cURL Command Generator
No request is ever sent
This page builds the text of a command; it does not run it, and it has no server side. The token you paste is held in the tab and nothing else — not localStorage, not the URL, not an analytics event — so closing the tab is what disposes of it. Because a generated command usually ends up in a ticket or a pull request, there is a second copy button that swaps every credential for a shell variable before it leaves this page.
Start from
Linux, macOS, WSL and Git Bash. Single-quoted, backslash line continuations.
How cURL Command Generator works
Two languages meet in a curl command and only one of them is HTTP. The other is your shell, which reads the line first, decides where each argument begins and ends, and hands curl an array of strings it has already rewritten. Quoting is how you tell the shell to stop rewriting. Get it wrong and the failure does not look like a quoting failure — it looks like the API rejecting a payload it never received in full.
Single quotes are the safest wrapper in bash and zsh because nothing inside them is interpreted: no dollar signs, no backticks, no backslash escapes. A payload containing $HOME, a regular expression, or a Windows path arrives byte for byte. The price is that an apostrophe cannot appear inside them at all, since the first one encountered simply ends the run. The only construction that works is to close the quoted run, emit an escaped apostrophe on its own, and open a new run — which is why an order note reading it is urgent comes out as four characters where one was typed. It looks like a typo and it is the correct answer.
Windows is a different language again rather than a formatting preference. The classic console has no literal-quote construct whatsoever, so a payload full of double quotes has to be wrapped in double quotes and escaped from the inside, following the argument rules of the Microsoft C runtime rather than anything the console itself defines. Those rules also mean a run of backslashes touching the closing quote must be doubled, or a path ending in one swallows the remainder of the line. PowerShell doubles apostrophes instead of escaping them and continues a wrapped line with a backtick where bash uses a backslash. Copying a working bash command into either one fails on the first payload that contains a quote.
Beyond quoting, a handful of flags mean something other than what they appear to. Naming a method explicitly alongside a payload flag is redundant, because supplying data already selects POST, and the explicit form additionally suppresses the method rewriting that happens on a redirect. Asking for a header-only response by naming the method makes the transfer hang, because the tool still waits for a response body that a header-only reply will never contain; the dedicated flag is the one that means what people mean. And the short data flag quietly deletes line breaks from what it is given and treats a leading at-sign as a path on disk, so a payload beginning with one is read as a filename rather than sent.
Reference
- posix: wrap in ' … ' and rewrite each interior ' as '\'' — close, escape, reopen
- powershell: wrap in ' … ' and double each interior ' as ''
- cmd: wrap in " … ", precede each interior " with a backslash, and double any backslash run that meets a quote
- line continuation: backslash (bash/zsh) · backtick (PowerShell) · caret (cmd)
- valueless header: -H 'Name;' sends an empty one — -H 'Name:' deletes it instead
- body flags: --data-raw sends verbatim · -d strips line breaks and expands @file · -F builds a multipart part · --data-urlencode percent-encodes one field
How to use this generator
Give it a destination and a verb
The address and the method come first, because a header and a payload have nowhere to go without them. The method also decides which flags are redundant, so choosing it changes what appears in the output.
Fill the rows
Headers, query parameters and form fields are all name-and-value grids, and a block copied out of a browser network panel can be pasted straight into one — it splits into rows on the first separator of each line. Unticking a row keeps it around without sending it.
Pick where the payload comes from
Choosing a payload kind sets the type header for you, which is the step most often skipped by hand. Structured payloads are checked as you type and reported without blocking, since half-finished ones are normal while debugging.
Choose the shell it is going to run in
The three targets differ in their wrapper character, their escape rule and their line-continuation marker. Switching between them rewrites every quoted argument rather than merely reflowing the text.
Copy it, redacted if it is going anywhere public
The plain copy carries real credentials. The second copy swaps each one for a variable name, which keeps the command runnable for whoever receives it while leaving nothing usable in a ticket or a chat log.
Worked examples
An apostrophe inside a structured payload
- Given
- A note field whose text reads it is urgent, written with an apostrophe
- Result
- The payload is emitted with '\'' where the apostrophe was
Four characters replace one. Written naively the run would end at the apostrophe, the shell would split what follows into separate words, and the server would receive a truncated fragment that is still syntactically plausible.
The same payload aimed at the Windows console
- Given
- A structured payload full of double quotes, targeting cmd
- Result
- Wrapped in double quotes with every interior one preceded by a backslash
The apostrophe needs nothing here and the double quotes need everything, which is the exact inverse of the bash case. This is why a copy button that only relabels its output is worse than none.
A method that does not need naming
- Given
- A POST carrying a structured payload
- Result
- The payload flag appears; the explicit method flag does not
Supplying data already selects the method. Writing both is the most reliable tell of a machine-generated command, and it changes redirect behaviour in a way nobody intended.
A file part with no type header
- Given
- One part naming a file on disk and one plain text part
- Result
- Two part flags and deliberately no type header
The tool generates a unique separator string between parts and writes the header itself. A hand-written one omits that separator, so the receiving end cannot tell where each part begins.
A header with nothing in it
- Given
- A trace header whose value is left blank
- Result
- -H 'X-Trace;' rather than -H 'X-Trace:'
The colon form is the documented way to REMOVE a header that would otherwise be sent automatically. The semicolon form is how you send one with an empty value — two spellings one character apart that do opposite things.
When to use it
- Turning a request that works in a browser into a reproducible line you can paste into a bug report, a runbook or a continuous-integration job.
- Handing a colleague a way to reproduce an API failure without also handing them your access token, by copying the redacted form instead.
- Producing a Windows-safe version of a line that a Linux teammate wrote, without discovering the incompatibility halfway through an incident call.
- Building a first request against unfamiliar documentation, where the interesting question is which headers an endpoint wants rather than how to spell them on a command line.
- Translating a working command into browser code, since the same description renders both and the two cannot drift apart.
- Checking whether an endpoint is reached at all before writing any client code against it.
Things to watch out for
- Nothing typed here is stored or transmitted. There is no saved draft, no address-bar state and no analytics property carrying any field, because the main input of a tool like this one is a credential.
- A credential passed as a command-line argument is visible to every user on the machine through the process table, and it lands in shell history as well. The pre-encoded header form avoids the process table but not the history file; a credentials file read from disk avoids both.
- Skipping certificate checks removes hostname, chain and expiry validation together. It silences the warning by deleting the check that produced it, so a line carrying that flag must never be pasted into anything that handles real traffic.
- Query values are percent-encoded on the safe side. A few characters that need no encoding are encoded anyway, which every receiver accepts, whereas the opposite mistake silently truncates a value at the first ampersand.
- Carriage returns and line feeds are removed from header names and values. Those characters terminate a header line, so leaving one in place would split a single request into two — usually the result of pasting a value with its line ending still attached.
- The browser-code rendering is equivalent, not identical. Redirect handling differs by default between the two, an on-disk file part has to become a file object chosen by the user, and a credential given as a command-line argument has to become a header because there is no other place for it.
Frequently asked questions
Why does an apostrophe come out as four characters?
Because a single-quoted run in bash or zsh cannot contain one, and there is no escape for it inside the run. The sequence closes the run, emits one escaped apostrophe outside any wrapper, and opens a fresh run. It is ugly, it is what experienced people type by hand, and it is the only construction that survives word splitting intact.
Why is the method flag missing from my POST?
Because supplying a payload already selects it, so writing it out adds nothing. It is not merely redundant either: naming the method explicitly also stops the automatic rewriting that normally happens when a redirect is followed, which turns a working request into a puzzling one. Requests with no payload still get the flag, since nothing else would set the verb.
Can I paste the bash output into PowerShell?
Not once it contains a double quote, which any structured payload does. PowerShell doubles apostrophes rather than escaping them and wraps continued lines with a backtick, so the bash form is read as several broken commands. Switch the target shell instead and every argument is rewritten for it.
Why is there no content type on my file upload?
Because setting it by hand breaks the request. Multipart bodies are separated by a unique boundary string that the tool generates at send time and announces in the header it writes itself. A hand-written header carries no boundary, so the receiving end has a declared format it cannot parse and rejects the whole thing.
What does the redacted copy actually change?
Every credential value becomes a shell variable name while the surrounding structure, including the scheme word that precedes a token, stays exactly as it was. The result is safe to paste into an issue tracker and still runnable by whoever reads it, once they export the variable with their own value.
Can it read an existing command back into the form?
Not yet, and it is deliberate rather than forgotten. Reading one back means recognising a flag vocabulary of roughly two hundred and fifty options, where anything unrecognised has to be reported rather than silently dropped. That is a different problem from writing one out, and it deserves its own treatment rather than a partial version bolted on here.
Related DevOps tools
All devops tools- Cron Expression Parser Read a cron line in plain English, expand every field, and see the next ten firings in local time and UTC.
- CIDR / Subnet Calculator Turn an IPv4 or IPv6 prefix into netmask, broadcast, usable range and host count — then split it, compare it, or aggregate a range.
- chmod / Unix Permissions Calculator Bind permission checkboxes, octal and symbolic modes together — including setuid, setgid, sticky and what a umask leaves behind.
- Uptime & SLA Calculator Convert an availability target into allowed downtime per day, month and year, track the error budget, and chain several services together.
- Kubernetes Resource Converter Convert CPU and memory quantities between every suffix Kubernetes accepts, and catch the ones that mean a billion times what you meant.
- YAML ↔ JSON Converter Convert either way with key order and comments-free fidelity, then see every scalar whose written form and parsed value disagree.