# HAR viewer & token scrubber — no upload

> Open a HAR file to inspect requests, timings, and headers, and scrub auth tokens before sharing — all in your browser. Nothing is uploaded.

Open a HAR (HTTP Archive) file to inspect its requests, timings, headers, and payloads, and scrub authorization tokens and cookies before sharing it. It all runs in the browser with no upload.

HAR files are how you share a network capture with support or teammates — but they're full of auth tokens and cookies. Viewing and scrubbing one locally lets you diagnose the issue and share it without leaking credentials.

For other captured traffic, the PCAP viewer reads packet captures; to scan any text for secrets, the secret scanner.

## How to

1. **Open a HAR.** Drop a .har file exported from your browser's dev tools.
2. **Inspect.** Browse requests, status, timings, and headers.
3. **Scrub & export.** Redact tokens and cookies, then save a safe copy.

## FAQ

### Why scrub a HAR before sharing?

HAR files capture full requests, including Authorization headers, cookies, and tokens — sharing a raw one can leak credentials. The scrubber removes those before you send it.

### What can I inspect in a HAR?

Every captured request: URL, method, status, timing waterfall, headers, and bodies — the same data as the network tab, in a shareable file.

### Is my HAR uploaded?

No. Parsing and scrubbing run in the browser, which is essential since HARs contain secrets.


## Related tools

- [PCAP viewer](https://www.safepaper.app/dev/pcap-viewer)
- [Secret scanner](https://www.safepaper.app/dev/secret-scanner)
- [HTTP client](https://www.safepaper.app/dev/http-client)
- [HTTP headers](https://www.safepaper.app/dev/http-headers)

---

Canonical HTML: https://www.safepaper.app/dev/har-viewer
Markdown: https://www.safepaper.app/dev/har-viewer.md

There is no upload endpoint — your files are processed in this browser tab. Open your network tab and check.
