Open a .har file in your browser to inspect requests, headers, timings and a waterfall — and automatically detect & redact secrets (auth tokens, cookies, API keys, passwords, credit cards) before you share it.
▶ Open HAR Sentinel — no install, no login, nothing uploaded
A HAR (HTTP Archive) file is a JSON export of your browser's network traffic — you make one from DevTools → Network → Save all as HAR, usually because a support team asked for it.
The problem: a raw HAR captures everything, including live Authorization headers, session
cookies, API keys, and sometimes passwords or card numbers in request bodies. Emailing a raw HAR can
hand over working credentials to anyone who receives it.
HAR Sentinel opens the file entirely in your browser, shows you exactly what's inside, flags the secrets, and gives you a redacted copy that's safe to share — while keeping the file structurally valid so the support tool on the other end can still open it.
- 🔍 Full HAR viewer — request table, status codes, sizes, per-request timing waterfall, and a detail panel with request/response headers, query string and timings.
- 🔑 Secret detection — JWTs, Bearer/Basic auth, AWS access keys, GitHub/Google/Slack/Stripe/OpenAI-style keys, cookies, private-key blocks, credit-card numbers (Luhn-checked), emails, and sensitively-named headers/params.
- 🧼 One-click redaction — download a sanitized
.harwith every detected secret replaced by[REDACTED-BY-HAR-SENTINEL]. Optional deep scrub of request/response bodies. - 🔒 Verifiably offline — a single static page with zero network calls. Your HAR is read with
the browser's
FileReaderand processed in memory. Turn off Wi‑Fi and it still works. - ⚡ Instant — no build, no account, no tracking. Drag, drop, done.
HAR Sentinel has no backend. There is no server to upload to. You can verify this yourself:
- Read the source — it's ~4 files of plain HTML/CSS/JS in this repo.
- Watch the Network tab while you use it — it stays empty (no XHR, no
fetch, no beacons). - Disconnect from the internet and use it anyway — everything still works.
It's static — clone and open, or serve the folder:
git clone https://github.com/OL-Projects/har-sentinel.git
cd har-sentinel
python3 -m http.server 8000 # then open http://localhost:8000- By key name: headers like
Authorization,Cookie,Set-Cookie,X-Api-Key; query/POST params matchingtoken,api_key,password,secret,signature, etc.; all cookies. - By value pattern: regexes for common credential formats, with a Luhn check so only valid card numbers are flagged (fewer false positives).
- Redaction produces a deep-cloned HAR — your loaded file is never mutated — and replaces only the secret values, leaving structure intact.
Detection is best-effort, not a guarantee. Always eyeball the result before sharing.
Vanilla HTML/CSS/JS. No framework, no dependencies, no build step. Tested with a Node test harness
(node test.js) covering detection, Luhn validation, redaction round-trips, and non-mutation.
Found a secret format it misses, or a false positive? Open an issue or PR — new detection patterns
live in PATTERNS in har-engine.js and are covered by test.js.
MIT — free for any use.
Keywords: har viewer, har file viewer, har analyzer, open har file online, redact har, sanitize har file, remove sensitive data from har, har file security risk, offline har viewer, har viewer github, devtools network export, http archive viewer.