Curl Request Workbench
Paste a literal cURL command to inspect its HTTP method, URL, headers and inline body. The workbench parses text locally without executing a shell or sending a request. It masks common credential-bearing headers and query parameters in previews and generated code. Review the generated code and replace placeholders before running it yourself.
Key features
- Parse POSIX-style literal quoting and escapes without evaluating shell expressions
- Read method, URL, multiple headers, inline data and the --json shortcut
- Reject unsupported options, file-backed bodies, duplicate headers and ambiguous multi-request input
- Mask common secret headers and query parameters in preview and code downloads
- Generate editable JavaScript Fetch and Python requests examples with JSON preview download
How to use
- Paste a cURL command or load the sample.
- Parse it and inspect the method, URL, headers and inline body.
- Review redaction placeholders and the warning about values embedded in the body.
- Switch between JavaScript Fetch and Python requests code.
- Copy or download the code or request preview; run code only after reviewing it.
Use cases
- Convert a copied API example into editable Fetch code
- Document the HTTP method and headers of a cURL snippet
- Check whether a command contains unsupported shell or file-input syntax before translating it
Frequently asked questions
Does this tool execute cURL or send an HTTP request?
No. Parsing and generation happen in your browser. The downloaded code will send a real request only if you run it elsewhere.
Which options are supported?
This version supports literal URL, -X/--request, -H/--header, one inline -d/--data/--data-ascii/--data-raw/--data-binary/--json body, --url, and selected output flags. Other options and file-backed @ input fail explicitly.
Are secrets automatically removed?
Common credential-bearing header names and query keys are replaced with placeholders in previews and generated code. The original command and body remain visible in this browser session. Body contents and unusual secret names are not automatically masked; review every download.
Can it parse shell variables or command substitution?
No. Shell expansion, command substitution, redirection, pipes and command chaining are refused. Quoted literal text and simple backslash escapes are supported.
Is binary or multipart upload supported?
No. Inline UTF-8 text is supported, including --data-binary when it is literal text. File upload, multipart, raw byte streams and curl configuration files are outside this tool.
Will generated code exactly reproduce cURL behavior?
It preserves supported request fields. Fetch and Python requests have their own defaults for redirects, cookies and transport; ignored output flags are shown. Review code before use.
Privacy
The command stays in this browser session. Parsing does not contact the target host. Generated code and downloaded files include the inline body; review them for secrets. If you run generated code, it sends a real request.
Comments & questions