Developer Tools

API Request Builder

Describe an API call once: method, URL, query parameters, headers, authentication and body. Then pick a language and copy code that sends exactly that request, with error handling and the details each library needs handled correctly.

  • Runs in your browser
  • No sign-up
  • Free to use
Query parameters
Headers
Authentication
Body

    The code is generated in your browser. Tokens and passwords you type here are not sent anywhere.

    How to use API Request Builder

    1. Choose the method and enter the URL of the endpoint.
    2. Add query parameters, headers and the authentication the API expects.
    3. Select a body type and enter the JSON, form fields or text to send.
    4. Pick a language and copy or download the generated code.

    API Request Builder features

    Five targets

    JavaScript fetch, Axios, Python requests, PHP cURL and the cURL command line from one definition.

    Idiomatic output

    Uses json= in Python, JSON.stringify in fetch, json_encode in PHP and FormData or CURLFile for uploads.

    Authentication built in

    Bearer tokens, Basic authentication and API keys in a header or in the URL.

    All body types

    JSON, URL-encoded forms, multipart forms with files, XML and plain text.

    Mistakes flagged

    Invalid JSON, credentials over http://, bodies on GET requests and conflicting headers are pointed out.

    Private

    Everything is generated in your browser, including code that contains your tokens.

    When to use API Request Builder

    • Turning an endpoint from API documentation into code for your language.
    • Translating a working request from one language to another.
    • Preparing a correct file upload or OAuth token request.
    • Teaching how the same HTTP request looks in different libraries.

    API Request Builder FAQ

    Does this tool send the request?

    No. It only writes code. To send a request and inspect the response, use the REST API Tester.

    Why is there no Content-Type header in the multipart code?

    A multipart body is divided by a boundary string, and the Content-Type header has to name it. The HTTP library generates both, so setting the header yourself produces a request the server cannot parse. The generated code leaves it to the library.

    Why does the Python code use json= and not data=?

    With json=, the requests library serialises the dictionary and sets the Content-Type header to application/json. With data= and a dictionary it would send a URL-encoded form. The generator picks the parameter that matches your body type.

    How should I handle the token in real code?

    Do not leave it in the source. Read it from an environment variable or a secrets manager, and never ship a secret API key in browser JavaScript, where every visitor can read it. Calls that need a secret key belong on your server.

    Why does my fetch call fail with a CORS error?

    Browsers only let a page read responses from another origin when that server allows it through CORS headers. The same request from a server, from Python or from cURL is not subject to this rule. If the API does not allow your origin, call it from your back end.

    Does it check the response status?

    Yes. The fetch code tests response.ok, the Python code calls raise_for_status(), and the PHP code checks for a transport error and reads the status code. Axios rejects non-2xx responses by itself.

    One request, many notations

    An HTTP request is a small, well-defined thing: a method, a URL, a set of headers and an optional body. Every HTTP library sends the same bytes in the end. What differs is the notation, and each library has conventions that are easy to get wrong when you switch between them. This tool keeps the request in one neutral form and prints it in the notation you need.

    The differences are mostly in how the body is prepared. JavaScript's fetch sends whatever string you give it, so objects have to be serialised with JSON.stringify and the content type set by hand. Axios serialises objects itself. The Python requests library distinguishes json= for JSON from data= for forms. PHP's cURL extension sends a string as given and turns an array into a multipart form. Knowing which of these applies is exactly the kind of detail people look up again and again.

    Authentication follows three common patterns. A bearer token goes in the Authorization header after the word Bearer. Basic authentication sends the user name and password, joined by a colon and Base64-encoded, in the same header; the encoding is not encryption, so it is only safe over HTTPS. API keys are sent in a custom header or, less ideally, as a URL parameter, where they tend to end up in logs.

    Generated code is a starting point. Before it goes into an application, move secrets out of the source, add a timeout if the library has no default, decide how to retry on temporary failures such as 429 and 503, and handle the error body the API returns. Those concerns depend on your application and cannot be generated, but the request itself, which is where most first attempts fail, will be right.

    Other useful tools