A HAR file (HTTP Archive) is a JSON recording of every request your browser made while a page was open — each URL, its headers, how long it took, and often the response itself. Support teams ask for one when they need to see what actually happened on your machine. It is also one of the most sensitive files you can email, and almost nobody says so.
A HAR is a single JSON object with a log containing an array of entries, one per request, in the order the browser made them. Each entry holds:
| request | Method, full URL, the query string broken out, every request header, cookies, and postData if anything was sent. |
| response | Status code, every response header, Set-Cookie values, the MIME type, sizes, and the body if the export included content. |
| timings | How long each phase took, in milliseconds. |
| startedDateTime | When the request began, which is how a viewer reconstructs the waterfall. |
| serverIPAddress, connection | Which server answered and which TCP connection was reused. |
The format is a W3C draft that never became a standard, which is why exports differ slightly between browsers. Every viewer worth using tolerates that.
Network tab → the gear icon at the right → Save All As HAR.
Enable the Develop menu in Settings → Advanced, open the Web Inspector's Network tab, then Export.
Opening it in a text editor tells you almost nothing: a minute of browsing is megabytes of JSON. Use something that shows one row per request.
Whatever you use, read it in this order: filter to the failing request, check its status, then its response headers, then its timings. Most investigations end at the status code and the first header.
Every entry has a timings object, in milliseconds. -1 means "does not apply".
| blocked | Queued in the browser, usually waiting for a free connection. Large numbers mean too many parallel requests to one host. |
| dns | Name lookup. Only on the first request to a host. |
| connect / ssl | TCP and TLS setup. ssl is counted inside connect. |
| send | Writing the request. Big only when uploading. |
| wait | Time to first byte — the server thinking. This is the number to quote when you report a slow API. |
| receive | Downloading the response body. |
A HAR captures the headers as they were sent, which means it captures your Cookie header, your Authorization bearer token, any api_key in a URL, and the body of the login form you submitted — password included. Anyone holding that file can usually act as you until those credentials expire. Support inboxes are shared, ticket systems are searchable, and attachments outlive the ticket.
HeaderForge sets and removes request and response headers for the sites you choose, unblocks CORS for local testing, and shows which of your rules actually fired — so you can tell a rule that did nothing from a server that ignored it. Free, local only, no account and no analytics.
Get HeaderForge for ChromeMore on this topic: JWT decoder and generator · JWT errors: jwt malformed, invalid signature, jwt expired and more · UUID generator · How to add a custom HTTP header to requests in Chrome