HAR Sentinel

HAR viewer & secret redactor — offline, in your browser

Open a .har file to inspect every request, header, timing and a waterfall — then automatically find and redact secrets (auth tokens, cookies, API keys, passwords, credit cards) before you send it to support or a colleague. 100% client-side. Your HAR never leaves this tab.

🛡️

Drag & drop a .har file

or

Nothing is uploaded. Processing happens entirely on your device — you can disconnect from the internet and it still works.

What is a HAR file — and why redact it?

A HAR (HTTP Archive) file is a JSON export of your browser's network activity. You create one from Chrome/Edge/Firefox DevTools → Network → Save all as HAR, usually because a support team asked for it to debug an issue.

The catch: a HAR captures everything — including Authorization headers, session cookies, API keys, and sometimes passwords or payment details in request bodies. Sending a raw HAR can hand over live credentials. HAR Sentinel scans for these and produces a redacted copy that's safe to share, while keeping the file structurally valid so support tools can still open it.

Privacy: verifiably offline

HAR Sentinel is a single static page with no backend and no network calls. Your file is read with the browser's FileReader and processed in memory. Don't take our word for it — read the source, open DevTools and watch the Network tab (it stays empty), or turn off your Wi‑Fi and use it anyway.

What it detects

JWTs, Bearer/Basic auth, AWS keys, GitHub/Google/Slack/Stripe/OpenAI-style keys, cookies, private-key blocks, credit-card numbers (Luhn-checked), emails and more. Detection is best-effort — always review before sharing.