# PCAP packet viewer — no upload

> Open a .pcap/.pcapng capture to inspect packets, protocols, and conversations in your browser. Nothing is uploaded — the capture stays on your device.

Open a packet capture (.pcap/.pcapng) to browse packets, protocols, and conversations. It's parsed entirely in the browser, so the capture is never uploaded.

Packet captures are sensitive — they can contain anything on the wire — so uploading one to inspect it is risky. A browser viewer lets you browse packets, protocols, and conversations without that exposure.

For application-level captures, the HAR viewer reads HTTP archives; to decode a protobuf payload inside a packet, the protobuf decoder.

## How to

1. **Open a capture.** Drop a .pcap or .pcapng file.
2. **Browse packets.** See the packet list with protocols and endpoints.
3. **Inspect.** Drill into a packet's layers and fields.

## FAQ

### What formats does it read?

Standard libpcap (.pcap) and pcapng (.pcapng) captures from tools like Wireshark and tcpdump, parsed locally into a browsable packet list.

### Why view a PCAP locally?

Captures can contain sensitive traffic and credentials. Parsing in the browser means that network data never leaves your device.

### Is my capture uploaded?

No. All parsing happens in the browser, so the .pcap stays local.


## Related tools

- [HAR viewer + scrub](https://www.safepaper.app/dev/har-viewer)
- [Protobuf decoder](https://www.safepaper.app/dev/protobuf-decoder)
- [IPv4 / IPv6](https://www.safepaper.app/dev/ip-convert)
- [Common ports](https://www.safepaper.app/dev/common-ports)

---

Canonical HTML: https://www.safepaper.app/dev/pcap-viewer
Markdown: https://www.safepaper.app/dev/pcap-viewer.md

There is no upload endpoint — your files are processed in this browser tab. Open your network tab and check.
