A HAR (HTTP Archive) file is a recording of everything your browser sent and received while loading a web page. Support teams often ask for a HAR file to debug a problem, but a raw HAR file can contain cookies, authorization tokens, passwords, and other sensitive data.
Before you send a HAR file to anyone, you should inspect it and remove the sensitive values you do not want to share. You do not need a desktop tool to do this - you only need a viewer that understands the HAR format.
Open the HAR Viewer to inspect and sanitize a supported .har file directly in your browser.
What is a HAR file?
A .har file is an HTTP Archive. It is a JSON document that records the network activity of a browser session. A HAR file can contain:
- Request URLs - every page, script, image, and API call the browser made
- Request headers - cookies, authorization tokens, user agents, and custom headers
- Request bodies - form data, JSON payloads, and uploaded content
- Response headers - server headers, set-cookie directives, and cache rules
- Response bodies - HTML, JSON, images, scripts, and other downloaded content
- Timing data - how long each request and response took
- Query strings - parameters appended to URLs
HAR files are produced by browser DevTools (Chrome, Edge, Firefox, Safari) and by some testing and monitoring tools.
Why HAR files are dangerous to share raw
A raw HAR file can contain a large amount of sensitive information. Common risks include:
- Session cookies: Anyone with your cookies can impersonate your session.
- Authorization tokens: Bearer tokens, API keys, and JWTs grant access to your account.
- Passwords: If you submitted a login form during the recording, the password may be in the request body.
- Personal data: Names, emails, phone numbers, and addresses may appear in responses.
- Internal URLs: Private or internal API endpoints may be exposed.
- Payment data: Card numbers or payment tokens may appear in request or response bodies.
- Tracking identifiers: Analytics and advertising IDs may be present.
Sharing a raw HAR file is similar to sharing your browser session. Always sanitize before sending.
Quick answer: what should you do?
Choose the method based on what you actually need.
| What you need to do | Better approach |
|---|---|
| Inspect the HAR before sharing | Use a HAR viewer |
| Remove cookies and tokens | Use a viewer with sanitization or manual editing |
| Check what a request sent | Use a viewer that shows request headers and bodies |
| Verify the file is valid | Open it in a viewer that reports errors |
| Share a safe copy with support | Sanitize, then export the cleaned file |
| Record a new HAR | Use browser DevTools to capture a fresh recording |
For a quick inspection, FileViewerHub is designed to show supported HAR file contents in your browser without requiring a desktop tool.
Method 1: Inspect and sanitize the HAR file in FileViewerHub
This method is useful when you need to review the requests, identify sensitive data, and remove it before sharing the file.
Step 1: Open the HAR Viewer
Go to the FileViewerHub HAR Viewer.
The viewer supports .har files and processes supported file contents locally in the browser for standard viewing.
Step 2: Select the HAR file
Drag the file into the upload area or choose it from your device.
Before parsing begins, FileViewerHub may show a large-file warning when the file exceeds the recommended size for the current device. Files above the viewer's hard browser-safety limit should be blocked rather than opened.
This limit is intentional. A HAR file with many large response bodies can expand significantly after parsing.
Step 3: Review the request list
After the file opens, verify that:
- The list of requests is shown with URL, method, and status.
- Requests are grouped or sortable where supported.
- The total request count looks reasonable.
- The recording covers the expected time range.
FileViewerHub can parse standard HAR files produced by Chrome, Edge, Firefox, and other browser DevTools where supported.
Step 4: Identify sensitive data
For each request, check the following for sensitive values:
- Request headers: Look for
Cookie,Authorization,X-API-Key,X-Auth-Token, and similar headers. - Request body: Look for form fields, JSON payloads, or uploaded content that may contain passwords or personal data.
- Query string: Look for tokens, IDs, or session parameters appended to URLs.
- Response headers: Look for
Set-Cookieand other server-set identifiers. - Response body: Look for personal data, account details, or payment information in the downloaded content.
Common sensitive headers and fields to watch for:
CookieAuthorizationSet-CookieX-API-KeyX-Auth-TokenX-CSRF-Tokenpasswordtokensecretapi_key
Step 5: Remove or redact sensitive values
For each sensitive value you found, decide whether to:
- Remove the header or field entirely
- Replace the value with a placeholder such as
[REDACTED] - Remove the entire request if it is not relevant to the support issue
If the viewer supports sanitization or export, use it to produce a cleaned copy. If not, you can:
- Export the HAR to JSON.
- Open it in a text editor.
- Search for sensitive keywords (
cookie,authorization,token,password). - Replace the values with
[REDACTED]. - Save the cleaned file.
Step 6: Verify the sanitized file
After sanitizing, reopen the cleaned file in the viewer and confirm that:
- No cookies or tokens remain.
- No passwords or personal data appear in request or response bodies.
- The file is still valid JSON.
- The requests relevant to the support issue are still present.
- The file can be opened without errors.
Only after verification should you share the file.
Method 2: Record a minimal HAR file
The safest approach is to record only what you need. If you have not yet captured the HAR, follow these steps to minimize sensitive data from the start.
Step 1: Open a fresh private or incognito window
A private window starts with no existing cookies or session data, which reduces the amount of sensitive information in the recording.
Step 2: Open browser DevTools
- Open the page where the problem occurs.
- Open DevTools (F12 or right-click > Inspect).
- Go to the Network tab.
- Check Preserve log if the problem involves navigation across pages.
Step 3: Clear any existing entries
Click the clear button in the Network tab to remove any pre-existing entries.
Step 4: Reproduce the problem
Perform only the actions needed to reproduce the issue. Avoid logging into unrelated accounts, opening other tabs, or browsing other sites.
Step 5: Export the HAR
- Right-click the request list and choose Save all as HAR with content (Chrome/Edge) or Save All As HAR (Firefox).
- Save the
.harfile.
Step 6: Sanitize before sharing
Even a minimal HAR can contain cookies and tokens. Always inspect and sanitize the file before sending it.
Method 3: Use a dedicated HAR sanitization tool
Several tools are designed specifically to sanitize HAR files. They can automatically remove or redact common sensitive fields.
Browser-based sanitizers
Some online tools can redact cookies, authorization headers, and other sensitive values automatically. However, be cautious:
- Online tools may upload your HAR file to a server.
- Automatic redaction may miss custom headers or body fields.
- Always verify the output before sharing.
Local tools
If you prefer not to upload the file, use a local tool or script:
- Open the HAR file in a text editor.
- Search for sensitive keywords.
- Replace values with
[REDACTED]. - Save the cleaned file.
Limitations
- Automatic redaction is not perfect. Always verify the output.
- Some tools remove too much and break the file structure.
- Some tools remove too little and leave sensitive data behind.
What sensitive data to look for in a HAR file
When sanitizing a HAR file, check these locations for sensitive values:
Request headers
| Header | What it may contain |
|---|---|
Cookie | Session IDs, authentication cookies |
Authorization | Bearer tokens, basic auth credentials |
X-API-Key | API keys |
X-Auth-Token | Authentication tokens |
X-CSRF-Token | CSRF tokens |
Origin | Internal origin URLs |
Referer | Internal page URLs |
Request body
| Field type | What it may contain |
|---|---|
| Form fields | Usernames, passwords, personal data |
| JSON payloads | Account details, payment data, tokens |
| Uploaded files | File contents and metadata |
Query string
| Parameter type | What it may contain |
|---|---|
token | Access tokens |
session | Session identifiers |
key | API keys |
id | User or account IDs |
Response headers
| Header | What it may contain |
|---|---|
Set-Cookie | New cookies set by the server |
Location | Internal redirect URLs |
Response body
| Content type | What it may contain |
|---|---|
| HTML | Personal data, account info |
| JSON | Account details, payment data, tokens |
| Images | Screenshots or captured content |
What if the HAR file is too large to sanitize?
HAR files can be very large, especially for pages with many resources or large response bodies.
1. Remove irrelevant requests
If the support issue is about a specific API call, remove requests for images, stylesheets, scripts, and fonts that are not related to the problem.
2. Strip response bodies
If the support team only needs to see the requests and headers, remove the response bodies. This can dramatically reduce the file size and remove a lot of sensitive data at the same time.
3. Record a shorter session
If the file is too large to handle, record a shorter session that reproduces only the specific issue.
4. Use a viewer with size limits
A viewer that enforces browser-safety limits can help you avoid loading a file that is too large to handle safely.
How to open and sanitize a HAR file on Windows
On Windows, options include:
- Browser-based viewer: Open the HAR Viewer in Edge, Chrome, or Firefox. No installation required.
- Text editor: Open the
.harfile in Notepad, VS Code, or another editor to search and replace sensitive values. - Browser DevTools: Reopen the HAR in the Network tab to inspect it before sharing.
For a quick inspection on Windows, a browser-based viewer is usually the fastest option.
How to open and sanitize a HAR file on Mac
On Mac, options include:
- Browser-based viewer: Open the HAR Viewer in Safari, Chrome, Edge, or Firefox. No installation required.
- Text editor: Open the
.harfile in TextEdit, VS Code, or another editor to search and replace sensitive values. - Browser DevTools: Reopen the HAR in the Network tab to inspect it before sharing.
For a quick inspection on Mac, a browser-based viewer is usually the fastest option.
How to open and sanitize a HAR file on iPhone or Android
On mobile, HAR capture is less common, but you may receive a HAR file to review. Options include:
- Browser-based viewer: Open the HAR Viewer in your mobile browser. No installation required.
- Text editor: Some mobile text editors can open large JSON files, but this is not practical for very large HAR files.
For a quick inspection on mobile, a browser-based viewer is usually the fastest option.
HAR sanitization checklist
Before sending a HAR file to support, check these items in order:
- Inspect the file in a viewer. Confirm it is valid and review the request list.
- Search for cookies. Remove or redact all
CookieandSet-Cookieheaders. - Search for authorization headers. Remove or redact
Authorization,X-API-Key,X-Auth-Token, and similar headers. - Search for passwords. Check request bodies for
password,secret,token, and similar fields. - Search for personal data. Check response bodies for names, emails, phone numbers, and account details.
- Check query strings. Remove tokens, session IDs, and other sensitive parameters from URLs.
- Remove irrelevant requests. Keep only the requests related to the support issue.
- Strip response bodies if not needed. This reduces size and removes sensitive content.
- Verify the cleaned file. Reopen it in a viewer and confirm no sensitive data remains.
- Share only the sanitized copy. Never send the raw HAR file.
Is it safe to open a HAR file in an online viewer?
HAR files are among the most sensitive file types you can share, because they can contain your entire browser session.
For standard viewing, FileViewerHub processes supported HAR file contents locally in your browser rather than uploading the file to FileViewerHub servers.
You should still:
- Use a device you trust.
- Avoid opening files from unknown sources.
- Sanitize the file before sharing it with anyone.
- Be aware that even a sanitized HAR file may contain URLs or metadata that reveal internal systems.
- Never share a raw HAR file in a public forum, issue tracker, or chat.
Limited technical diagnostics may be processed when a viewer fails, but diagnostic logging should exclude filenames and file contents.
HAR viewer vs manual editing: which should you use?
Use a HAR viewer when your main goal is:
- Quick inspection of requests and responses
- Identifying sensitive data before sharing
- Verifying the file is valid
- Checking timing and status codes
- Opening a file without installing a tool
Use manual editing when you need:
- Fine-grained control over what is removed
- Bulk search-and-replace across the entire file
- Removing specific requests by ID or URL
- Custom redaction patterns
Use a dedicated sanitization tool when you need:
- Automatic redaction of common sensitive fields
- Batch processing of multiple HAR files
- Integration with a CI/CD or testing pipeline
The tools solve different problems. A HAR viewer does not need to replace manual editing to be useful; it can help you understand the file and identify what needs to be removed before you share it.


