How to use cURL Command Builder
- Choose Build a command, then set the method, URL and headers. Add a body only for methods that send one.
- Read the generated cURL command, followed by JavaScript fetch, Python requests and PHP curl snippets for the same request.
- To work the other way, switch to Read a pasted command and paste a cURL line. A flag this tool will not model is named in the result instead of being guessed at.
Example: cURL Command Builder
Build the command for a JSON POST request.
Supported inputs and limits
Where your input is processed
This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.
Reading a command back is deliberately narrow
Several cURL options read files or change how a request is sent. The reader maps the supported request flags and refuses the rest. When it refuses a flag, enter the supported parts in the builder fields and check the generated command before using it.
Questions about cURL Command Builder
Does this page send my request?
No. The tool only prints the command and the code snippets. Nothing is fetched, and the URL, headers and body stay in this browser.
Why does a value in the cURL command have quotes around it?
Any value with a space, quote, dollar sign or newline is wrapped in single quotes so the shell passes it through unchanged. An embedded single quote is written as close-quote, escaped quote, open-quote, which is the standard way to keep it literal.
Why was my pasted command refused?
Some flags read or write files on your computer, send a multipart upload, move the data into the query string, or change how the response is handled. That covers -K, -o, -T, -O, -x, -w, -D, -F, -G, -k, -L and --compressed. The result names each flag it will not model, so the command you keep is one the printed snippets really match.
Does the Python or PHP snippet include my password?
If you fill Basic auth, every snippet includes your credentials in a Base64 Authorization header. Base64 is readily decoded and does not hide the password. Clear the field before sharing a snippet, and use an environment variable for credentials in real code.
Will all four snippets behave the same on the network?
They send the same method, URL, headers and body, with redirects turned off, but the browser's fetch is bound by browser rules. It cannot set a forbidden header such as Host or Content-Length, a cross-origin call needs the target to allow CORS, and cookies follow the browser's credential rules rather than your machine's cookiejar. Treat the JavaScript snippet as the browser version of the request, not as a byte-for-byte copy of cURL.