viewhack

HAR file viewer: see what a network log gives away, and remove it before you send it

A support desk asked you for a HAR file. Drop it here first. You get every request with its status, size and timings, the failures and the slow ones, and a list of the session cookies, Authorization headers, API keys, tokens, JWTs and passwords recorded in it. Save cleaned HAR writes a copy with each of those replaced by [removed by viewhack].

The file is read on your device. It is never uploaded.

What it shows

The file is parsed in a Web Worker, a background thread, which keeps the log and sends the page only what it draws. Measured once in headless Chrome on the site's test server: a generated 44 MB log of 20,000 requests, each with a cookie, opened in about 0.6 seconds, and the page never stopped responding for more than about 0.13 seconds. Saving its cleaned copy, with 20,200 values replaced, took about 0.7 seconds.

What a HAR file gives away

A HAR file is every request a browser tab made while the Network panel was open, written out as JSON. HTTPS protects these values on the way to the server, but the browser records them before encrypting, so they sit in the file as plain text:

Recent versions of Chrome and Edge save a sanitized HAR by default, without Cookie, Set-Cookie and Authorization headers, and offer the full one as "Export HAR (with sensitive data)". Even the sanitized export keeps tokens in URLs, request and response bodies and custom headers, and Firefox and Safari save the whole thing. The support engineer usually needs only the URLs, status codes, timings and error bodies. All of that stays in the cleaned copy.

How to save a HAR file

What it cannot do