a HAR records headers, cookies and full bodies·tokens inside stay sensitive until revoked·files of 134 companies exposed in one 2023 incident·sanitize locally, then attach

Why every support team asks for a HAR

HAR stands for HTTP Archive: one JSON file holding every request a browser tab made, with URLs, status codes, request and response headers, timings and, depending on the export, the complete bodies. For a support engineer it is the difference between “checkout is broken” and seeing the exact POST that returned a 403 with a readable error body. Okta, Zendesk, Atlassian, Salesforce and practically every SaaS vendor have a help-center page walking you through the export.

The format was designed for performance debugging around 2009, and it shows. Completeness was the whole point, privacy was nobody’s requirement, and the spec never made it past a W3C draft. What everyone exchanges today is a frozen editor’s draft that browsers implement by convention.

None of that makes the request unreasonable. It makes the file worth two minutes of your attention before it leaves your machine.

What the file records while you reproduce the bug

Open a HAR in a text editor and search for cookie. Everything the browser sent during the recording is in there, verbatim:

  • Session cookies, in the Cookie request header and in every Set-Cookie response. A session is a login in portable form, which is the same reason the storage question matters in where to store JWTs.
  • Authorization headers with bearer tokens or basic credentials, on every API call the page made.
  • Request bodies, meaning every form you submitted during the recording. Reproduce a login problem and the capture contains the password you typed, in plain text.
  • Response bodies, which for an admin dashboard means the customer data the API returned while you clicked around.
  • Query strings, where plenty of apps still put API keys, reset tokens and signed URLs.

A useful mental model: the file is exactly as sensitive as the most sensitive thing the tab did while you recorded. For a quick look at a broken marketing page, that is nothing. For a billing dashboard, it is a lot.

The incident that made vendors add a warning box

The clearest demonstration of what an unsanitized HAR upload is worth happened to Okta in late 2023. An unauthorized party gained access to Okta’s support case management system and downloaded attachments from recent tickets. Those attachments were HAR files, uploaded by customers doing exactly what the support flow asked of them, and some still contained valid session data. Okta’s root-cause write-up puts the blast radius at files associated with 134 customers, with five customer environments affected as a result. Cloudflare, 1Password and BeyondTrust were among those who noticed suspicious activity, raised it, and contained it.

The detail worth remembering is how ordinary every step was. Customers followed documented support instructions. The support system did its job of storing attachments. Each file simply carried more than the ticket needed, and nobody in the chain had stripped it.

Since then the ecosystem has moved a little. Chrome DevTools now defaults to a sanitized HAR export that omits cookies and sensitive headers, and vendor help pages grew warning boxes. The response bodies, form values and query strings are still on you.

Sanitizing a HAR before you attach it

Sanitizing means editing the JSON, and doing it by hand in a 40 MB file is miserable, so use a tool and then spot-check. Our HAR analyzer parses the file in your browser tab, shows every request as a waterfall, and its one-click sanitizer removes cookies, auth headers and token-carrying query parameters before you download the cleaned copy. Nothing is uploaded anywhere, which for this particular file type is the whole point.

Whatever tool you use, check three places afterwards, because they are where sanitizers miss:

  • Search for password, token, secret and your own email address. Form submissions and JSON request bodies keep them under postData.
  • Skim the response bodies of API calls. Customer lists and profile endpoints return exactly what they say.
  • Look at query strings for signed URLs, which are self-contained access grants with their expiry in the URL.

If the ticket is about one failing request, delete every other entry. A HAR with three requests answers the question just as well as one with three hundred, and there is nothing to leak from entries that are not in the file.

If the file already left your machine

No panic, just housekeeping, in this order:

  • End the recorded session server-side. Use the “sign out everywhere” or active-sessions page of the service. Deleting the cookie in your own browser does nothing for the copy in the file.
  • Rotate any API keys that appeared in headers or query strings, the same discipline as after a committed .env file: rotate first, investigate second.
  • Ask support to delete the attachment once the ticket is resolved. Reputable vendors do this on request, and several now purge attachments automatically after a retention window.
  • Consider what the response bodies contained. If customer personal data was in there, your own privacy obligations may apply to the copy you just shared.

Expired tokens shrink the problem but do not end it, because the data in the file does not expire.

Capturing less in the first place

The cheapest sanitizing is a capture that never contains the secret. Record in a fresh private window where you log in with a test account instead of your admin user. Start the recording right before the failing action instead of browsing for five minutes first. And if the bug reproduces on a page that works without login, record it logged out.

One habit covers most of it: treat “export HAR” like “screenshot of my screen”, and glance at what is on screen before you share.

Before you hit attach

Why does support ask for a HAR file?

Because it answers in one attachment what would otherwise take a week of back and forth. The file shows every request the browser made, with status codes, timings, headers and bodies, so an engineer sees the failing call and its exact error instead of a description of it. That is also why the format records so much. It was built for performance debugging, where completeness is the point.

Does a HAR file contain personal data?

Usually yes. Beyond credentials it holds every API response the page received while recording, which for an admin view can mean customer names, addresses and order data. Under GDPR that makes the file itself personal data, with everything that follows for storing and sharing it.

What was the Okta HAR file incident?

In October 2023, an unauthorized party accessed Okta’s support case system and downloaded customer-uploaded HAR files, some of which still contained valid session data. Okta’s own write-up says files associated with 134 customers were accessed and five customer environments were affected, among them Cloudflare and 1Password, who detected and contained it quickly. It is the reason most vendors now tell you to sanitize a HAR before uploading.

Should I log out before recording a HAR?

It does not help much, because the capture includes whatever session the browser holds while you reproduce the problem. The reliable cleanup is the other way around: record, send the sanitized file, then end the session from the account’s active-sessions page so the server no longer accepts it.

How do I end a session I think is exposed?

Use the account’s “sign out everywhere” or active-sessions feature, which invalidates sessions on the server. Changing the password triggers this in many apps, but not all, so check the sessions list afterwards. For an exposed API key there is no session list: rotate the key.

Is it safe to attach a HAR file to a Jira or GitHub issue?

Only after sanitizing. Everyone with read access to the tracker can read the file, and tickets get copied, quoted and mirrored.

Do sanitized HAR exports still leak anything?

They can. Chrome’s sanitized export strips cookies and auth headers, but values in URL query strings, request bodies and custom headers survive, and so does every form value you typed while recording, including a password typed on a login page. A sanitizer is a first pass, not a guarantee, which is why the file deserves a manual look before it leaves your machine.

How long does a HAR file stay sensitive?

Until every token inside has expired or been revoked, which can mean weeks. The data in response bodies stays sensitive forever.