cURL Converter & HTTP Request Builder
Sent from your browser: the API must allow CORS, and browsers drop headers like Cookie and User-Agent.
Query params
Headers
Auth
curl 'https://jsonplaceholder.typicode.com/posts/1'
Requests you send or save appear here. They stay in this browser.
How it works
Paste a cURL command in the box at the top and press Import. The easiest source is your browser: in DevTools, open the Network tab, right-click a request and choose Copy as cURL. Both the bash and the cmd variants work, and so do commands you wrote by hand, with single quotes, double quotes, $'...' strings and lines broken with a backslash, a caret or a backtick. The command is split into method, URL, headers and body, and every field becomes editable.
What the importer reads. `-X` or `--request` sets the method. `-H` adds a header. `-d`, `--data`, `--data-raw`, `--data-binary` and `--data-urlencode` set the body; several of them are joined with `&`, as curl does. A body with no `-X` makes the request a POST, and a body with no Content-Type gets application/x-www-form-urlencoded, again as curl does. `--json` sets a JSON body with its two headers. `-u user:pass` becomes a Basic Authorization header, `-A` a User-Agent, `-e` a Referer, `-b` a Cookie. `-G` moves the data into the query string, `-I` sends a HEAD. `-F` form fields are turned into urlencoded fields, because a file upload from your disk cannot be reproduced in a web page. Flags that do not change the request, such as `-L`, `-k`, `-s`, `-v` and `--compressed`, are dropped.
Building a request from scratch. Pick the method (GET, POST, PUT, PATCH, DELETE, HEAD or OPTIONS), type the URL, add header rows and write a body. The Query params table lists the parameters of the URL decoded, one per row: edit a value, add a row or remove one and the URL is rewritten with the encoding done for you, so `a&b` becomes `a%26b`. Typing in the URL updates the table the other way. The Auth selector adds an Authorization header for you: Bearer token, or Basic from a username and password (encoded as Base64 of user:pass). An imported Authorization header lands in that selector, so a token is edited in one place. Format JSON pretty-prints the body with two-space indentation and tells you when it does not parse.
Code in five languages. The Code panel rewrites the request as cURL, JavaScript fetch, axios, Python requests or HTTPie, and updates as you type. When the Content-Type is JSON, fetch gets a `JSON.stringify({...})` body, axios gets a plain object and Python gets a `json=` payload with true, false and null turned into True, False and None. The cURL output quotes every value for a POSIX shell, so a URL or a body with an apostrophe in it survives the round trip. Copy puts the current tab on your clipboard.
Sending it. Send runs the request with the browser's fetch and shows the status code, the time it took, the response headers and the body, pretty-printed if it is JSON. The request goes from your browser straight to the API, not through a server of ours. That has two consequences. The API has to allow cross-origin requests (CORS): public APIs usually do, internal and admin APIs often do not, and then the page tells you the request failed and suggests running the cURL in a terminal. And browsers refuse to let a page set some headers, including Cookie, User-Agent, Referer and Host, so those are silently left out of a sent request even though they appear in the generated code.
History. Every request you send, and any you save with the Save button, goes into a History list of the last 30. Click one to load it back into the builder. The list lives in this browser's localStorage and nowhere else, which also means a saved request keeps its Authorization header there: clear the history on a shared computer.
Frequently Asked Questions
How do I convert a cURL command to fetch or Python?
- Paste it in the import box, press Import and pick the fetch or Python tab in the Code panel. The command is parsed into method, URL, headers and body, and each tab rewrites that request: `fetch()` with a headers object for JavaScript, `requests.request()` for Python, plus axios and HTTPie. Copy takes the code of the tab you are on.
Is this a Postman alternative?
- For single requests, yes: build a GET or POST with headers, auth and a JSON body, send it, read the response, and keep a history. It is not a full Postman replacement. There are no collections, environments, variables or test scripts, and requests run from the browser, so the API has to allow CORS. For an API that does not, copy the cURL and run it in a terminal.
Why does Send fail with a CORS error?
- Because the API does not allow requests from other websites. A web page can only read a response from another origin when the server answers with an Access-Control-Allow-Origin header that permits it. Postman and curl are not web pages, so they ignore CORS; this tool cannot. Copy the cURL and run it in a terminal, or test against an API that sends the header.
How do I get a cURL command from Chrome or Firefox?
- Open DevTools (F12), go to the Network tab, reload the page, right-click the request you want and choose Copy, then Copy as cURL. Chrome on Windows offers Copy as cURL (cmd) and Copy as cURL (bash); both import here. Firefox has Copy as cURL in the same menu.
Why are my Cookie and User-Agent headers not sent?
- Browsers forbid web pages from setting them. Cookie, User-Agent, Referer, Host, Origin and a few others are on the fetch specification's list of forbidden header names, so the browser drops them from a request the page sends. They still appear in the generated code, which is what you want when you run it outside the browser.
How do I send a JSON POST request with curl?
- Use `curl -X POST https://api.example.com/items -H 'Content-Type: application/json' -d '{"name":"Ada"}'`, or on curl 7.82 and later the shorter `curl --json '{"name":"Ada"}' https://api.example.com/items`. `-X POST` is optional, since `-d` implies POST. Build the request here and the cURL tab writes the command with the quoting done for you.
How do I add a Bearer token or Basic auth?
- Pick Bearer token or Basic in the Auth selector. Bearer adds `Authorization: Bearer <token>`; Basic takes a username and password and adds `Authorization: Basic` followed by the Base64 of user:pass, the same header curl builds from `-u user:pass`. Base64 is encoding, not encryption, so treat a Basic header as the password itself.
Are my requests and tokens stored anywhere?
- Only in your browser. Importing, editing and generating code make no network request at all; Send makes exactly one, to the URL you typed. The History list is saved in this browser's localStorage, including any Authorization header, and is never uploaded. Use Clear history when you are done on a shared machine.
curl flags the converter reads
What each flag does to the request, and what the importer does with it.
| Flag | Meaning | In the builder |
|---|---|---|
| -X, --request | HTTP method | Method selector |
| -H, --header | Add a request header | Header row |
| -d, --data, --data-raw, --data-binary | Request body; implies POST | Body, repeats joined with & |
| --data-urlencode | URL-encoded body field | Body |
| --json | JSON body plus Content-Type and Accept headers | Body and two header rows |
| -F, --form | multipart/form-data field | Urlencoded body field (files not supported) |
| -u, --user | Basic authentication | Auth: Basic |
| -A, --user-agent | User-Agent header | Header row (not sent by browsers) |
| -e, --referer | Referer header | Header row (not sent by browsers) |
| -b, --cookie | Cookie header | Header row (not sent by browsers) |
| -G, --get | Send the data as a query string | Appended to the URL |
| -I, --head | HEAD request | Method: HEAD |
| -L, -k, -s, -v, --compressed | Follow redirects, skip TLS check, silent, verbose, accept gzip | Ignored |
Flag meanings from the curl manual (curl.se/docs/manpage.html). --json needs curl 7.82.0 or later.