Skip to content

Repository files navigation

🛡️ HAR Sentinel — offline HAR viewer & secret redactor

Open a .har file in your browser to inspect requests, headers, timings and a waterfall — and automatically detect & redact secrets (auth tokens, cookies, API keys, passwords, credit cards) before you share it.

▶ Open HAR Sentinel — no install, no login, nothing uploaded

100% client-side no upload MIT


Why HAR Sentinel?

A HAR (HTTP Archive) file is a JSON export of your browser's network traffic — you make one from DevTools → Network → Save all as HAR, usually because a support team asked for it.

The problem: a raw HAR captures everything, including live Authorization headers, session cookies, API keys, and sometimes passwords or card numbers in request bodies. Emailing a raw HAR can hand over working credentials to anyone who receives it.

HAR Sentinel opens the file entirely in your browser, shows you exactly what's inside, flags the secrets, and gives you a redacted copy that's safe to share — while keeping the file structurally valid so the support tool on the other end can still open it.

Features

  • 🔍 Full HAR viewer — request table, status codes, sizes, per-request timing waterfall, and a detail panel with request/response headers, query string and timings.
  • 🔑 Secret detection — JWTs, Bearer/Basic auth, AWS access keys, GitHub/Google/Slack/Stripe/OpenAI-style keys, cookies, private-key blocks, credit-card numbers (Luhn-checked), emails, and sensitively-named headers/params.
  • 🧼 One-click redaction — download a sanitized .har with every detected secret replaced by [REDACTED-BY-HAR-SENTINEL]. Optional deep scrub of request/response bodies.
  • 🔒 Verifiably offline — a single static page with zero network calls. Your HAR is read with the browser's FileReader and processed in memory. Turn off Wi‑Fi and it still works.
  • ⚡ Instant — no build, no account, no tracking. Drag, drop, done.

Privacy — don't take our word for it

HAR Sentinel has no backend. There is no server to upload to. You can verify this yourself:

  1. Read the source — it's ~4 files of plain HTML/CSS/JS in this repo.
  2. Watch the Network tab while you use it — it stays empty (no XHR, no fetch, no beacons).
  3. Disconnect from the internet and use it anyway — everything still works.

Run it locally

It's static — clone and open, or serve the folder:

git clone https://github.com/OL-Projects/har-sentinel.git
cd har-sentinel
python3 -m http.server 8000   # then open http://localhost:8000

How detection/redaction works

  • By key name: headers like Authorization, Cookie, Set-Cookie, X-Api-Key; query/POST params matching token, api_key, password, secret, signature, etc.; all cookies.
  • By value pattern: regexes for common credential formats, with a Luhn check so only valid card numbers are flagged (fewer false positives).
  • Redaction produces a deep-cloned HAR — your loaded file is never mutated — and replaces only the secret values, leaving structure intact.

Detection is best-effort, not a guarantee. Always eyeball the result before sharing.

Tech

Vanilla HTML/CSS/JS. No framework, no dependencies, no build step. Tested with a Node test harness (node test.js) covering detection, Luhn validation, redaction round-trips, and non-mutation.

Contributing

Found a secret format it misses, or a false positive? Open an issue or PR — new detection patterns live in PATTERNS in har-engine.js and are covered by test.js.

License

MIT — free for any use.


Keywords: har viewer, har file viewer, har analyzer, open har file online, redact har, sanitize har file, remove sensitive data from har, har file security risk, offline har viewer, har viewer github, devtools network export, http archive viewer.

About

Offline HAR viewer & secret redactor — open a .har file in your browser to inspect requests, headers, timings and a waterfall, and automatically detect & redact secrets (tokens, cookies, API keys, passwords, cards) before sharing. 100% client-side, nothing uploaded.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages