HAR File Analyzer & Sanitizer
See what a page loaded and why it was slow — then clean the file before sending it.
Open a HAR file
Paste HAR text instead
In Chrome or Edge: open DevTools (F12) → Network → reload the page → Export HAR. In Firefox: Network → ⚙ → Save All As HAR. The file is read on your device and never uploaded.
Overview
Requests
| Status | Request | Size | Time | Waterfall |
|---|
Request
Slowest requests
Largest requests
By domain and type
| Domain | Requests | Transferred | Errors |
|---|
| Type | Requests | Transferred | Time |
|---|
Sanitize before sharing
A HAR file contains everything the browser sent and received — including session cookies and tokens that let someone sign in as you. Remove them before sending the file to support.
At least 3 characters each; matched without regard to case.
About the HAR File Analyzer & Sanitizer
A HAR file (HTTP Archive) is a recording of everything a browser loaded for a page: every request and response with its headers, timings, sizes and often the content itself. Support teams ask for one when a site is slow or broken. This tool opens it on your device and shows the requests as a waterfall with each timing phase, filters for errors, types and domains, the slowest and largest requests, and per-domain totals — so you can see what is going on yourself.
Because a HAR file also contains session cookies, authorization headers and tokens that can let someone act as you, the sanitizer writes a copy with those values removed — cookie and header names, timings and sizes stay, so the file is still useful to support — and then checks the result for anything that still looks like a secret.
How to use it
- Export a HAR file: in Chrome or Edge open DevTools (F12) → Network, reload the page, then Export HAR. In Firefox use the Network toolbar menu → Save All as HAR; in Safari, Web Inspector → Network → Export.
- Drop the file here (or choose it). Nothing is uploaded — it is read in your browser.
- Use the filters to find errors, slow requests or one domain; select a request to see its timing breakdown and headers.
- Before sharing the file, choose what to remove under Sanitize before sharing and press Download sanitized HAR.
- Read the check after downloading: it lists anything that still looks like a token, key or password.
Examples
HAR summary (WebInspector 537.36, Test Browser 1.0) 8 requests · 108 kB transferred · 379 kB resources · 1.16 s from first request to last response Status: 1xx 1, 2xx 3, 3xx 1, 4xx 1, 5xx 1, Failed / blocked 1 Page “https://shop.example.com/account”: DOMContentLoaded 450 ms, load 900 ms Failed requests: 401 POST https://api.example.com/v1/login ERR GET https://tracker.example.org/pixel.gif?uid=42 (net::ERR_BLOCKED_BY_CLIENT) 500 GET https://api.example.com/v1/items?access_token=%5BREDACTED%5D&page=2
From the built-in sample file (press “Try a sample file”). Token-like URL parameters are masked in the copied summary too.
Cookie: sid=abc123secret; theme=dark Authorization: Bearer eyJhbGci… https://shop.example.com/home?code=AUTHCODE42&lang=en
Cookie: sid=[REDACTED]; theme=[REDACTED] Authorization: Bearer [REDACTED] https://shop.example.com/home?code=%5BREDACTED%5D&lang=en
Common uses
- Finding out why a page loads slowly: long DNS or TLS setup, slow server responses (waiting time) or large downloads.
- Spotting failed requests — 4xx and 5xx responses, blocked or cancelled requests — and the third-party domains a page depends on.
- Sending a HAR file to a vendor’s support team without handing over your session cookies and tokens.
- Checking what a web app sends to which servers, for privacy or security reviews.
Reading the waterfall
Each bar starts when the request started (relative to the first request) and is split into the phases the HAR 1.2 format records:
- Queued / blocked: waiting for a free connection or behind higher-priority requests.
- DNS lookup and TCP connect: setting up a new connection; reused connections skip both.
- TLS handshake: negotiating encryption (HAR counts it inside connect, so the tool shows it separately).
- Request sent, then Waiting (TTFB): the time until the first byte of the response — mostly server processing time.
- Content download: receiving the response body.
Phases a browser does not record are left out. Transferred is what went over the network (headers plus compressed body); resources is the decoded size of the content. Requests served from the browser cache transfer almost nothing.
What the sanitizer removes
- Cookies: the values in
CookieandSet-Cookieheaders and in the cookie lists. Names and attributes (Path, Secure, SameSite…) stay, which is often what support needs. - Credentials:
AuthorizationandProxy-Authorization(the scheme such as “Bearer” is kept), and any header whose name mentions a token, secret, password, session, CSRF token, API key, credential or signature — such asX-CSRFTokenorOcp-Apim-Subscription-Key. CORS headers are kept. - Tokens in URLs: values of parameters such as
access_token,id_token,code,state,key,sig,PHPSESSIDand anything containing “token”, “secret”, “password”, “session” or “signature” — in the query string, the fragment after#, path parameters such as;jsessionid=, redirect targets, the HTTP/2:pathheader,Location,Refererand URLs inside other text — and passwords inuser:password@URLs. - Bodies and messages: request and response bodies, and the WebSocket and server-sent event messages Chrome records. If you keep the bodies, password and token fields in forms and JSON are still masked.
- JSON Web Tokens anywhere in the file, optionally email addresses, and any words you add.
Timings, sizes, status codes and the rest of each header stay unchanged, and the result is still a valid HAR file that Chrome, Firefox and Safari can import again. Chrome’s own “Export HAR (sanitized)” leaves out the Cookie, Set-Cookie and Authorization headers and the cookie lists (Chrome DevTools); its source code keeps tokens in URLs, other credential headers, request bodies and WebSocket messages.
Limitations
- Files up to 200 MB. Very large captures can be slow on phones; record only the page you need.
- Browsers record different details: Firefox and Safari files may lack the resource type or transferred size, which then show as “Other” or “—”.
- The analyzer lists the request that opened a WebSocket or event stream, not its individual messages (the sanitizer still removes their payloads).
- Sanitizing is pattern-based: it cannot know every secret format your application uses. Read the final check, and add your own words to remove if needed.
Privacy
Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.
Frequently asked questions
Is it safe to share a HAR file?
Not as it comes from the browser: it can contain session cookies, authorization tokens, passwords typed into forms and the content of every page you loaded. Anyone holding a live session cookie may be able to act as you. Sanitize the file first, and share it only with the people who asked for it.
Is my file uploaded?
No. The file is read and analysed by JavaScript in this page; the sanitized copy is created in your browser and saved straight to your device.
What does “Waiting (TTFB)” mean?
Time to first byte: the time between sending the request and receiving the first byte of the response. Long waiting times usually point to slow server-side processing, a slow database query or a distant server, not to your connection.
Why do some requests show status ERR?
They got no response: blocked by an ad blocker or extension, cancelled because the page navigated away, refused by the network or failed DNS. When the browser recorded a reason (such as net::ERR_BLOCKED_BY_CLIENT in Chrome), it is shown under the URL.
Does sanitizing change timings or sizes?
No. Only the values of sensitive fields are replaced with [REDACTED] and bodies are removed, so the waterfall, status codes and sizes in the file stay exactly as recorded.
Can I open the result in browser DevTools?
Yes. Chrome and Edge import a HAR file when you drag it onto the Network panel’s request table or use Import HAR; Firefox and Safari have an Import option in their network tools too.