Developer Tools

cURL Generator

Build a cURL command without memorising flags or fighting with quotes. Fill in the request, tick the options you want and choose your shell. The command is quoted correctly for Bash, PowerShell or the Windows Command Prompt, which is where hand-written commands most often break.

  • Runs in your browser
  • No sign-up
  • Free to use
Query parameters
Headers
Authentication
Body
cURL options

    The command is generated in your browser. Remember that a command containing a token is saved in your shell history.

    How to use cURL Generator

    1. Choose the method and enter the URL, then add parameters, headers and authentication.
    2. Select a body type and enter the JSON, form fields or text.
    3. Choose your shell and tick cURL options such as follow redirects or show headers.
    4. Copy the command and run it in your terminal.

    cURL Generator features

    Three shells

    Quoting and line continuation for Bash and zsh, PowerShell, and cmd.exe.

    Right flag for each body

    -d for JSON and text, --data-urlencode for forms, -F for multipart and file uploads.

    Common options

    Follow redirects, show headers, verbose mode, timeout, save to file, compression and HTTP version.

    Authentication

    Bearer token and API-key headers, and -u for Basic authentication.

    Short or long options

    Switch between -H and the self-explanatory --header style for scripts.

    Warnings where it matters

    Notes on --insecure, credentials over http:// and tokens following redirects.

    When to use cURL Generator

    • Testing an API endpoint from the terminal.
    • Writing a reproducible request for a bug report or documentation.
    • Getting a command that works on a colleague's Windows machine as well as on Linux.
    • Scripting a file upload or a webhook call.

    cURL Generator FAQ

    Why does my cURL command fail on Windows?

    Quoting rules differ. Bash uses single quotes; cmd.exe only understands double quotes, and inner double quotes must be escaped as \". In Windows PowerShell, curl may be an alias for Invoke-WebRequest, which takes different arguments, so the command has to call curl.exe. Choose your shell and the generator applies these rules.

    What is the difference between -d and -F?

    -d sends the data as the request body, by default with the type application/x-www-form-urlencoded; it is also used for JSON together with a Content-Type header. -F builds a multipart/form-data body, the format of HTML forms with file inputs, and is required for uploading files with @path.

    Do I need -X POST?

    Not when you send data: -d and -F make the request a POST automatically. -X is needed for other methods such as PUT, PATCH and DELETE. For a HEAD request, use -I, since -X HEAD makes cURL wait for a body that never comes.

    Is it safe to use -k?

    Only against your own development server. -k, or --insecure, disables certificate verification, which removes the protection HTTPS provides against interception. For a server with a private certificate authority, pass the CA file with --cacert.

    How do I keep a token out of my shell history?

    Put it in an environment variable and reference it in the command, for example -H "Authorization: Bearer $TOKEN" in Bash. For Basic authentication, a .netrc file avoids typing the password at all.

    How do I see the response headers?

    Tick “Show response headers” for -i, which prints them above the body. Verbose mode, -v, additionally shows the request cURL sent and the TLS handshake, which is the best way to debug a failing call.

    cURL and the problem of quoting

    cURL is the universal tool for making HTTP requests from a command line. It is installed on practically every Linux and macOS system and has shipped with Windows since 2018. API documentation uses it as a common language: a cURL command is a complete, executable description of a request. It has well over two hundred options, of which a dozen cover almost all everyday use.

    The command itself is rarely the hard part. The shell is. Before cURL sees its arguments, the shell splits the line into words and interprets special characters, and each shell does this differently. A JSON body is full of double quotes, braces and sometimes dollar signs. In Bash, wrapping it in single quotes passes it through untouched. The Windows Command Prompt has no single quotes, so the body must be in double quotes with every inner quote escaped. PowerShell has single quotes but, in the versions shipped with Windows, strips inner double quotes when calling an external program unless they are escaped.

    This is why a command copied from documentation often fails on a different system with a confusing JSON parse error from the server: the request arrived, but the body was mangled on the way. Generating the command for the shell that will run it removes this class of problem. Where a shell cannot express something, such as a multi-line quoted value in cmd.exe, the generator restructures the command and tells you.

    A few options are worth knowing by heart. -i shows response headers. -v shows the whole conversation. -L follows redirects. -o saves the body to a file. -s silences the progress meter in scripts, usually combined with -S to keep error messages. --max-time prevents a script from hanging forever. --fail makes cURL return a non-zero exit code for HTTP errors, which is what a script needs to detect failure.

    Other useful tools