Home/Security & Digital Trust/Developer Security & Safe Sharing
Developer Security & Safe Sharing

HAR File Secret Scanner and Safe-Sharing Sanitizer

Inspect a HAR file locally before sharing it with support, vendors, developers, contractors, issue trackers or AI assistants. Review masked evidence, preview transformations and generate a separate sanitised HAR.

Local privacy workspace

Awaiting HAR intake

Choose a HAR file to inspect requests, headers, cookies, query values and supported bodies locally before sharing.

Requests inspected

--

Hosts contacted

--

Sensitive values

--

High-risk findings

--

Affected requests

--

Unresolved findings

--

Host summary

Evidence and transformation preview

All inspection, sanitisation preview, validation and report generation run locally in your browser.

What a HAR file contains

A HTTP Archive file can record pages, requests, responses, URLs, headers, cookies, timings, redirect targets and sometimes request or response bodies. It is useful diagnostic evidence, but can contain more than a support recipient needs.

Why HAR files may expose credentials and private data

Cookies, Authorization headers, API keys, signed URLs, passwords, emails and account references may be captured alongside normal diagnostics. Internal hostnames, private IP addresses and proprietary paths can also be commercially sensitive without being credentials.

How to sanitise a HAR before sharing it

Inspect the local file, review each masked finding and selected transformation, compare the safe preview, generate a separate copy and review it manually. The original file is never modified.

What the HAR Safe-Sharing Inspector checks

The local rules inspect supported request and response URLs, headers, cookies, query values, JSON and text bodies, server addresses and internal infrastructure patterns. Findings are evidence for review, not proof that a value is active or universally sensitive.

Request versus response sanitisation

Request data may include submitted credentials or form values. Response data can contain customer records, returned tokens or rendered diagnostic content. Both directions need review; removing all bodies can reduce support value.

Cookies, authorization headers and API keys

The tool recognises common authentication headers, Cookie and Set-Cookie representations and common API-key header names. Evidence stays masked, with no control to reveal complete detected secrets.

Sensitive query parameters and signed URLs

Query strings often persist in tickets and logs. The inspector identifies commonly sensitive parameter names and signed values cautiously while preserving non-sensitive query structure where selected.

Request and response body privacy

Supported textual JSON, URL-encoded, XML-like and plain text bodies are inspected within size safeguards. Binary, opaque and large content is not silently trusted: it remains an unresolved review item.

Internal hostnames and infrastructure details

Localhost, RFC1918 and link-local addresses, .local domains, single-label hosts and development-looking names are reported without DNS, WHOIS, location or ownership calls.

Why local browser processing matters

A HAR can contain live access material. This tool has no HAR upload endpoint, no request replay, no remote scanner, no browser storage and no captured HTML rendering or script execution.

What sanitisation cannot guarantee

Sanitisation reduces accidental exposure but cannot guarantee that every sensitive, identifying or proprietary value has been detected. Review the generated HAR before sharing it.

How to generate a HAR in Chrome, Edge and Firefox

Open browser developer tools, use the Network panel, reproduce the issue, then export a HAR from that panel. Browser options and defaults vary; review whether sensitive data was included before using any export.

Frequently asked questions

What sensitive data can a HAR file contain?

HAR files can contain request and response URLs, headers, cookies, query values, timings and bodies. Those records can include credentials, personal-data indicators, internal hosts and proprietary diagnostics.

How do I sanitise a HAR file before sharing it?

Choose the HAR locally, inspect the masked finding register, review selected transformations, validate the generated copy, then manually review that separate sanitised HAR before sharing it.

Does Chrome already remove sensitive data from HAR exports?

Chrome may export a sanitised HAR by default, but sensitive data can still be deliberately exported. Browser-level sanitisation does not necessarily identify every custom header, query field, body field or proprietary value.

Can a HAR file contain cookies and authorization tokens?

Yes. HAR entries can include Cookie and Set-Cookie headers, cookie arrays, Authorization headers and other custom authentication headers.

Does MicroIntent upload or replay my HAR file?

No. Inspection, preview, validation and reports run locally in the browser. The tool does not upload, store, replay or execute HAR requests.

Can the tool inspect request bodies?

Yes. It inspects supported JSON, URL-encoded and textual request bodies within a local size safeguard, while unsupported or oversized bodies remain explicitly unresolved.

Can it inspect response bodies?

Yes. It inspects supported textual response content and reports encoded, binary, missing or oversized content cautiously without rendering captured HTML.

Does it remove API keys and query tokens?

Recognised API-key headers and sensitive query names can be replaced in a previewed separate HAR copy. The original file is not modified.

Can it hide internal hostnames and private IP addresses?

It identifies local, private, development and internal-looking infrastructure patterns without external DNS or ownership lookup, and can replace hosts or values in the generated copy.

Will the sanitised HAR still work for technical support?

Selected redaction preserves request order, methods, status codes, timings and harmless diagnostics where practical. Removing bodies or requests can reduce support value, so review the preview for the recipient's needs.

Can I download a sanitised HAR and professional report?

After local validation, the tool provides a sanitised HAR, redaction manifest, print/PDF layout, genuine DOCX, Markdown, JSON evidence, and request and finding CSV registers.

Does sanitisation guarantee that the file is safe to share?

No. Sanitisation reduces accidental exposure but cannot guarantee that every sensitive, identifying or proprietary value has been detected. Review the generated HAR before sharing it.

Related local security tools

Continue reviewing developer evidence with live MicroIntent tools.