SafeShare — Sanitize HAR files & logs before sharing
Local-first · Zero uploads

Sanitize debugging data
before you share it.

Drop a HAR file or paste logs. SafeShare detects Authorization headers, cookies, API keys, tokens, and personal information — lets you review every change — and produces a sanitized copy that's still useful for support, AI chatbots, or public issues. Everything runs in your browser.

Drop a .har file here

HAR files from Chrome, Firefox, Edge, Safari DevTools. Parsed structurally — cookies, headers, query params, and post data are inspected individually.

safeshare/diff-view.js
- Authorization: Bearer eyJhbGciOi...
- Cookie: sessionid=abc123def456...
+ Authorization: [REDACTED_BEARER_TOKEN]
+ Cookie: [REDACTED_COOKIE]
  Status: 200 OK
  Content-Type: application/json
- "email": "john.doe@example.com"
+ "email": "[REDACTED_EMAIL]"
  "role": "admin"
12 secrets foundScan complete
sanitized.harDownloaded locally

Scanning for sensitive information...

02 / Review Detections

Control exactly what gets removed.

0
High confidence
0
Personal data
0
Potentially sensitive
Originalbefore
SafeShare versionafter

      
Export sanitized copy:

Local-processing verification

SafeShare wraps fetch, XMLHttpRequest, sendBeacon, and WebSocket during processing and counts every outbound call. This is what actually happened during your last scan:

○ No scan run yet.
03 / FAQ

Common questions about HAR files & logs

Real questions developers and IT teams ask before sending debugging data to support, vendors, or AI tools.

Does a HAR file contain passwords? +

It can. A HAR file recorded by browser DevTools captures every HTTP header, cookie, query parameter, and request body — including Authorization headers, Set-Cookie response headers, session cookies, and form posts. If a request carried a Bearer token, an API key, or a password field, it is in the HAR.

Is it safe to send a HAR file to support? +

Only after sanitizing. Vendors like Cloudflare, Atlassian, and Datadog explicitly tell users to redact cookies and Authorization headers before sending HAR files. SafeShare removes those fields while preserving the request/response structure that support engineers actually need.

How do I remove cookies from a HAR file? +

Cookies live in request.cookies, response.cookies, and inside the Cookie / Set-Cookie headers. SafeShare walks the HAR JSON tree, finds every cookie value, and replaces it with a placeholder like [REDACTED_COOKIE] — keeping the structure intact so the file still loads in DevTools and HAR viewers.

Can I paste error logs into ChatGPT or Claude? +

You can, but be careful. Stack traces, env dumps, and debug logs routinely contain API keys, JWTs, database URLs, internal hostnames, and customer emails. Run the text through SafeShare first — it flags each match with a confidence level so you decide what stays and what gets redacted.

Does SafeShare upload my HAR file? +

No. All parsing, detection, and redaction happen in your browser. The network monitor at the top of the page counts outbound calls during processing — it stays at zero. There is no backend, no analytics on file content, and no third-party API for redaction.

Scroll to Top