HAR viewer & secret redactor — offline, in your browser
Open a .har file to inspect every request, header, timing and a waterfall —
then automatically find and redact secrets (auth tokens, cookies, API keys,
passwords, credit cards) before you send it to support or a colleague.
100% client-side. Your HAR never leaves this tab.
Drag & drop a .har file
or
Nothing is uploaded. Processing happens entirely on your device — you can disconnect from the internet and it still works.
| Method | Status | URL | Size | Time | Waterfall |
|---|
What is a HAR file — and why redact it?
A HAR (HTTP Archive) file is a JSON export of your browser's network activity. You create one from Chrome/Edge/Firefox DevTools → Network → Save all as HAR, usually because a support team asked for it to debug an issue.
The catch: a HAR captures everything — including
Authorization headers, session cookies, API keys, and sometimes passwords or
payment details in request bodies. Sending a raw HAR can hand over live credentials.
HAR Sentinel scans for these and produces a redacted copy that's safe to share,
while keeping the file structurally valid so support tools can still open it.
Privacy: verifiably offline
HAR Sentinel is a single static page with no backend and no network calls.
Your file is read with the browser's FileReader and processed in memory.
Don't take our word for it — read the source,
open DevTools and watch the Network tab (it stays empty), or turn off your Wi‑Fi and use it anyway.
What it detects
JWTs, Bearer/Basic auth, AWS keys, GitHub/Google/Slack/Stripe/OpenAI-style keys, cookies, private-key blocks, credit-card numbers (Luhn-checked), emails and more. Detection is best-effort — always review before sharing.