Open a .har file to see every request the browser made, how long each took, and — the part most viewers skip — the cookies, tokens and passwords sitting inside it. Then save a redacted copy that is safe to send to support. The file is read in this page and never uploaded; watch the Network tab while you load one.
| # | Method | Status | URL | Type | Size | Time | Carries |
|---|
A HAR is a JSON log written by the browser. Each entry holds the request line, every request and response header, the query string, anything posted, the timings, and — if "Preserve log" was on and the body was text — the response itself. That is why it is so useful for debugging, and why it is dangerous to email around.
| Cookie | Your session. Whoever has it is usually signed in as you until it expires. |
| Authorization | A bearer token or basic credentials, in plain text. |
| Set-Cookie | The server handing out a session, sometimes a long-lived one. |
| postData | Whatever you typed into a form, including the password field. |
| ?token= / ?key= / ?api_key= | Credentials in the URL, which also end up in server logs. |
"Save a redacted copy" above replaces those values with [redacted] and leaves everything a support engineer needs: URLs, statuses, headers, sizes and timings. It is a copy — your original file is untouched.
Chrome or Edge: open DevTools with F12, go to Network, tick Preserve log, reproduce the problem, then right-click any row and choose Save all as HAR with content. To leave response bodies out, choose Save all as HAR instead.
Firefox: Network tab, then the gear icon, Save All As HAR.
Safari: enable the Develop menu, open the Web Inspector's Network tab, then Export.
HeaderForge sets and removes request and response headers for the sites you choose, unblocks CORS for local testing, and shows which of your rules actually fired — so you can tell a rule that did nothing from a server that ignored it. Free, local only, no account and no analytics.
Get HeaderForge for Chrome