thoughtasylumTOOLBOX Preview

Tools › Developer

cURL to Code

Paste a curl command, a raw HTTP request or a HAR from your browser, and get the same request as curl, Python requests, JavaScript fetch, Go or PHP.

About this tool What it's for, how to use it and an example

What it's for

Turn a curl command into code: the same request written for Python’s requests library, JavaScript’s fetch, Go’s net/http or PHP’s cURL functions. The command is only read, never run, so no request is made.

For example, to script a call your browser makes, find it under the Network tab of the developer tools, choose Copy as cURL, paste it here and copy the Python.

How to use it

Choose what you’re pasting under From, paste it, and choose the Language; the code is written as you type. From takes:

  • a curl command, such as one from your browser’s Copy as cURL;
  • a raw HTTP request: the request line, headers, a blank line and the body, as Burp, a proxy, a log or your browser’s raw view of the request headers shows it (HTTP/2’s :method and :path lines work too);
  • a HAR: from the Network tab, Copy as HAR for one request, or a whole saved .har file, of which the first request is used.

Choose curl as the Language to turn a raw request or HAR into a curl command you can run or share. Headers the client sets itself (Host, Content-Length) are left out, and a raw request is assumed to be https.

For a curl command, the rest of this applies. Commands split over lines with \ (or ^ from Windows) are fine, as are the $'…' quotes that browsers use.

It understands the method (-X), headers (-H, -A, -e, -b), data (-d, --data-raw, --data-binary, --data-urlencode, --json, and @file to send a file), forms (-F, with @file for an upload), -u for a user name and password, -G to put the data in the address, -I for HEAD, -L to follow redirects and -k to skip certificate checks. Like curl, data without a Content-Type is sent as a form, and a request with data is a POST. A JSON body becomes the language’s own data (a Python dict, a JavaScript object). Options that don’t change the request, such as -s or -o, are ignored; the message line lists anything else that was left out. The From and Language choices are remembered in the browser.

Example

Choose Try an example, which pastes a POST of {"name": "Widget", "price": 9.99} with a bearer token. The Python is:

import requests

headers = {
    "Authorization": "Bearer YOUR_TOKEN",
}

json_data = {
    "name": "Widget",
    "price": 9.99
}

response = requests.post("https://api.example.com/v1/items", headers=headers, json=json_data, allow_redirects=False)
print(response.status_code, response.text)

Good to know

Requests copied from a browser (as curl or HAR) often carry your session cookies and tokens. They stay on this page, but take them out before sharing the code. There’s no link to share for the same reason. Shell variables ($TOKEN) are kept as written, not filled in. A file to upload with fetch comes from a file input on your page, so the code marks where it goes. Proxies, client certificates and most timing options are left out. A HAR’s responses and timings are ignored.

Private: this tool runs in your browser. Nothing you type, paste or choose leaves this page.

Saved you a few minutes? Say thanks with a coffee.

Something wrong with this tool, or missing from it? Report a bug or suggest a feature.

↑ ↓ move↵ openesc close