cURL Converter
Paste a curl command and get the same request as JavaScript fetch, Node axios, Python requests, PHP cURL, Go, wget or HTTPie, or turn a fetch() call back into curl. Every flag, header and body decision is shown.
How to Use
- Choose the direction: curl → code, or fetch → curl to turn a fetch() call back into a command.
- Paste the command. Multi-line commands with
\continuations, single and double quotes,$'…'strings and Chrome’s “Copy as cURL” output (bash or cmd) all work. - Pick the target: JavaScript fetch, Node axios, Python requests, PHP cURL, Go net/http, wget or HTTPie. The code updates as you type.
- Read the warnings box: it flags
-k, an unquoted&, file references and JSON sent with the wrong Content-Type. - Check Show Work for each flag’s mapping, why the method was chosen and which headers curl adds by itself, then press Copy code.
Worked Example
Convert curl -u user:pass -d 'name=Ada' https://api.example.com/users to Python requests.
Tokens: the shell splits it into 6 words: curl, -u, user:pass, -d, name=Ada (the quotes are removed) and the URL.
Method: there is no -X, so the -d decides it: POST.
Headers: -d also implies Content-Type: application/x-www-form-urlencoded, and -u becomes Authorization: Basic + base64 of the 9 bytes user:pass = dXNlcjpwYXNz.
Code: requests.post('https://api.example.com/users', headers=headers, data=data, auth=('user', 'pass')), with the Content-Type in headers and data = 'name=Ada' sent exactly as written.
Add -G and the data moves into the URL instead: curl -G --data-urlencode 'q=hello world' https://api.example.com/search is a GET to https://api.example.com/search?q=hello%20world.
The common mistake: sending JSON with plain -d. curl -d '{"name":"Ada"}' https://api.example.com/users sends the 14 bytes of JSON labelled application/x-www-form-urlencoded, so many APIs answer 415 Unsupported Media Type or read an empty body. A converter that silently writes json= in Python hides the bug in curl and changes the request. This one keeps the request as curl sends it and warns you; add -H 'Content-Type: application/json', or use --json (curl 7.82.0 and later), which also adds Accept: application/json.
Show Work
curl Flag Reference
How curl Became the Common Language of APIs
curl grew out of httpget, a small program by Rafael Sagula that Daniel Stenberg started improving in 1996. It was renamed urlget, and on 20 March 1998 it was released as curl 4.0, the name meaning “client for URLs”. Stenberg still leads the project. The library behind the tool, libcurl, followed in 2000 and is what PHP’s cURL extension wraps, which is why the PHP output here uses the same option names as curl itself.
Because curl ships with Linux distributions, macOS and, since 2018, Windows 10, API documentation adopted it as the neutral way to show a request: one line that runs in any terminal, with no language to choose. Browser developer tools followed with “Copy as cURL”, which is why most real commands arrive with a dozen headers and bash’s $'…' quoting.
The libraries it is converted to come from different eras: Python’s requests (2011) made auth= and json= one-word options, the WHATWG Fetch standard gave browsers a promise-based successor to XMLHttpRequest, and Node.js 18 (2022) made the same fetch() available on the server. Their defaults differ from curl’s in small ways, such as following redirects, and those differences are what the notes under the code point out.
About This Tool
This converter reads a curl command the way a shell does — quotes, escapes, $'…' strings, line continuations and Windows ^ escapes — then applies curl’s own rules: which flag sets the method, which headers are implied, how -d pieces are joined and what -G moves into the URL. It writes the request for seven targets and keeps bodies byte for byte, writing JSON as a literal only when no number, key order or duplicate key would change. In the other direction it reads a fetch() call, including Chrome’s “Copy as fetch”, with a parser that accepts literal values only.
Nothing is run and nothing is sent: commands often contain API keys, cookies and tokens, and they stay in your browser. Input up to 1 MB is converted as you type.
Related tools: JSON Formatter, HTTP Status Codes, and Base64 Encoder.
Frequently Asked Questions
Why does curl -d send a POST request?
Any -d, --data-raw, --data-binary or --data-urlencode makes curl send POST and, unless you set one, the header Content-Type: application/x-www-form-urlencoded. To send the same data as a query string instead, add -G: -G --data-urlencode 'q=hello world' becomes ?q=hello%20world on a GET. -X GET -d … is different: it sends a GET with a body, which most servers ignore.
How is curl -u user:pass converted?
It becomes HTTP Basic authentication: the text user:pass is turned into UTF-8 bytes and base64-encoded, giving Authorization: Basic dXNlcjpwYXNz (9 bytes in, 12 characters out). Base64 is an encoding, not encryption, so only send it over https. Each target uses its own option where it has one: auth=('user', 'pass') in requests, CURLOPT_USERPWD in PHP and SetBasicAuth in Go.
Do fetch, axios and requests follow redirects like curl?
No: they follow them by default, and curl does not. Without -L curl stops at a 301 or 302 and shows that response; fetch, axios, Python requests (except for HEAD), Go and wget follow it. PHP’s cURL extension and HTTPie behave like curl, so the converter adds CURLOPT_FOLLOWLOCATION or --follow only when you used -L. Show Work names the option that turns following off in each target.
What happens to -k / --insecure?
It switches off TLS certificate checks, so the converter shows it in red and writes the matching switch: verify=False in requests, CURLOPT_SSL_VERIFYPEER => false in PHP, InsecureSkipVerify: true in Go, --no-check-certificate in wget and --verify=no in HTTPie. Browsers cannot skip certificate checks at all, so the fetch code only explains the Node option. Use it for a local test server, never in production.
Can I paste “Copy as cURL” from Chrome or Firefox?
Yes. The bash version, with its $'…' strings, and Chrome’s Windows cmd version, with ^ escapes, are both read. Those commands carry your session cookies and tokens, so check them before sharing the result. Nothing you paste leaves the browser: the command is split into words by a tokenizer written for this page and never run or uploaded.
How do I use the cURL Converter?
Just type or paste your value. The answer shows up right away — there is no button to press. Change anything and it updates by itself.
Do I need to install or sign up for anything?
Not at all — it runs in the browser with nothing to install and no account. After it loads once, it even works without an internet connection.
Is my information private?
Yes. Everything happens in your browser. Nothing you type is sent to a server or saved anywhere.
Common Use Cases
From DevTools to code
Right-click a request in the Network panel, Copy as cURL, paste it here and pick fetch: the same headers and body, with Cookie and Referer flagged as headers a browser will not let you set.
API documentation examples
Docs that show curl -u sk_test_123: (key, empty password) become auth=('sk_test_123', '') in requests; the header is Basic c2tfdGVzdF8xMjM6.
GitHub REST API
The documented call with 3 headers (Accept, Authorization: Bearer and X-GitHub-Api-Version 2022-11-28) becomes a complete Go program with 3 req.Header.Set lines.
Debugging a 415 error
curl -d '{"name":"Ada"}' sends 14 bytes of JSON labelled application/x-www-form-urlencoded. The warning box catches it and suggests --json.
Search queries
-G --data-urlencode 'q=hello world' becomes a GET to ?q=hello%20world; Show Work shows the data moving into the URL.
Bug reports from front-end code
Turn a fetch() call with JSON.stringify, headers and referrer into one curl command a back-end developer can run, with -L added because fetch follows redirects.
Last updated: