> ## Documentation Index
> Fetch the complete documentation index at: https://docs.twinbay.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Record a HAR file in Chrome

> Record the provider's web app so we can build a twin of an API Twinbay does not cover yet

If you need a twin for a provider Twinbay does not cover yet, we may ask you for a HAR file. A HAR (HTTP Archive) file records every request a browser tab makes, with its headers, body, response and timing. You record yourself using the provider's own web app, and we build the twin from the requests and responses in the file.

## Before you record

Sign in to a sandbox or test account. Everything the provider's app loads while you record ends up in the file, including the records on screen.

Decide which flows your code depends on, and plan to do each one. A twin covers what the recording shows, so if your code creates an invoice, sends it and voids it, record all three. Add a failure your code handles, such as a required field left empty or a duplicate record. We can only reproduce an error response we have seen.

<Steps>
  <Step title="Open the provider's web app">
    In Chrome, sign in to the provider's web app and go to the screen where your first flow starts.
  </Step>

  <Step title="Open DevTools">
    Right-click anywhere on the page and select **Inspect**. You can also press `⌥ ⌘ I` on macOS, or `Ctrl Shift I` on Windows and Linux.

    <Frame>
      <img src="https://mintcdn.com/twinbay/ei4sETwSjOe4JqhE/images/har/inspect.png?fit=max&auto=format&n=ei4sETwSjOe4JqhE&q=85&s=aa9a8c40a74e1b68297fa04b3515b93e" alt="Chrome context menu with Inspect highlighted" width="400" data-path="images/har/inspect.png" />
    </Frame>
  </Step>

  <Step title="Open the Network tab and turn on Preserve log">
    Click the **Network** tab, then check **Preserve log**. With it on, the recording survives page reloads and moves to another page.

    <Frame>
      <img src="https://mintcdn.com/twinbay/ei4sETwSjOe4JqhE/images/har/network-preserve-log.png?fit=max&auto=format&n=ei4sETwSjOe4JqhE&q=85&s=9a3884c9cda5d4ce101c9c6dab7b0588" alt="The Network tab selected, then Preserve log checked" width="1600" height="612" data-path="images/har/network-preserve-log.png" />
    </Frame>
  </Step>

  <Step title="Start recording and reload">
    Check that the record button at the top left of the Network tab is red. If it is grey, click it. Click the clear button next to it to empty the list, then reload the page.

    <Frame>
      <img src="https://mintcdn.com/twinbay/ei4sETwSjOe4JqhE/images/har/record.png?fit=max&auto=format&n=ei4sETwSjOe4JqhE&q=85&s=43d79ba386bb4905f50d12613f45c357" alt="The record button at the top left of the Network tab" width="1600" height="257" data-path="images/har/record.png" />
    </Frame>
  </Step>

  <Step title="Run through your flows">
    Work through each flow you planned. Requests appear in the list as you go. If a list is long enough to have more than one page, go to the next page too, because a twin reproduces the provider's pagination.
  </Step>

  <Step title="Export the HAR file">
    Click the download icon, **Export HAR (sanitized)...**, in the Network toolbar and save the file.

    <Frame>
      <img src="https://mintcdn.com/twinbay/ei4sETwSjOe4JqhE/images/har/export.png?fit=max&auto=format&n=ei4sETwSjOe4JqhE&q=85&s=feddae1612916468f0a1c5580032d95f" alt="The Export HAR (sanitized) button in the Network toolbar" width="1600" height="268" data-path="images/har/export.png" />
    </Frame>
  </Step>

  <Step title="Send it to us">
    Email the `.har` file to [hi@twinbay.ai](mailto:hi@twinbay.ai), or reply to the thread where we asked for it. Name the provider and list the flows you recorded, in order.
  </Step>
</Steps>

## What the file contains

The sanitized export removes cookies and `Authorization` headers, so your session with the provider stays out of the file. Request and response bodies stay in. That covers every record the provider's app loaded or you changed, and any API key or secret the app showed you. Some web apps also send tokens in a body or a custom header, and those stay in too.

<Warning>
  Do not create or reveal API keys in the provider's app while you record. If one appeared on screen, rotate it in the provider's settings after you send the file.
</Warning>

Chrome can also export a HAR file with sensitive data, which keeps cookies and `Authorization` headers. Use the sanitized export. Building a twin never needs your session with the provider.
