cURL Command Builder

Write a cURL command for an HTTP request and get the same request as fetch, Python and PHP code.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Build request controls

Showing an example. Edit to see your own.

The full address, starting with http:// or https://.

One header per line, written as Name: value. Each name may appear once.

Sent with --data-raw, so a body that starts with @ stays literal. GET and HEAD cannot carry a body; leave it empty for those.

Optional. Adds an Authorization: Basic header to every snippet.

Used in read mode. Paste a command that starts with curl.

Mode

Processed in your browser. Your inputs stay on this device.

How to use cURL Command Builder

  1. Choose Build a command, then set the method, URL and headers. Add a body only for methods that send one.
  2. Read the generated cURL command, followed by JavaScript fetch, Python requests and PHP curl snippets for the same request.
  3. To work the other way, switch to Read a pasted command and paste a cURL line. A flag this tool will not model is named in the result instead of being guessed at.

Example: cURL Command Builder

Build the command for a JSON POST request.

You add
Mode: Build a command. Method: POST. URL: https://api.example.com/v1/orders. Headers: Content-Type: application/json. Request body: {"item": "book", "qty": 2}. Basic auth: empty.
You get
The cURL block reads: curl \ -X POST \ https://api.example.com/v1/orders \ -H 'Content-Type: application/json' \ --data-raw '{"item": "book", "qty": 2}' The summary reads "Built a POST request to https://api.example.com/v1/orders with 1 header and a body.", and the same request follows as fetch, requests and PHP curl.

Supported inputs and limits

Up to 50 header lines, 20,000 characters per text field and 20,000 characters for a pasted command. The reader understands -X, -H, -d, --data-raw, --data-binary, --data-ascii, --json, -u, --url, -A, -b, -e and -I. Flags outside that set are refused by name, including -K, -o, -T, -O, -x, -w, -D, -F, -G, -k, -L and --compressed, because they read or write files, route traffic elsewhere, or change the response in a way the printed snippets do not rebuild. A -d, --data, --data-binary or --json value that starts with @ is refused, and -b without an = is treated as a cookie file and refused; use --data-raw for literal text that starts with @. -d, --data and --data-ascii strip carriage returns and newlines, so a multi-line value through those flags is refused; --data-raw keeps the line breaks. An empty -d '' is read as POST with an empty body, which is what cURL sends. Shell expansion and operators ($, backtick, $(...), ;, |, &, >, <) are refused, because the read value would not be the text the shell produced; a single-quoted or escaped value is literal and is kept as it is. HEAD requests print with -I, since -X HEAD alone makes cURL wait for a body. All four snippets describe the same method, URL, headers and body, with redirects off and the same content type, but they are not interchangeable across every environment: the JavaScript snippet runs under browser rules, where forbidden headers such as Host and Content-Length are dropped, cross-origin requests need CORS, and credentials follow the browser's rules. Nothing is executed here: the tool prints text and never sends a request.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Reading a command back is deliberately narrow

Several cURL options read files or change how a request is sent. The reader maps the supported request flags and refuses the rest. When it refuses a flag, enter the supported parts in the builder fields and check the generated command before using it.

Questions about cURL Command Builder

Does this page send my request?

No. The tool only prints the command and the code snippets. Nothing is fetched, and the URL, headers and body stay in this browser.

Why does a value in the cURL command have quotes around it?

Any value with a space, quote, dollar sign or newline is wrapped in single quotes so the shell passes it through unchanged. An embedded single quote is written as close-quote, escaped quote, open-quote, which is the standard way to keep it literal.

Why was my pasted command refused?

Some flags read or write files on your computer, send a multipart upload, move the data into the query string, or change how the response is handled. That covers -K, -o, -T, -O, -x, -w, -D, -F, -G, -k, -L and --compressed. The result names each flag it will not model, so the command you keep is one the printed snippets really match.

Does the Python or PHP snippet include my password?

If you fill Basic auth, every snippet includes your credentials in a Base64 Authorization header. Base64 is readily decoded and does not hide the password. Clear the field before sharing a snippet, and use an environment variable for credentials in real code.

Will all four snippets behave the same on the network?

They send the same method, URL, headers and body, with redirects turned off, but the browser's fetch is bound by browser rules. It cannot set a forbidden header such as Host or Content-Length, a cross-origin call needs the target to allow CORS, and cookies follow the browser's credential rules rather than your machine's cookiejar. Treat the JavaScript snippet as the browser version of the request, not as a byte-for-byte copy of cURL.

Project manager: Tony Hines · Content updated 1 October 2026 · Report a problem