

Example

Save this as capture.har and open it:

{"log":{"entries":[{"time":120,"request":{"method":"GET","url":"https://app.example.com/api/me?session=abc123","headers":[{"name":"Authorization","value":"Bearer xyz"},{"name":"Accept","value":"application/json"}],"cookies":[{"name":"sid","value":"s1"}],"queryString":[{"name":"session","value":"abc123"}]},"response":{"status":401,"headers":[],"cookies":[],"content":{"size":27,"mimeType":"application/json","text":"{\"error\":\"session expired\"}"}}}]}}

The table shows one request, GET, status 401 in red, 27 B in 120 ms. The message says saving redacts 1 header, 1 cookie, 1 parameter and 0 web tokens, and removes 1 response body. In the saved capture-redacted.har the address ends ?session=REDACTED, the Authorization header and the cookie are REDACTED, Accept is unchanged, and the response’s text is empty.

To make a real HAR in Chrome, open the developer tools, choose the Network tab, load the page, then Export HAR (the download arrow).

Good to know

Redaction goes by names and the shape of JSON Web Tokens, so a secret under an unusual name, or personal details in a request body or a page address, can remain: look through the copy before sending it, and keep response bodies removed unless they’re needed. Names are matched loosely (anything containing “auth”, “token” or “session”, for example), so some harmless values are redacted too. For free text rather than a HAR, use Redact for AI.

Private: this tool runs in your browser. Nothing you type, paste or choose leaves this page.

Saved you a few minutes? Say thanks with a coffee.

Something wrong with this tool, or missing from it? Report a bug or suggest a feature.

↑ ↓ move↵ openesc close