HAR File Sanitizer & Viewer
Drop in a .har export from your browser's network panel to strip out credentials and session data, check what was removed, and download a copy that's safe to attach to a bug report.
Overview
A HAR (HTTP Archive) file records every request your browser made, including the headers and bodies. That makes it the most useful thing you can attach to a bug report, and also one of the riskiest: it usually contains your session cookies, bearer tokens, API keys, and sometimes passwords from login forms. Anyone holding the file can often replay those credentials and sign in as you.
This tool finds those values and replaces them with [REDACTED] while keeping the file a valid HAR, so support teams can still open it in Chrome DevTools or any HAR viewer and see the full request timeline. Because the file never leaves your browser, you don't have to trust another server with the very secrets you're trying to protect.
Examples & Sample Data
Request header and query string
Authorization: Bearer eyJhbGciOi... GET https://api.example.com/v1/me?access_token=abc123&lang=en
Authorization: [REDACTED] GET https://api.example.com/v1/me?access_token=%5BREDACTED%5D&lang=en
JSON login body
{"email":"[email protected]","password":"hunter2","remember":true}
{"email":"[email protected]","password":"[REDACTED]","remember":true}
How It Works
- Export a HAR from your browser: open DevTools, go to the Network tab, reproduce the problem, then right-click the request list and choose Save all as HAR (Chrome, Edge), Save All As HAR (Firefox), or Export HAR (Safari).
- Choose or drop the .har file here. It's parsed and sanitized immediately with every redaction rule switched on.
- Review the report and the request table. The Redacted column shows how many values were removed from each request; turn rules on or off and the result updates instantly.
- Download the sanitized copy and share that instead of the original.
Common Use Cases
Attaching a HAR to a support ticket
Vendors often ask for a HAR to debug a failing login or checkout. Sanitize it first so the ticket system doesn't end up storing a working session cookie.
Sharing a network trace in a public issue
Open-source maintainers frequently ask for HARs in GitHub issues, which anyone can download. Strip tokens before posting.
Quickly reading a HAR someone sent you
Use the request table and waterfall to see failing requests, slow calls, and response sizes without opening DevTools.
Tips & Best Practices
- Turn on Remove all response bodies when the bug is about requests or timings. Response bodies often contain personal data (names, emails, addresses) that no key-based rule can recognise.
- If your app uses a custom auth header such as X-Session or X-Tenant-Token, add it to Extra headers to redact.
- Sanitizing removes credentials, but it's still worth logging out or rotating any token that was in the original file if it may already have been shared.
Frequently Asked Questions
No. The file is read and processed by JavaScript in your browser, and the sanitized copy is generated locally. Nothing is sent to Adikya or any other server.
Credential headers (Authorization, Proxy-Authorization, Cookie, Set-Cookie, X-API-Key, X-Auth-Token, CSRF tokens, AWS security tokens), all cookie values, query parameters and JSON or form body fields whose names contain words like token, key, secret, password, session, code, or signature, and any JWT found anywhere in the text. You can also drop every response body.
Yes. Only values are replaced with [REDACTED]; the structure, URLs, timings, and every request entry stay in place, so the file still opens in Chrome DevTools, Firefox, and other HAR viewers.
No automated tool can. Personal data in response bodies (names, addresses, order details) or secrets stored under unusual field names won't be recognised by name. Review the report, consider removing all response bodies, and add any custom headers your app uses.
In Chrome or Edge, open DevTools (F12), select the Network tab, reproduce the issue, then right-click any request and choose Save all as HAR with content. In Firefox, use the gear menu in the Network panel and choose Save All As HAR. In Safari, enable the Develop menu, open Web Inspector's Network tab, and click Export.
Related Tools
Explore more high-performance utilities.