What is a HAR file?

A HAR file (HTTP Archive) is a JSON recording of every request your browser made while a page was open — each URL, its headers, how long it took, and often the response itself. Support teams ask for one when they need to see what actually happened on your machine. It is also one of the most sensitive files you can email, and almost nobody says so.

On this page
  1. What is actually inside one
  2. How to export a HAR file
  3. How to open and read one
  4. Reading the timings
  5. Why you should redact it first

What is actually inside one

A HAR is a single JSON object with a log containing an array of entries, one per request, in the order the browser made them. Each entry holds:

requestMethod, full URL, the query string broken out, every request header, cookies, and postData if anything was sent.
responseStatus code, every response header, Set-Cookie values, the MIME type, sizes, and the body if the export included content.
timingsHow long each phase took, in milliseconds.
startedDateTimeWhen the request began, which is how a viewer reconstructs the waterfall.
serverIPAddress, connectionWhich server answered and which TCP connection was reused.

The format is a W3C draft that never became a standard, which is why exports differ slightly between browsers. Every viewer worth using tolerates that.

How to export a HAR file

Chrome or Edge

  1. Open DevTools with F12 and go to Network.
  2. Tick Preserve log so a redirect or reload does not wipe what you captured.
  3. Reproduce the problem.
  4. Right-click any row → Save all as HAR with content, or Save all as HAR to leave response bodies out (smaller, and much less sensitive).

Firefox

Network tab → the gear icon at the right → Save All As HAR.

Safari

Enable the Develop menu in Settings → Advanced, open the Web Inspector's Network tab, then Export.

How to open and read one

Opening it in a text editor tells you almost nothing: a minute of browsing is megabytes of JSON. Use something that shows one row per request.

Whatever you use, read it in this order: filter to the failing request, check its status, then its response headers, then its timings. Most investigations end at the status code and the first header.

Reading the timings

Every entry has a timings object, in milliseconds. -1 means "does not apply".

blockedQueued in the browser, usually waiting for a free connection. Large numbers mean too many parallel requests to one host.
dnsName lookup. Only on the first request to a host.
connect / sslTCP and TLS setup. ssl is counted inside connect.
sendWriting the request. Big only when uploading.
waitTime to first byte — the server thinking. This is the number to quote when you report a slow API.
receiveDownloading the response body.

Why you should redact it first

A HAR captures the headers as they were sent, which means it captures your Cookie header, your Authorization bearer token, any api_key in a URL, and the body of the login form you submitted — password included. Anyone holding that file can usually act as you until those credentials expire. Support inboxes are shared, ticket systems are searchable, and attachments outlive the ticket.

Before you send one: open it, find every request carrying a credential, replace the values, and send the copy. Our HAR viewer does exactly that in your browser — it flags the requests that carry credentials and saves a redacted copy that keeps the URLs, statuses, header names and timings a support engineer actually needs.
Debugging the headers themselves?

HeaderForge sets and removes request and response headers for the sites you choose, unblocks CORS for local testing, and shows which of your rules actually fired — so you can tell a rule that did nothing from a server that ignored it. Free, local only, no account and no analytics.

Get HeaderForge for Chrome

More on this topic: JWT decoder and generator · JWT errors: jwt malformed, invalid signature, jwt expired and more · UUID generator · How to add a custom HTTP header to requests in Chrome