Free tool
Local HAR sanitizer
Remove sensitive HAR fields locally and review a redacted network recording before exporting it for a bug report.
Remove private fields before sharing a network recording
Choose a HAR 1.2 file to process in your browser. No signup is needed. File contents stay on this device; recorded requests are never replayed.
HAR 1.2, up to 20 MiB and 10,000 requests. Choose a shorter capture if a limit is exceeded.
What the exported HAR keeps
The export keeps HTTP methods, status codes, numeric sizes, request timings, timestamps, and recognized media types. It removes request and response bodies, credentials, cookies, queries, fragments, page titles, comments, cache data, and browser extension fields. Headers are limited to a normalized Content-Type without parameters.
Unsupported fields are omitted. Unknown methods become OTHER, unrecognized media types become application/octet-stream, and invalid timestamps become the Unix epoch. This export supports debugging, but cannot reproduce the original session.
Unsupported URLs and URLs longer than 2,048 characters are replaced with a neutral address, or omitted for redirects. This also bounds URLs that expand during encoding.
Review URLs locally before sharing
URL paths and hostnames can contain names, account identifiers, or tokens. The sanitizer cannot infer every sensitive value and does not guarantee that a recording is safe to share. Review all retained URLs locally; use a fresh capture with test data if sensitive paths remain.
A builder’s checkout trace
Reproduce a checkout failure with a test account, export a HAR, and load it here. Check that the failed POST still has its status and timing. Review the remaining /checkout path and redirect, then download the sanitized HAR for the GitHub issue alongside reproduction steps. Never attach the original recording by mistake.
An agency’s staging handoff
Capture a slow staging form with synthetic client data. Remove cookies and response bodies here, then check every retained hostname and path for a client name or account ID. If either remains sensitive, record again with neutral test data. Share the reviewed export with the tested release, browser, and expected result.
Examples for your team
Builder example
A builder removes authorization headers, cookies, query values, and response bodies before sharing a checkout trace.
Start your 14-day free trialAgency / QA example
An agency reviews remaining URL paths for client names or identifiers before exporting a sanitized staging trace.
Start your 14-day free trial