WoluTools

Developer Tools

Remove cookies and tokens from a HAR file before sharing

Upload a HAR file and choose what to hide: headers, cookies, URL and form fields, or all bodies. You get a cleaned HAR, a list of every replaced value and a request timing table.

or drop it here

Free account needed · HAR or JSON, up to 100,000 requests

  • Stored encrypted on our server in Austria
  • Result expires after 24 hours
  • No request is replayed
  • Not used to train AI models

No file at hand? See what changes in a sample file

Free: 3 jobs a day, files up to 10 MB Pro: up to 200 jobs a day, €12.99/month or €89.99/year

Sample run · 2 requestsWhat changes in the fileSettings: session added as extra key name, bodies set to Remove all

Request 1 · GET · 200 · 125 ms

url: https://example.test/orders?session=secret

url: https://example.test/orders?session=%5BREDACTED%5D

Authorization: Bearer secret

Authorization: [REDACTED]

Request 2 · POST · 503 · 2400 ms

postData.text: card=secret

postData.text: [REMOVED]

content.text: failure

content.text: [REMOVED]

Redactions
4
Removed bodies
2
Findings
HTTP 503, slow request (2400 ms)

redacted.har · redaction-manifest.csv · waterfall.csv · findings.csv · manifest.json

What is replaced by default

Any header, cookie, query parameter, form field or URL parameter with one of these names gets the value [REDACTED]. Names are matched without regard to case.

Add your own names under Additional sensitive key names, for example session or x-tenant-id. With Remove all, request and response bodies become [REMOVED].

How it works

  1. 1

    Add the HAR

    Export it from the browser's network panel and drop it above. One file per job.

  2. 2

    Choose extra keys and bodies

    Add header or parameter names your API uses, then keep or remove all bodies.

  3. 3

    Check and download

    Read the redaction list and findings, then download the package.

Clean a HAR capture before you share it

What you upload

A HAR file, or its JSON, with up to 100,000 requests. A browser capture often holds cookies, session tokens and customer data. Values are matched by key name and replaced. No request is replayed against your servers, and your original capture is not changed.

What comes back

redaction-manifest.csv lists every replacement with request number, location and key name. waterfall.csv has one row per request with method, host, status, time and response size, so you can sort for slow or failed calls in a spreadsheet. findings.csv flags error responses (status 400 and above) and requests slower than 2 seconds.

What it will not catch

Matching works on names, so a token stored under an unrelated key inside a body stays in place unless you remove all bodies. The tool does not claim to find every secret. Read the findings and skim the file before it leaves your team.

Questions before you run it

Which fields are redacted by default in a HAR file?

Standard authentication and session headers, cookies, query parameters and form fields are matched by name. Each replacement is listed in redaction-manifest.csv so you can see exactly what changed.

Can I redact a custom header or parameter my API uses?

Yes. Add its name under Additional sensitive key names and it is treated like the built-in list. Matching works on key names, so a token buried inside a JSON body under an unrelated key will not be caught.

Does it remove request and response bodies?

That is your choice: Remove all strips every body, Keep bodies leaves them in place. Removing bodies is the safer setting when the capture includes API responses containing customer records.

Is the redacted HAR safe to attach to a support ticket?

It removes the fields it names and reports residual risk in findings.csv, but universal secret removal is not claimed. Read the manifest and skim the file yourself before sending it outside your team.

What does the waterfall CSV show?

One row per request with timing and status, so you can sort for slow or failed calls in a spreadsheet. Nothing is replayed and no request is re-issued against your servers.