cURL to code converter
Developer tools
Loading
Loading tool
The tool is loaded only when you open it.
All processing for this tool happens in your browser. Your input is not sent to a server.
About this tool
Paste a literal cURL command to translate its URL, method, headers, and inline body into one of three programming languages. The generated code updates immediately when you edit the command, change the language, or toggle redaction. The converter parses text in your browser: it never runs cURL, calls the endpoint, uploads the input, or saves conversion history. Copy or download a snippet only after reviewing its warnings and credential placeholders.
Common uses
- Turn a supported cURL example from API documentation into Fetch, Python Requests, or Go net/http code.
- Move a quoted JSON POST or form-style request into an application without manually re-escaping each string.
- Prepare a shareable request example with recognized header and URL credentials replaced, then manually inspect the body and custom fields.
How to use it
- 1.Paste one cURL command containing an absolute HTTP(S) URL. Quote URLs with query strings and use literal POSIX-style single or double quotes.
- 2.Choose JavaScript Fetch, Python Requests, or Go. Keep credential redaction enabled unless you intentionally need the original values; inspect every warning.
- 3.Review the current code and manually remove any remaining secrets. Copy it or download a .js, .py, or .go file, then adapt it to your runtime before execution.
Worked request examples
GET with a query parameter and Accept header
curl 'https://example.com/api/items?limit=2' -H 'Accept: application/json'
GET https://example.com/api/items?limit=2 Accept: application/json
The output shown here is a request summary, not a live response. All three language targets represent the same GET URL and Accept header; no endpoint is contacted.
Inline JSON POST
curl 'https://example.com/api/items' --json '{"name":"demo","active":true}'POST https://example.com/api/items
Content-Type: application/json
Accept: application/json
{"name":"demo","active":true}With no explicit method, --json produces a POST and supplies JSON Content-Type and Accept defaults. The JSON text stays an inline body; the converter does not validate its schema or redact its fields.
Move form fields into a GET query
curl -G 'https://example.com/search' --data-urlencode 'q=hello world' -d 'page=2'
GET https://example.com/search?q=hello%20world&page=2
-G moves data to the query, --data-urlencode percent-encodes the value hello world, and the second data field is joined with &. The resulting GET has no body.
Common conversion mistakes
- Pasting an unquoted URL containing ? or &: quote the complete URL so shell metacharacters are treated as literal text.
- Pasting browser-exported flags such as --compressed, -L, -s, or -S: unsupported flags cause an error instead of being silently discarded. Review their meaning before simplifying the command.
- Using -d @payload.json or -F file=@image.png: this tool never reads files or creates multipart uploads. Supply supported inline text, or implement file handling in your application.
- Combining -X GET with a body: use -G when fields belong in the query, or select the method required by the API.
- Assuming redaction hides all secrets: a JSON password, custom X-Secret header, or session_id query value remains visible. Inspect all code before copying or sharing.
Limits and notes
- The input limit is 100,000 characters and one HTTP(S) URL. Supported methods are uppercase GET, HEAD, POST, PUT, PATCH, DELETE, and OPTIONS. Only the options listed in the interface are accepted; this is not a complete cURL parser.
- Shell variables, substitutions, pipes, PowerShell/CMD quoting, URL globbing, multipart uploads, file reads, proxies, TLS options, and redirect flags are unsupported. GET/HEAD bodies, empty headers, header suppression, and Host, Content-Length, Transfer-Encoding, or Connection headers are rejected. Repeated -A/-e/-b options, or combining an alias with the same named -H header, are also rejected; plain repeated -H headers remain supported.
- Redaction replaces only recognized headers, URL credentials, and the listed query names. Bodies, custom header/query names, paths, fragments, and the original input are not redacted. The toggle is a convenience, not a complete secret detector.
- Browser Fetch remains subject to CORS and forbidden-header rules. Fetch combines repeated headers; Python Requests keeps the last value; Go preserves them separately. Non-ASCII header values may fail in the target runtime. Python needs the requests package.
- URL parsing can normalize hostnames, ports, paths, or escaping. Literal text bodies are encoded as UTF-8. Generated requests do not automatically follow redirects, and browser redirect responses may be opaque. Runtime networking behavior is not guaranteed to match cURL byte for byte.
Frequently asked questions
Which cURL options can I convert?
The supported subset is -X/--request, -H/--header, -d/--data, --data-raw, --data-binary, --data-urlencode, --json, -G/--get, -I/--head, -u/--user, -A/--user-agent, -e/--referer, -b/--cookie, and --url. Values must be literal; file references and unlisted options are rejected. Repeated data fields are joined with &, while -G moves the data into the query string.
Exactly which values does redaction replace?
It replaces Authorization, Proxy-Authorization, Cookie, and X-Api-Key values, URL userinfo, and query values named token, access_token, access-token, accesstoken, refresh_token, refresh-token, refreshtoken, api_key, api-key, apikey, key, password, secret, or authorization, ignoring case. Basic credentials become an Authorization header. Bodies and other locations must be reviewed manually.
Why does Fetch fail when the original cURL request succeeds?
A browser applies CORS, forbidden-header, and credential rules that do not apply to command-line cURL. Generating code does not grant cross-origin access or permission to set controlled headers. Check the API’s browser support and server configuration, or use an appropriate server-side runtime.
Does conversion send or save my request?
No. Parsing and code generation happen locally, without executing the command or saving conversion history. Copying places the current code on your clipboard, and downloading writes the current code to a file. The input field itself still contains the original command even when output redaction is enabled.