Skip to main content
Decoding Fiddler SAZ Files: Format, Tools & Automation
Advanced Techniques7 min read

Decoding Fiddler SAZ Files: Format, Tools & Automation

Learn the SAZ file format internals, how to inspect it without Fiddler, and access HTTP(S) sessions programmatically using .NET, Python, and PowerShell — essential for advanced fiddler debugging and automation.

Share:

Fiddler’s .saz files are the de facto standard for saving and sharing HTTP(S) traffic captures — but their opaque binary structure often hides rich opportunities for programmatic analysis, CI/CD integration, and custom reporting. If you’ve ever needed to extract request headers from hundreds of captures, validate API response schemas across test runs, or correlate Fiddler logs with backend metrics, understanding the SAZ format isn’t optional — it’s essential.

This guide walks through the internals of the SAZ file format, demonstrates how to open, inspect, and reconstruct it without Fiddler, and shows how to access its contents programmatically using .NET, Python, and PowerShell. Whether you're building automated regression checks, auditing HTTPS decryption artifacts, or extending your fiddler debugging workflow, this is your reference for treating SAZ as structured data — not just a black-box archive.

What Is a SAZ File — Really?

A .saz file is a ZIP archive with a custom internal structure — not encrypted, but deliberately organized to support Fiddler’s session model. Unlike raw PCAPs or HAR files, SAZ preserves all Fiddler-specific metadata: breakpoints, comments, inspectors, custom flags, and even decrypted HTTPS payloads (provided HTTPS decryption was enabled during capture).

Internally, a SAZ file contains:

  • SessionArchive.xml: The master index — lists every SessionID, timestamps, URLs, status codes, and inspector tabs.
  • Raw/: Subfolders (Raw/000001/, Raw/000002/, etc.) containing request.txt, response.txt, and optional response.bin (for binary responses like images or PDFs).
  • Custom/: Stores user-added notes, flags, and custom columns (e.g., X-Test-Run-ID).
  • FiddlerRoot.cer: The root certificate used for HTTPS decryption — embedded only if the capture included decrypted TLS traffic.

💡 Pro Tip: Rename any .saz file to .zip and open it with 7-Zip or Windows Explorer. You’ll immediately see the structure — no special tooling required for inspection.

How to Open and Inspect SAZ Without Fiddler

While Fiddler remains the gold standard for interactive analysis, many teams need to parse SAZ outside the GUI — especially in headless environments like CI pipelines or security audit scripts.

Step-by-step manual inspection

  1. Rename & extract: mv capture.saz capture.zip && unzip capture.zip -d saz-unpacked
  2. Read the index: cat saz-unpacked/SessionArchive.xml | head -n 20 reveals session count, version, and top-level metadata.
  3. Find a specific request: Search for <SessionID>12345</SessionID> in SessionArchive.xml, then navigate to Raw/00012345/request.txt.
  4. Decode binary responses: If response.bin exists, use file saz-unpacked/Raw/00012345/response.bin to identify content type, then decode accordingly (e.g., base64 -d for text-based encodings).

This approach supports rapid validation — for example, confirming that all POST /api/v1/login requests include an X-Auth-Version header across 200 captured sessions.

Programmatic Access with .NET (C#)

FiddlerCore and the official FiddlerCore.dll expose native APIs to read SAZ files in-process. This is ideal for C#-based test frameworks or internal tooling.

Prerequisites

  • Install NuGet package: FiddlerCore4 (v4.6.2023+ recommended for .NET 6+ compatibility)
  • Reference using Fiddler;

Minimal working example

var sessions = SessionImporter.LoadSessionsFromFile(@"C:\logs\capture.saz");
foreach (var oSess in sessions)
{
    Console.WriteLine($"{oSess.id} {oSess.RequestMethod} {oSess.fullUrl} → {oSess.responseCode}");
    
    // Extract decrypted response body (if HTTPS decryption was active)
    if (!string.IsNullOrEmpty(oSess.GetResponseBodyAsString()))
    {
        var json = JsonSerializer.Deserialize<JsonElement>(oSess.GetResponseBodyAsString());
        Console.WriteLine($"→ API status: {json.GetProperty("status").GetString()}");
    }
}

⚠️ Troubleshooting tip: If GetResponseBodyAsString() returns null or garbled bytes, verify the SAZ was saved after HTTPS decryption completed — and that the original Fiddler instance trusted the FiddlerRoot.cer certificate. For more on securing and validating your fiddler proxy setup, see our dedicated guide.

Python Access via `fiddler-saz` Library

Python developers can leverage the community-maintained fiddler-saz package (v0.3.1+) — a pure-Python parser that reads SAZ without requiring .NET or Fiddler installation.

Installation & usage

pip install fiddler-saz
from fiddler_saz import SAZFile

saz = SAZFile("capture.saz")
for session in saz.sessions:
    if session.request.method == "POST" and "/graphql" in session.request.url:
        # Parse GraphQL operation name from request body
        try:
            body = session.request.body.decode('utf-8')
            op_name = json.loads(body).get('operationName', 'unknown')
            print(f"GraphQL op: {op_name} → {session.response.status_code}")
        except (UnicodeDecodeError, json.JSONDecodeError):
            pass  # Skip binary or malformed payloads

✅ Bonus: This library correctly handles compressed responses (gzip/deflate), base64-encoded bodies, and even reconstructs full Host + Origin headers from Fiddler’s internal cache — features missing in naive ZIP+XML parsers.

PowerShell for Quick Forensics & Reporting

PowerShell shines for ad-hoc analysis and DevOps scripting — especially when integrated into Azure DevOps or GitHub Actions.

Example: List all 5xx responses and their URLs

Add-Type -AssemblyName System.IO.Compression.FileSystem
$path = "C:\logs\capture.saz"
$tempDir = Join-Path $env:TEMP "saz-$(Get-Random)"
New-Item -ItemType Directory -Path $tempDir | Out-Null

[System.IO.Compression.ZipFile]::ExtractToDirectory($path, $tempDir)

[xml]$index = Get-Content "$tempDir\SessionArchive.xml"
$sessions = $index.SessionArchive.Session

$sessions | Where-Object { $_.ResponseCode -ge 500 } | ForEach-Object {
    $reqPath = Join-Path $tempDir "Raw\$($_.SessionID.PadLeft(6,'0'))\request.txt"
    if (Test-Path $reqPath) {
        $url = Select-String -Path $reqPath -Pattern "^GET |^POST |^PUT " -First 1
        [PSCustomObject]@{
            SessionID = $_.SessionID
            URL = ($url.Line -split '\s+')[1]
            StatusCode = $_.ResponseCode
            Timestamp = $_.StartTime
        }
    }
} | Format-Table -AutoSize

🔧 Pro tip: Wrap this in a reusable function (Get-FiddlerSAZErrorReport) and publish it to your internal PowerShell Gallery. Combine with Invoke-RestMethod to auto-post findings to Slack or Jira.

Automating SAZ Validation in CI/CD

Integrating SAZ parsing into your pipeline transforms passive logging into active quality control. Here’s how real teams do it:

Use case: Regression testing for auth token propagation

  • Capture SAZ during E2E tests with Fiddler running as system proxy.
  • After test run, download auth-flow.saz artifact.
  • Run Python script verifying:
    • Every Authorization: Bearer <token> header matches the expected JWT structure.
    • No Set-Cookie contains HttpOnly without Secure in HTTPS contexts.
    • All /api/** endpoints return Content-Type: application/json.

Toolchain recommendations

  • GitHub Actions: Use windows-latest runner + PowerShell core, or ubuntu-latest + Python + fiddler-saz.
  • Azure Pipelines: Leverage UseDotNet@2 task to load .NET SDK, then invoke C# console app.
  • Docker: Build lightweight Alpine image with unzip + xmllint + jq for shell-based validation.

This level of automation turns your fiddler debugging sessions into auditable, versioned assertions — critical for compliance-heavy domains like fintech or healthcare.

Troubleshooting Common SAZ Issues

Symptom Root Cause Fix
SessionArchive.xml missing or empty SAZ saved before capture finished or while Fiddler was unstable Always click File > Save > All Sessions after stopping capture. Avoid Ctrl+S mid-capture.
response.bin present but response.txt empty Response was streamed or chunked without full buffering Use Fiddler’s Inspectors > TextView tab before saving — forces full body capture.
Decrypted HTTPS bodies appear as gibberish Certificate trust wasn’t established on the machine where SAZ was created Reinstall FiddlerRoot.cer via Tools > Options > HTTPS > Actions > Export Root Certificate to Desktop, then import manually.
Python fiddler-saz throws KeyError: 'Content-Encoding' Corrupted or partial SAZ (e.g., network interruption during save) Validate ZIP integrity: zip -T capture.saz. Discard if errors found.

For deeper diagnostics, enable Fiddler’s log viewer (Help > Debug Logs) and search for SAZSave entries. This reveals exactly which sessions were serialized — and why some may have been skipped.

Conclusion: From Archive to Asset

The SAZ file format is far more than a convenience wrapper — it’s a portable, self-contained record of your entire HTTP debugging context. By moving beyond manual inspection and embracing programmatic access, you unlock repeatable validation, cross-tool correlation, and infrastructure-aware analysis.

Key takeaways:

  • SAZ is a ZIP archive — inspect it with standard tools before writing custom code.
  • Use .NET + FiddlerCore for deep integration in C# ecosystems and full access to decrypted HTTPS payloads.
  • Prefer fiddler-saz in Python for lightweight, cross-platform parsing — especially in CI.
  • Leverage PowerShell for fast forensic sweeps and DevOps scripting without external dependencies.
  • Always validate SAZ integrity and HTTPS decryption trust before assuming payload fidelity.

Mastering SAZ access elevates your fiddler tutorial journey from reactive troubleshooting to proactive quality engineering. Want to go further? browse Advanced Techniques tutorials for topics like custom FiddlerScript rules, WebSocket replay, and automated certificate pinning bypass. Or contact us if you’re building a SAZ-powered analytics dashboard — we’d love to feature your use case.

For more foundational knowledge on traffic interception and secure configuration, explore our more tutorials section — including deep dives on https decryption and fiddler proxy best practices.

Share:

Related Topics

fiddler tutorialfiddler debugginghttp debuggingfiddler proxyhttps decryption

Get Fiddler Tips & Tutorials

Stay updated with the latest Fiddler tutorials, HTTP debugging guides, request modification tips, and web traffic analysis techniques.

Free forever. New tutorials published daily.

Related Articles