curl Command Generator
Specify the HTTP method, URL, headers, body, and authentication method in the form to generate a ready-to-run curl command you can copy and paste. No request is actually sent, so CORS restrictions never apply.
Common curl Options
| Option | Description |
|---|---|
| -X, --request <method> | Specifies the HTTP method (GET, POST, PUT, PATCH, DELETE, etc.). If omitted, it defaults to GET when there is no body, or POST when there is a body. |
| -H, --header <header> | Adds a single request header. Repeat -H to add multiple headers. |
| -d, --data <data> | Sends a request body. If -X is not specified, it is automatically sent as POST with Content-Type: application/x-www-form-urlencoded. |
| -u, --user <user:password> | Specifies the username and password for Basic authentication in "user:password" format. |
| -k, --insecure | Skips SSL certificate verification. Intended for development environments with self-signed certificates. Not recommended in production. |
| -L, --location | Automatically follows the destination indicated by the Location header when the server returns a 3xx redirect. |
| -v, --verbose | Prints detailed request and response exchanges, including headers, to standard error. Useful for debugging. |
| --compressed | Adds an Accept-Encoding header, requesting and automatically decompressing responses compressed with gzip and similar encodings. |
| -o, --output <file> | Saves the response body to the specified file instead of standard output. |
| -F, --form <name=content> | Sends form data or files as multipart/form-data. Specify "@filepath" for file uploads. |
Assembling a curl command from a form
State the method, URL, headers, body and authentication in the form and out comes a curl command ready to paste into a terminal and run. **This tool never actually sends the request, so it is not bound by the browser's CORS restrictions:** the command can be assembled even for an API that would refuse a request from a page.
**What trips people up in curl is the relation between method and body.** Attach a body with `-d` and **the method becomes POST automatically, even if you never wrote one.** Intending to send a PUT or a PATCH while supplying only `-d` therefore fires off an unintended POST. The other frequent error is sending JSON while forgetting `Content-Type: application/json`; curl then sends it as `application/x-www-form-urlencoded`, and **the server does not read it as JSON at all.** When pasting the generated command into a terminal, mind the shell's quoting too: **variables are not expanded inside single quotes but are inside double quotes.**
How to use it
- State the method and the URL Choose GET to retrieve and POST to send.
- Add your headers **If you are sending JSON, do not forget `Content-Type: application/json`.**
- Write the body **Attaching a body makes the method POST automatically where none was stated.**
- Copy the command and run it Pasting it into a terminal is all that is needed.
Tips for getting more out of it
- The generated command can be pasted directly into a terminal, shell script, or CI/CD config file and run as-is. All values are already escaped with single quotes.
- A warning appears if you enter a body while the method is still GET. This is because curl automatically sends the request as POST when
-dis used without-X, so the warning helps you avoid unintended behavior. - Checking "Automatically add Content-Type: application/json" adds the Content-Type header that is easy to forget when calling a JSON API.
- Both Basic auth and Bearer token values are processed entirely inside your browser and are never sent to any server.
- The generated
-k(skip certificate verification) is a temporary workaround meant only for local development with self-signed certificates. Avoid using it permanently against production APIs.
Where it comes in useful
Testing how an API behaves
**An API you cannot call from a browser can still be tried with curl, unhindered by CORS.**
Putting a command into a procedure document
You can record what a request consists of in a form anyone can reproduce.
Sharing the steps to reproduce a fault
**Handing someone a command to run yields a reproduction far less affected by differences of environment.**
Learning curl's options
You can see which option each entry in the form turns into.
Curl terms
- -X
- States the method explicitly. **Since `-d` makes it POST even when omitted, this is what you need for PUT or DELETE.**
- -H
- Adds a header. Write it several times and that many headers are attached.
- -d
- States the request body. **Writing it makes the method POST, and the default content type becomes the form encoding.**
- -u
- States the user name and password for basic authentication, written in the form `user:password`.
- Bearer token
- The scheme sending credentials as `Authorization: Bearer ...`. A great many APIs adopt this form.
- -i and -v
- Show the response headers, and show the details of the exchange. **Both earn their keep when something will not work.**
Frequently Asked Questions
-d (body data) without the -X option, it automatically sends the request as POST. For the rare case where you need to keep GET while sending a body, manually add -X GET to the generated command.
Side Note — Why curl Is the Tool Everyone Uses but Almost No One Knows
curl is a command-line tool for transferring data with URLs, created in 1996 by Swedish engineer Daniel Stenberg. It originated from a small script that fetched currency exchange rates for an IRC chat bot, and has since grown into a massive project supporting more than 25 protocols, including HTTP, FTP, and SMTP.
curl is considered one of the most widely used pieces of software in the world. It is embedded inside virtually every internet-connected device — smartphones, cars, home appliances, game consoles, and even spacecraft (it has been used in NASA Mars missions) — with an estimated installed base in the tens of billions. Despite this ubiquity, it remains a classic example of unsung infrastructure that almost no one outside of developers has heard of.
In 2019, Stenberg was honored by the Linux Foundation for his contributions to foundational web technology. He remains the central maintainer driving curl development today, known for carefully preserving backward compatibility over more than two decades.
Even now that GUI tools like Postman are widespread, curl commands are still used in READMEs, official documentation, and API verification steps. The reason is simple: curl requires no installation and comes preinstalled on nearly every Linux and macOS environment, letting anyone run a single command on the spot and share the result — a level of reproducibility that is hard to beat.