Skip to content

cURL Command Generator

No request is ever sent

This page builds the text of a command; it does not run it, and it has no server side. The token you paste is held in the tab and nothing else — not localStorage, not the URL, not an analytics event — so closing the tab is what disposes of it. Because a generated command usually ends up in a ticket or a pull request, there is a second copy button that swaps every credential for a shell variable before it leaves this page.

Start from

Method

Headers

Paste a whole block of Name: value lines and they split into rows. Uncheck one to keep it without sending it.

Auth
Body

Shell

Linux, macOS, WSL and Git Bash. Single-quoted, backslash line continuations.

Layout
HTTP version
Output

How cURL Command Generator works

Two languages meet in a curl command and only one of them is HTTP. The other is your shell, which reads the line first, decides where each argument begins and ends, and hands curl an array of strings it has already rewritten. Quoting is how you tell the shell to stop rewriting. Get it wrong and the failure does not look like a quoting failure — it looks like the API rejecting a payload it never received in full.

Single quotes are the safest wrapper in bash and zsh because nothing inside them is interpreted: no dollar signs, no backticks, no backslash escapes. A payload containing $HOME, a regular expression, or a Windows path arrives byte for byte. The price is that an apostrophe cannot appear inside them at all, since the first one encountered simply ends the run. The only construction that works is to close the quoted run, emit an escaped apostrophe on its own, and open a new run — which is why an order note reading it is urgent comes out as four characters where one was typed. It looks like a typo and it is the correct answer.

Windows is a different language again rather than a formatting preference. The classic console has no literal-quote construct whatsoever, so a payload full of double quotes has to be wrapped in double quotes and escaped from the inside, following the argument rules of the Microsoft C runtime rather than anything the console itself defines. Those rules also mean a run of backslashes touching the closing quote must be doubled, or a path ending in one swallows the remainder of the line. PowerShell doubles apostrophes instead of escaping them and continues a wrapped line with a backtick where bash uses a backslash. Copying a working bash command into either one fails on the first payload that contains a quote.

Beyond quoting, a handful of flags mean something other than what they appear to. Naming a method explicitly alongside a payload flag is redundant, because supplying data already selects POST, and the explicit form additionally suppresses the method rewriting that happens on a redirect. Asking for a header-only response by naming the method makes the transfer hang, because the tool still waits for a response body that a header-only reply will never contain; the dedicated flag is the one that means what people mean. And the short data flag quietly deletes line breaks from what it is given and treats a leading at-sign as a path on disk, so a payload beginning with one is read as a filename rather than sent.

Reference

  • posix: wrap in ' … ' and rewrite each interior ' as '\'' — close, escape, reopen
  • powershell: wrap in ' … ' and double each interior ' as ''
  • cmd: wrap in " … ", precede each interior " with a backslash, and double any backslash run that meets a quote
  • line continuation: backslash (bash/zsh) · backtick (PowerShell) · caret (cmd)
  • valueless header: -H 'Name;' sends an empty one — -H 'Name:' deletes it instead
  • body flags: --data-raw sends verbatim · -d strips line breaks and expands @file · -F builds a multipart part · --data-urlencode percent-encodes one field

How to use this generator

  1. Give it a destination and a verb

    The address and the method come first, because a header and a payload have nowhere to go without them. The method also decides which flags are redundant, so choosing it changes what appears in the output.

  2. Fill the rows

    Headers, query parameters and form fields are all name-and-value grids, and a block copied out of a browser network panel can be pasted straight into one — it splits into rows on the first separator of each line. Unticking a row keeps it around without sending it.

  3. Pick where the payload comes from

    Choosing a payload kind sets the type header for you, which is the step most often skipped by hand. Structured payloads are checked as you type and reported without blocking, since half-finished ones are normal while debugging.

  4. Choose the shell it is going to run in

    The three targets differ in their wrapper character, their escape rule and their line-continuation marker. Switching between them rewrites every quoted argument rather than merely reflowing the text.

  5. Copy it, redacted if it is going anywhere public

    The plain copy carries real credentials. The second copy swaps each one for a variable name, which keeps the command runnable for whoever receives it while leaving nothing usable in a ticket or a chat log.

Worked examples

An apostrophe inside a structured payload

Given
A note field whose text reads it is urgent, written with an apostrophe
Result
The payload is emitted with '\'' where the apostrophe was

Four characters replace one. Written naively the run would end at the apostrophe, the shell would split what follows into separate words, and the server would receive a truncated fragment that is still syntactically plausible.

The same payload aimed at the Windows console

Given
A structured payload full of double quotes, targeting cmd
Result
Wrapped in double quotes with every interior one preceded by a backslash

The apostrophe needs nothing here and the double quotes need everything, which is the exact inverse of the bash case. This is why a copy button that only relabels its output is worse than none.

A method that does not need naming

Given
A POST carrying a structured payload
Result
The payload flag appears; the explicit method flag does not

Supplying data already selects the method. Writing both is the most reliable tell of a machine-generated command, and it changes redirect behaviour in a way nobody intended.

A file part with no type header

Given
One part naming a file on disk and one plain text part
Result
Two part flags and deliberately no type header

The tool generates a unique separator string between parts and writes the header itself. A hand-written one omits that separator, so the receiving end cannot tell where each part begins.

A header with nothing in it

Given
A trace header whose value is left blank
Result
-H 'X-Trace;' rather than -H 'X-Trace:'

The colon form is the documented way to REMOVE a header that would otherwise be sent automatically. The semicolon form is how you send one with an empty value — two spellings one character apart that do opposite things.

When to use it

  • Turning a request that works in a browser into a reproducible line you can paste into a bug report, a runbook or a continuous-integration job.
  • Handing a colleague a way to reproduce an API failure without also handing them your access token, by copying the redacted form instead.
  • Producing a Windows-safe version of a line that a Linux teammate wrote, without discovering the incompatibility halfway through an incident call.
  • Building a first request against unfamiliar documentation, where the interesting question is which headers an endpoint wants rather than how to spell them on a command line.
  • Translating a working command into browser code, since the same description renders both and the two cannot drift apart.
  • Checking whether an endpoint is reached at all before writing any client code against it.

Things to watch out for

  • Nothing typed here is stored or transmitted. There is no saved draft, no address-bar state and no analytics property carrying any field, because the main input of a tool like this one is a credential.
  • A credential passed as a command-line argument is visible to every user on the machine through the process table, and it lands in shell history as well. The pre-encoded header form avoids the process table but not the history file; a credentials file read from disk avoids both.
  • Skipping certificate checks removes hostname, chain and expiry validation together. It silences the warning by deleting the check that produced it, so a line carrying that flag must never be pasted into anything that handles real traffic.
  • Query values are percent-encoded on the safe side. A few characters that need no encoding are encoded anyway, which every receiver accepts, whereas the opposite mistake silently truncates a value at the first ampersand.
  • Carriage returns and line feeds are removed from header names and values. Those characters terminate a header line, so leaving one in place would split a single request into two — usually the result of pasting a value with its line ending still attached.
  • The browser-code rendering is equivalent, not identical. Redirect handling differs by default between the two, an on-disk file part has to become a file object chosen by the user, and a credential given as a command-line argument has to become a header because there is no other place for it.

Frequently asked questions

Why does an apostrophe come out as four characters?

Because a single-quoted run in bash or zsh cannot contain one, and there is no escape for it inside the run. The sequence closes the run, emits one escaped apostrophe outside any wrapper, and opens a fresh run. It is ugly, it is what experienced people type by hand, and it is the only construction that survives word splitting intact.

Why is the method flag missing from my POST?

Because supplying a payload already selects it, so writing it out adds nothing. It is not merely redundant either: naming the method explicitly also stops the automatic rewriting that normally happens when a redirect is followed, which turns a working request into a puzzling one. Requests with no payload still get the flag, since nothing else would set the verb.

Can I paste the bash output into PowerShell?

Not once it contains a double quote, which any structured payload does. PowerShell doubles apostrophes rather than escaping them and wraps continued lines with a backtick, so the bash form is read as several broken commands. Switch the target shell instead and every argument is rewritten for it.

Why is there no content type on my file upload?

Because setting it by hand breaks the request. Multipart bodies are separated by a unique boundary string that the tool generates at send time and announces in the header it writes itself. A hand-written header carries no boundary, so the receiving end has a declared format it cannot parse and rejects the whole thing.

What does the redacted copy actually change?

Every credential value becomes a shell variable name while the surrounding structure, including the scheme word that precedes a token, stays exactly as it was. The result is safe to paste into an issue tracker and still runnable by whoever reads it, once they export the variable with their own value.

Can it read an existing command back into the form?

Not yet, and it is deliberate rather than forgotten. Reading one back means recognising a flag vocabulary of roughly two hundred and fifty options, where anything unrecognised has to be reported rather than silently dropped. That is a different problem from writing one out, and it deserves its own treatment rather than a partial version bolted on here.

All devops tools