๐งพ Curl Command Builder
Fill in a method, URL, headers and body and get a ready-to-run curl command โ no need
to remember the flags.
How the command is assembled
Flags go on in a fixed order - method, headers, body, -k, then the URL
last - and every value is wrapped in single quotes, with any embedded quote escaped as
'\''. The default form produces this:
curl \
-H 'Content-Type: application/json' \
-H 'Authorization: Bearer YOUR_TOKEN' \
'https://api.example.com/v1/users'
Switch the method to POST and the same form gains -X POST and
-d '{"name": "Alice"}'. A body is deliberately dropped for GET and HEAD,
and -X GET is never emitted because that is already curl's default.
Things worth knowing before you run it
- The quoting is POSIX. Single quotes and trailing backslashes work
in bash, zsh and Git Bash. In PowerShell the continuation character is a backtick,
and Windows PowerShell aliases
curlto Invoke-WebRequest - callcurl.exethere. - HEAD is a trap. The builder emits
-X HEAD, which leaves curl waiting for a body the server will never send. Use-Iby hand for header-only requests. - -d implies a form content type. Delete the JSON
Content-Typeheader and curl will sendapplication/x-www-form-urlencodedinstead.
Frequently asked questions
Why is there no -X GET in the output?
curl already sends GET, and forcing the method has a side effect: with
-X set, curl keeps that method across a 301 or 302 redirect instead of
switching to GET the way a browser does.
What does the -k flag do?
It tells curl to accept any TLS certificate, including expired and self-signed ones. That is fine against a local dev server, and it removes the protection against an intercepted connection anywhere else - never leave it in a production script.
How do I keep my API token out of shell history?
Export it first and reference it from the header:
export TOKEN=abc, then use a double-quoted
-H "Authorization: Bearer $TOKEN". The single quotes this page emits
would stop the variable expanding, so swap them yourself.