Logo

MonoCalc

/

cURL to Code Converter

Programming

Shell

Runs only if the server allows your page's origin (CORS). Uses top-level await: paste it into the DevTools console or an ES module.

curl command

Browser fetch

Notes

No notes: the command converts cleanly.

Command map

Each option and its value, in the order you pasted them. Click a row for the full decoded value.

Request

What the command sends. Chips show what the Browser fetch code changes.

POST

https://api.example.com/v1/users?page=2

Scheme

https

Host

api.example.com

Port

443 (default)

Path

/v1/users

Query (1)

NameValue
page2

Headers (3)

NameValueSource
Content-Typeapplication/json
-H
X-Request-Id42
-H
Authorization

Basic auth

ada:••••••
-u

Body

JSON · 79 bytes

{ "name": "Ada Lovelace", "roles": [ "admin", "editor" ], "active": true, "manager": null }

About This Tool

cURL to Code Converter – Turn Any curl Command Into Working Code

API documentation, Postman and the browser's DevTools all speak one common language: curl. Right-click a request in the Network panel, choose Copy as cURL, and you have a complete, reproducible HTTP request. The hard part is turning that one-liner into code your application can run. This cURL to code converter reads the command the way a shell and curl itself would, then writes the same request as browser fetch, Node.js fetch, Axios, Python requests, Go net/http, PHP cURL, Java HttpClient, Ruby Net::HTTP or a raw HTTP/1.1 message.

How the conversion works

Conversion happens in three steps. First the pasted text is split into words using the rules of the shell it came from. Bash quoting, $'…' ANSI-C strings and backslash line continuations are handled, and so is the caret escaping that Chrome's Copy as cURL (cmd) produces for Windows. Next, every curl option is applied to a request model: the method, URL, headers, cookies, Basic or bearer auth, body and connection settings such as timeouts, redirects, proxies and TLS verification. Finally a generator for each language writes idiomatic code from that model.

Next to the code, the request breakdown shows what the command actually does. The command map lists every option in the order you pasted it, colour-coded by role, with options that only affect curl's own output struck through. The request card splits the URL into scheme, host, port and path, decodes the query string, lists every header with the flag that produced it, and pretty-prints the body. Hover a row on either side to see how they connect.

curl behaviour the tool reproduces

Many small curl rules change the request, and they are easy to miss when converting by hand:

CommandWhat curl actually sends
-d a=1 -d b=2A POST with body a=1&b=2 and application/x-www-form-urlencoded
-G --data-urlencode 'q=a b'A GET with ?q=a+b in the URL and no body
--json '{…}'Content-Type and Accept set to application/json
-H 'Accept:'Removes curl's own header, but never one you set with another -H
-T notes.txt https://host/files/A PUT to /files/notes.txt: the file name is appended to a URL ending in a slash

When something can't be expressed in a target language, the tool says so in the notes panel instead of dropping it silently. Each target tab shows how many warnings it has, so you can see at a glance which language converts your request cleanly.

Differences between languages

HTTP libraries don't behave alike, and the generated code accounts for that. Browsers refuse to let scripts set forbidden headers such as Cookie, Origin and Host, so those are written as comments. Accept-Encoding is removed because each library negotiates compression and decompresses the reply itself. Repeated headers are combined for libraries that store headers in a map, and Basic auth with non-ASCII credentials becomes a ready-made Authorization header, because library helpers disagree on how to encode it. JSON bodies can be written as native objects for easy editing or kept as exact text, which matters when a server checks a signature over the raw bytes.

Treat pasted commands like passwords
A command copied from DevTools usually carries live session cookies and tokens. The converter runs entirely in your browser and never sends the request, but the generated code still contains those secrets. Switch on Hide secrets before you paste code into a ticket or a chat.

Tips for clean results

  • Turn on Remove browser-only headers to drop sec-fetch-*, sec-ch-ua* and similar noise from DevTools copies.
  • If the shell is detected wrongly, pick Bash/POSIX or Windows cmd yourself: backslashes and quotes mean different things in each.
  • Replace placeholders such as $TOKEN with real values. Shell variables are kept as written, never expanded.
  • Use --data-binary @file rather than -d @file when the exact bytes matter, because curl strips line breaks from -d files.

Frequently Asked Questions

Is the cURL to Code Converter free?

Yes, cURL to Code Converter is totally free :)

Can I use the cURL to Code Converter offline?

Yes, you can install the webapp as PWA.

Is it safe to use cURL to Code Converter?

Yes, any data related to cURL to Code Converter only stored in your browser (if storage required). You can simply clear browser cache to clear all the stored data. We do not store any data on server.

How does this cURL to code converter work?

It splits the pasted command into words the way bash or Windows cmd would, reads every curl option into a request model (method, URL, headers, auth, body and connection settings), and then writes that request in the language you pick. Parsing and code generation run entirely in your browser.

Does this tool send my request or my cookies anywhere?

No. The tool never runs the request and makes no network calls with your command. Copied commands often contain live session cookies and tokens, so treat the generated code like a password, or switch on Hide secrets before sharing it.

Why does the browser code comment out Cookie, Origin or Host?

Browsers don't let scripts set these forbidden headers. Cookies are sent automatically for same-site requests, or with credentials: "include" when the server allows it, and the browser always sets Origin and Host itself.

Why did Accept-Encoding disappear from the code?

Each library asks for compression and decompresses the reply on its own. Setting the header by hand turns that off in Go and Ruby, so you would get compressed bytes back. The raw HTTP view still shows it, because it mirrors what curl sends.

curl doesn't follow redirects, but the generated code does. Why?

Without -L, curl stops at a 3xx response, while fetch, Axios, requests and Go follow redirects by default. PHP's cURL and Java's HttpClient don't, so the tool only turns redirects on for them when you used -L. Ruby's Net::HTTP never follows them, so the tool adds a note instead.

Which curl options are supported?

Everything that shapes the request: method, URL, headers, cookies, Basic and bearer auth, data, forms, uploads, timeouts, TLS verification, redirects and proxies. Options that only change curl's own output are ignored, and anything else is listed as not converted.