// TOOLS · HTTP CLIENT

HAR File Analyzer

Export a HAR from your browser's network tab, drop it here, and see what the page really did: who it talked to, what was slow, what was big, and which cookies and headers were set carelessly. The file is read in this tab and nowhere else.

HAR FILE
Drop a .har file here
Chrome and Edge: DevTools › Network › ⬇ Export HAR. Firefox: Network › ⚙ › Save All As HAR. Safari: Web Inspector › Network › Export. HAR files contain cookies and sometimes tokens, which is exactly why this runs locally.
ON YOUR PHONE · HTTP CLIENT

A HAR shows what a browser did. The app's HTTP Client lets you send the request yourself from your phone, on the hotel or office Wi-Fi where the problem happens, and grades the response headers on the spot. Get RECON for iPhone — one-time purchase, no account, nothing leaves the device.

What is a HAR file

HTTP Archive is the JSON format every browser uses to export its network tab: one entry per request with the URL, method, status, headers, cookies, sizes, timing phases and, unless you strip it, the response bodies. Support teams ask for one when "the page is slow" or "the login fails" because it is a complete recording of what the browser saw. That completeness is also why a HAR should not be pasted into an online tool: it usually contains session cookies and bearer tokens that would let whoever runs that tool act as you.

First party versus third party

Every host is compared against the site of the first request. Anything on another registrable domain is third party: analytics, ad networks, tag managers, fonts, CDNs, chat widgets. The by-host table shows how many requests and bytes each one took, which is usually where the answer to "why is this page heavy" is. A page that loads from thirty hosts pays DNS, TCP and TLS setup for each one, and that shows in the phase totals.

The findings section

Cookies set without Secure can be sent over plain HTTP; without HttpOnly they are readable by any script on the page; without SameSite they ride along on cross-site requests. A first-party HTML response without Strict-Transport-Security leaves the first visit open to downgrade. A Server or X-Powered-By header with a version number tells anyone scanning the site exactly which advisory to look up. None of these are exploits on their own. They are the things a reviewer writes up first because they are cheap to fix and easy to prove from a capture.

Reading the timings

Each entry breaks its time into blocked, DNS, connect, SSL, send, wait and receive. A high wait is the server; a high receive is the payload or the link; high DNS and connect across many entries means too many hosts or no keep-alive. The slowest-requests table sorts by total time and shows wait alongside it so you can tell the two apart at a glance.

// OTHER TOOLS
Subnet Calculator
IPV4 · IPV6 · CIDR
MAC Vendor Lookup
OUI · MA-L · MA-M · MA-S
Certificate & CSR Decoder
X.509 · PKCS#10 · PEM · DER
DNS Leak Test
VPN · RESOLVER · PRIVACY
DNS Benchmark
CLOUDFLARE · GOOGLE · QUAD9 · 8 RESOLVERS
Port Lookup
TCP · UDP · WHAT IS PORT…
What Is My IP
PUBLIC IP · FINGERPRINT