/

cURL Command Builder

Processed Client Side

Build a cURL command from a simple form — set the method, URL, headers, and body, then copy the ready-to-run command.

Request
cURL command
GET
curl -L 'https://api.example.com/v1/users' \
  -H 'Content-Type: application/json' \
  -H 'Authorization: Bearer TOKEN'

Bookmark this tool now — skip the search next time you need it.

About cURL Command Builder

This tool runs entirely in your browser. Whatever you paste is processed on your own device and is never uploaded, logged, or sent to any server.

Build a cURL command from a form instead of remembering the flags. Pick the HTTP method, type the URL, add headers as key/value rows, paste a request body, and the finished command is assembled live and ready to copy into a terminal. It covers the options people actually reach for — following redirects, showing response headers, skipping certificate verification, requesting compressed responses — and quotes the body correctly so a JSON payload containing spaces or quotes does not fall apart when the shell gets hold of it. Useful for turning an API call you are reading about into one you can actually run, and for producing a reproducible command to paste into a bug report.

Key features

  • All seven common HTTP methods: GET, POST, PUT, PATCH, DELETE, HEAD, and OPTIONS
  • Headers as editable key/value rows you can add and remove, prefilled with Content-Type and Authorization
  • Request body field with correct shell quoting, so JSON payloads survive the copy to a terminal
  • Follow redirects (-L) for endpoints that 301 to their real location
  • Include response headers (-i) when you need to inspect status and headers, not just the body
  • Insecure (-k) for local development against a self-signed certificate
  • Compressed, to request and transparently decode a gzipped response
  • Command updates live as you edit any field, with one-click copy
  • Runs entirely in your browser — the tool builds text and never sends your request anywhere

How to use it

  1. Choose the HTTP method and enter the endpoint URL.
  2. Add the headers you need as key/value rows, and remove any you do not.
  3. Paste a request body if the method takes one.
  4. Toggle the options — follow redirects, include headers, insecure, compressed.
  5. Copy the generated command and run it in your terminal.

Tips & common mistakes

  • This tool writes the command, it does not send the request. Nothing is called until you run the command yourself, which is what makes it safe to build a request against production.
  • Replace the token in the Authorization header before sharing a command. Pasting a working cURL command into a ticket is one of the most common ways real credentials leak.
  • Only use insecure (-k) against local development certificates. It disables certificate verification entirely, so it defeats the protection TLS exists to provide.
  • Include headers (-i) is what you want when debugging a redirect, a caching problem, or a CORS failure — the answer is almost always in the response headers rather than the body.
  • If a POST returns 415 Unsupported Media Type, the Content-Type header does not match what you actually sent. That is the first thing to check.
  • Most browsers can do the reverse: right-click a request in the network panel and choose Copy as cURL to capture a call you have already made, including its cookies.
  • To actually send the request and see the response, rather than just build the command, use the REST API Tester.
  • Need the same request as Python, JavaScript, or another language instead of a shell command? Convert it with cURL to Code Converter.
  • Need to build or break down the query string itself? Use the Query String Parser.

Related tools

Browse all 9 Web / API tools

Frequently asked questions

9

Fill in the method, URL, headers, and body in the form and the tool assembles a correctly quoted cURL command you can copy straight into your terminal. No cURL flag memorisation needed.

Yes. All values are single-quoted and embedded single quotes are escaped, so the command is safe to paste into bash, zsh, and other POSIX shells.

-L follows redirects, -i includes the response headers in the output, -k allows insecure (self-signed TLS) connections, and --compressed requests and decodes a gzip/brotli response.

No. It only builds the command text — nothing is called until you run it yourself in a terminal. That is what makes it safe to assemble a request against a production endpoint.

Only after you replace the Authorization header. Pasting a working cURL command into a ticket or a chat is one of the most common ways real tokens leak.

Only against local development servers using a self-signed certificate. It disables certificate verification completely, which defeats the protection TLS exists to provide, so it should never appear in a command you run against production.

Open your browser network panel, right-click the request, and choose Copy as cURL. That captures the real headers and cookies, which you can then edit here.

The Content-Type header does not match the body you actually sent. Sending JSON with a Content-Type of text/plain, or the reverse, is the usual cause.

The -i flag includes the response headers in the output alongside the body. Verbose mode (-v) additionally shows the request headers and the TLS handshake, which is more detail than you usually want.