HAR Viewer
Inspect HAR statuses, hosts, timings and headers, with filters and deliberately limited summary exports.
This tool runs entirely in your browser. Your data is never uploaded, never stored, and never leaves your device.
Read a local HAR 1.2 trace, inspect request statuses and supplied timings, and export filtered summaries with URL credentials, queries, headers and bodies omitted.
How to use it
- 1Choose a UTF-8 HAR file up to 5 MiB or paste its JSON and inspect it.
- 2Filter by host, HTTP status or redacted URL text and open a request's details.
- 3Review the active JSON or CSV export preview, then copy or download the filtered summary.
What happens to your data
HAR parsing and filtering happen in this browser without replaying trace URLs or saving history. Summary exports omit all headers, bodies, cookies and URL queries/credentials, but paths and metadata can still contain sensitive information; review before sharing.
Last updated October 2026
Open a saved HAR 1.2 network trace and inspect its requests locally. See the method, redacted URL, HTTP status, supplied duration and response body size; filter by host, status group or text in the method and redacted URL. Selected request details show supplied timing phases and header text, with sensitive header values omitted. Copy or download the filtered request summary as JSON or CSV.
This workflow is useful when a teammate gives you a browser network export or when an API call fails among many successful requests. It is a reader for an existing trace. It does not visit the recorded sites, replay requests, capture a new trace or test an API endpoint. The result depends on the fields actually recorded by the exporting browser or application.
How it works
Choose a UTF-8 HAR file or paste its JSON and select Inspect HAR. File input is inspected after reading; pasted input is inspected only when you press the button. A leading UTF-8 byte-order mark is accepted. The input limit is 5 MiB, or 5,242,880 UTF-8 bytes, and the request limit is 5,000 entries. Objects, arrays, required fields, absolute request URLs, date-time offsets and numeric ranges are checked before any result is displayed. Individual header, cookie, query or posted-parameter arrays are limited to 200 items; header names to 256 characters, values to 65,536 and request URLs to 8,192. Exceeding a limit rejects the trace rather than silently truncating it.
The supported format is HAR 1.2. Request and response structures, content metadata and required send, wait and receive timings must be present and have valid types. Optional timing phases can be missing or -1; they are shown as unknown or not applicable. Required send, wait and receive phases must be non-negative. Header field names and values follow this reader's strict subset: invalid names, embedded line breaks or null bytes are rejected. The tool is not a comprehensive HAR schema validator and does not validate vendor-specific fields. Cache information may be absent when unavailable.
HTTP status 0 is displayed as no HTTP status. It is not counted as a successful HTTP response or as an HTTP error. The 4xx and 5xx groups are counted as HTTP errors; an unexpected response within those groups still requires investigation in the original application. A response bodySize of -1 is unknown, while zero is an actual supplied zero. The known-body total excludes unknown values and response headers. It is not a complete network transfer total. Decoded content size is shown separately in request details.
Request durations are taken from each entry's time field. The summary adds those durations for the currently filtered requests. Requests can overlap, so this sum is not page load time. Timing details are displayed as supplied, without reconstructing missing measurements. SSL negotiation can already be included in connect time, so the viewer does not add all the visible phases together or assert that their sum agrees with the supplied duration. This is an inspection of recorded facts, not an independent performance measurement.
Recorded URLs and header values are rendered as text. There are no live links, external previews, embedded response documents or request replay controls. Bodies, cookie arrays and posted data are not displayed in the result. Header names associated with authorization, cookies, API keys, tokens, passwords, credentials, sessions and CSRF/XSRF have their values replaced by an omission marker. Ordinary header values remain visible as local text and may themselves be sensitive.
The export is deliberately a fresh summary, not a rewritten HAR archive. It includes request number, recorded start time, method, redacted URL, host, status, duration, known or unknown body size, decoded-content size and MIME label. URL credentials, query strings and fragments are removed. Non-HTTP/WebSocket URLs are omitted from the exported URL column. All headers, cookie arrays, request and response bodies, creator text and unknown source fields are excluded from summaries. CSV uses unknown for missing body sizes and protects formula-like text for common spreadsheet viewers. JSON uses null for unknown body sizes.
The export preview reflects the active filters and selected format. It displays up to 16,000 characters; Copy and Download include the full filtered summary. The request table shows the first 100 matches, while the totals and exports include every matching request within the 5,000-entry limit. Filtering or editing clears the selected detail, and editing the source removes the old result. No trace history, file or result is saved in browser storage.
Redaction is not a promise that a report is safe to share. Hostnames, URL paths, MIME text, methods and timing metadata can still identify people or internal resources. Review the preview and full downloaded summary before sending it to someone else. This tool does not certify the absence of all secrets, produce a sanitized HAR for reimport or infer permission to share a trace.
Worked example: Two overlapping requests with one unknown body size
- Input
- GET https://example.com/api/items?token=example-secret → 200, 120 ms, 90 body bytes GET https://static.example.com/missing.png → 404, 40 ms, bodySize -1
- Result
- Requests: 2 HTTP errors: 1 Known response body bytes: 90; unknown sizes: 1 Sum of request durations: 160 ms Exported first URL: https://example.com/api/items
Use HAR example loads this synthetic trace. The 160 ms is a sum, not a page-load measurement. The token query, authorization value and response body are omitted from the summary.
Common use cases
- Find 4xx and 5xx responses in a saved browser trace
- Focus on requests to a particular API host
- Inspect supplied wait and receive phases without replaying traffic
- Separate unknown body sizes from recorded zero-byte responses
- Export only filtered request summaries for a developer discussion
- Review a trace containing URL queries without putting those queries into the summary
Frequently asked questions
How do I export a HAR from Chrome?+
Open the Network panel in Chrome DevTools, reproduce the issue and use Export HAR (sanitized). Chrome also supports exports with sensitive data, which require extra care. A sanitized browser export is still worth reviewing because paths, query values or response content can contain private information.
Does opening a trace contact the recorded websites?+
No. The viewer reads the JSON already in the local file or pasted field. URLs and header text are inert; it does not fetch assets, load response HTML or replay requests. The results do not prove that the endpoints are reachable now.
Why is a response size unknown rather than zero?+
The source may record bodySize as -1 when the measurement is unavailable. The viewer preserves that distinction: the row says Unknown, JSON exports null and CSV exports unknown. Only known body sizes contribute to the displayed byte total.
Is the sum of request durations the page load time?+
No. Several requests may run simultaneously, so adding their individual durations double-counts overlapping time. This viewer labels the sum and does not present it as navigation time, user experience or a Core Web Vitals measurement.
Are my request headers included in the exported summary?+
No headers are included in exports. The local detail view keeps ordinary header text and replaces sensitive header values with an omission marker. Bodies, cookie arrays, posted parameters and unknown extension fields are also excluded from the JSON and CSV summaries.
Can I reimport the downloaded report as a HAR?+
No. The download is a request summary with a deliberately small set of fields. It omits structures needed for a complete HAR and is intended for inspection or reporting, not replay or reimport into a network debugger.
Why does my trace fail validation?+
The document may be invalid JSON, a different HAR version, missing required fields or outside the reader's limits. The error names the relevant request or field when possible. Very large traces and unusual multiline headers need a different reader or a smaller export; the viewer does not guess or repair them.
Does filtering change the download?+
Yes. Host, status and text filters determine the summary totals and the downloaded request list. The table is limited to its first 100 matches, but the download contains all matches within the input limit. An empty result produces a valid empty summary rather than retaining older requests.
Can I share the redacted report without checking it?+
Review it first. Removing URL queries, credentials, headers and bodies reduces some common exposures, but secrets can be embedded in a path or other retained text. The report is not guaranteed to contain no sensitive information, and your permission to share the source is a separate decision.
Related tools
HTTP Status Codes & Log Analyzer
Look up HTTP status codes and analyze response lines or access logs with counts and explanations.
HTTP Header Inspector & Compare
Inspect and compare pasted HTTP response headers locally, keeping repeated fields and response blocks.
JSON Formatter & Validator
Format, validate, and minify JSON with exact line errors, a searchable tree, and private processing.
URL Parser
Break a URL into protocol, host, path, and query parameters.