How HTTP Works

Tools

curl Command Explainer

Paste a curl command, including one from Chrome DevTools "Copy as cURL". See what every flag does, the exact HTTP request that goes on the wire, and the same call as fetch or Python requests. Everything runs in your browser.

Try
Runs in your browser. Nothing is sent anywhere.

This command contains secrets

  • -b: Cookie values (may include session ids)
  • -H authorization: Authorization credentials
  • request body: Field with a secret-looking name (password, token, key...)

Anyone with this command can replay your session. Rotate a credential if you pasted it into a chat, ticket or issue. .

Heads up

  • Checksec-fetch-* and sec-ch-ua* headers are added automatically by browsers and are rarely needed when replaying a request with curl.

The request that will be sent

> POST /v1/orders?expand=items HTTP/1.1> Host: api.example.com# added by curl> user-agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36> accept: application/json, text/plain, */*> Accept-Encoding: deflate, gzip, br, zstd# from a flag> Cookie: session=abc123def456; theme=dark# from a flag> accept-language: en-US,en;q=0.9> authorization: Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjMifQ.c2lnbmF0dXJl> content-type: application/json> origin: https://app.example.com> referer: https://app.example.com/orders> sec-fetch-mode: cors> Content-Length: 83# implied> 

Body (sent as written)

{"items":[{"sku":"A-1","qty":2}],"note":"Don't ring the bell","password":"hunter2"}

Headers marked "added by curl" are what curl 8 sends by default. Run the command with -v to see your exact version's list.

Flag by flag

  • URL

    Target URL

    https://api.example.com/v1/orders?expand=items

    Request https to api.example.com.

  • -H

    Header: accept

    accept: application/json, text/plain, */*

    Adds or replaces a header. A header with an empty value ("Name:") removes the one curl would add; "Name;" sends it empty.

  • -H

    Header: accept-language

    accept-language: en-US,en;q=0.9

    Adds or replaces a header. A header with an empty value ("Name:") removes the one curl would add; "Name;" sends it empty.

  • -H

    Header: authorization

    authorization: Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjMifQ.c2lnbmF0dXJl

    Adds or replaces a header. A header with an empty value ("Name:") removes the one curl would add; "Name;" sends it empty.

  • -H

    Header: content-type

    content-type: application/json

    Adds or replaces a header. A header with an empty value ("Name:") removes the one curl would add; "Name;" sends it empty.

  • -b

    Send cookies

    session=abc123def456; theme=dark

    A string containing "=" is sent as a Cookie header; otherwise it is a cookie jar file to read.

  • -H

    Header: origin

    origin: https://app.example.com

    Adds or replaces a header. A header with an empty value ("Name:") removes the one curl would add; "Name;" sends it empty.

  • -H

    Header: referer

    referer: https://app.example.com/orders

    Adds or replaces a header. A header with an empty value ("Name:") removes the one curl would add; "Name;" sends it empty.

  • -H

    Header: sec-fetch-mode

    sec-fetch-mode: cors

    Adds or replaces a header. A header with an empty value ("Name:") removes the one curl would add; "Name;" sends it empty.

  • -H

    Header: user-agent

    user-agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36

    Adds or replaces a header. A header with an empty value ("Name:") removes the one curl would add; "Name;" sends it empty.

  • --data-raw

    Send a body, no @ handling

    {"items":[{"sku":"A-1","qty":2}],"note":"Don't ring the bell","password":"hunter2"}

    Like -d but a leading @ is literal text, not a filename. Chrome DevTools uses it for request bodies.

  • --compressed

    Ask for compressed response

    Sends Accept-Encoding with the encodings your curl build supports and automatically decompresses the response.

  • implied

    Method becomes POST

    -d / --data* switch the method from GET to POST automatically.

  • implied

    Redirects are not followed

    Without -L, a 301/302/307/308 response is printed as is. Add -L to follow Location.

Convert to code

// Browsers silently drop these forbidden headers: Cookie, origin, referer, sec-fetch-mode. Node's fetch sends them.
// --compressed: fetch advertises and decodes gzip/br automatically.

const response = await fetch("https://api.example.com/v1/orders?expand=items", {
  method: "POST",
  headers: {
    "user-agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36",
    "accept": "application/json, text/plain, */*",
    "Cookie": "session=abc123def456; theme=dark",
    "accept-language": "en-US,en;q=0.9",
    "authorization": "Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjMifQ.c2lnbmF0dXJl",
    "content-type": "application/json",
    "origin": "https://app.example.com",
    "referer": "https://app.example.com/orders",
    "sec-fetch-mode": "cors",
  },
  body: JSON.stringify({
    items: [
      {
        sku: "A-1",
        qty: 2
      }
    ],
    note: "Don't ring the bell",
    password: "hunter2"
  }),
  redirect: "manual", // curl does not follow redirects without -L; fetch does by default
  credentials: "include", // browsers ignore a manual Cookie header; send cookies this way instead
});

console.log(response.status, await response.text());
Share links always redact credentials, cookies and secret-looking values.

What the tool does and does not show

The request is built from the flags you gave and from curl's documented defaults, so it is a close model of what curl -v prints on lines starting with >. Details that only exist at run time, such as the multipart boundary, the exact User-Agent version and redirects, are marked as such. To send the request and look at the response, open it in the HTTP Playground. To read a raw message, use the Message Parser.

Background: POST, Content-Type, Authorization and Cookie.

Frequently asked questions

How do I copy a request as curl from Chrome DevTools?

Open DevTools, go to the Network tab, right-click the request and choose Copy, then Copy as cURL (bash). Paste it here. The command contains your cookies and Authorization header, so use the redact option before sharing it.

What does curl -d do besides sending data?

It changes the method from GET to POST and adds Content-Type: application/x-www-form-urlencoded unless you set your own. -d with JSON therefore needs -H "Content-Type: application/json" (or --json on curl 7.82 and newer).

What is the difference between -d and --data-raw?

-d treats a leading @ as a filename and reads the file, and strips newlines from it. --data-raw sends the text exactly as written, which is why Chrome uses it. --data-binary also reads files but keeps newlines.

Why does curl not follow redirects?

By default curl prints the 3xx response and stops. Add -L (--location) to follow the Location header. JavaScript fetch is the opposite: it follows redirects unless you pass redirect: "manual".

Is Basic auth from -u secure?

The header is only base64 encoded, not encrypted, so anyone who sees it can decode it. It is safe only over HTTPS. The tool shows the encoded header so you can see exactly what is sent.

Browse /search