cURL Converter
Paste a curl command and get ready-to-run fetch, Axios, Python requests, Go, PHP or Ruby code. Works with Copy as cURL. Runs entirely in your browser.
Most API docs and browser dev tools hand you a curl command, but your project needs JavaScript, Python, Go, PHP or Ruby. This converter parses the command locally and generates idiomatic HTTP client code for six targets, so you can go from a working curl example to a working snippet in seconds without retyping headers, auth or JSON bodies.
fetch("https://api.example.com/users", {
method: "POST",
headers: {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_TOKEN",
},
body: "{\"name\":\"tanaka\",\"age\":30}",
})
.then((res) => res.json())
.then((data) => console.log(data))
.catch((err) => console.error(err));// cURL Converter: Features
Why convert curl commands?
curl is the lingua franca of HTTP. Stripe, GitHub, OpenAI and almost every other API document their endpoints as curl commands, and Chrome, Firefox and Safari can export any network request as one. The trouble starts when you need the same request inside an application: you have to translate flags into method calls, quoting rules into string literals and Basic auth into headers by hand. This tool automates that translation so the request you verified in the terminal is exactly the request your code sends.
Supported output targets
Six targets are supported: fetch (browser and Node.js 18+), Axios, Python requests, Go net/http, PHP with the cURL extension, and Ruby Net::HTTP. Each generator follows the conventions of its ecosystem: fetch and Axios use Promise chains, Python uses the requests keyword arguments for headers, params, data, json and auth, Go builds an http.Request with a context-free client, PHP sets curl_setopt options, and Ruby builds the request object explicitly. Switching targets regenerates the code instantly, so you can compare implementations side by side.
Supported curl options
The parser understands -X/--request, -H/--header, -d/--data/--data-raw/--data-binary/--data-ascii/--data-urlencode, -F/--form for multipart bodies, -u/--user for Basic auth, -b/--cookie, -A/--user-agent, -e/--referer, -L/--location for following redirects, -k/--insecure for skipping TLS verification, -G/--get for sending data as a query string, and -I/--head. Output-only flags such as -s, -S, -v, -i, -f, -O and --compressed are recognized and silently dropped because they do not change the request. Unknown flags are ignored and reported in a warning list so nothing disappears without notice.
Multipart forms, files and edge cases
Simple key=value form fields from -F are converted to FormData in JavaScript, a files or data dictionary in Python, and CURLFile in PHP. Because a browser cannot read your local disk, -d @file and -F field=@file references are replaced with a placeholder and flagged with a warning so you remember to load the file in your own code. Backslash line continuations copied from documentation are handled, and single or double quoted arguments are unwrapped according to shell rules.
Safe to paste a curl command containing a Bearer token
Everything happens in your browser. The curl command you paste, including Authorization headers, Bearer tokens, API keys and Basic auth credentials, is parsed by client-side JavaScript and never transmitted to a server. That makes the tool safe to use with real production credentials while you debug.
// cURL Converter: FAQ
Does it work with "Copy as cURL" from Chrome DevTools?
- Yes. Open the Network tab, right-click a request, choose Copy and then Copy as cURL, and paste the result into the input box. On macOS and Linux the bash variant is what you want. On Windows choose Copy as cURL (bash) rather than the cmd variant, because the cmd version uses caret line continuations and different quoting that the parser does not understand.
What happens to -d @filename or -F field=@path?
- Browsers cannot read arbitrary files from your disk, so file references are replaced with a placeholder such as <file content> and a warning is shown above the output. The generated code is otherwise complete; replace the placeholder with your own file read (fs.readFile, open(), file_get_contents and so on) before running it.
What happens to curl options the tool does not support?
- Unsupported flags are skipped and listed in the warning panel so you can see exactly what was dropped. Method, URL, headers, body, cookies and auth are still converted correctly. Always read the warnings before you paste the output into a project, especially for commands that rely on proxies, client certificates or retry settings.
Is the generated code production ready?
- It is correct for the request itself and ideal for prototyping, tests and quick scripts. For production you should still add error handling, timeouts, retries and proper secret management according to your project standards. Treat the output as an accurate starting point rather than a finished module.
Why does the request work in curl but fail after converting to fetch or Axios?
- When JavaScript runs in a browser it is subject to CORS, which curl ignores. If the API does not return an Access-Control-Allow-Origin header that matches your page, the browser blocks the response even though the request is identical. Running the same fetch code in Node.js or on a server avoids CORS entirely. If you control the API, add the appropriate CORS headers on the server side.
Does the tool validate my JSON body?
- No. The body passed with -d is embedded in the generated code exactly as written. If the JSON is malformed the server will typically respond with 400 Bad Request. Validate the payload with a JSON formatter before converting if you are unsure about the syntax.
How are query strings and -G handled?
- The URL is emitted exactly as you typed it, without re-encoding. When you add -G or --get, any -d values are moved into the query string instead of the body, and the generated code reflects that. Values that contain spaces or non-ASCII characters should already be URL-encoded in the curl command, just as they would need to be for curl itself.
Is Basic authentication converted correctly?
- Yes. The -u user:password flag becomes an auth option in Axios and Python, a SetBasicAuth call in Go, CURLOPT_USERPWD in PHP, basic_auth in Ruby, and a base64-encoded Authorization header in fetch. If you also pass an explicit Authorization header, the explicit header is kept. Tokens sent via headers, such as a JWT, are passed through untouched; you can inspect them with the JWT Decoder.
Can I convert commands from webhooks or scheduled jobs?
- Absolutely. A common workflow is to test a webhook or health check with curl, convert it here, and drop the result into a script that runs on a schedule. If you are wiring that script into crontab, GitHub Actions or a Kubernetes CronJob, the Cron Expression Parser helps you verify the schedule before you deploy.
Is my data sent anywhere?
- No. Parsing and code generation are done entirely by JavaScript in your browser. Nothing you paste, including secrets, is logged or transmitted. You can verify this by loading the page, disconnecting from the network and converting a command; it keeps working.
// How to Use cURL Converter
-
Paste a curl command
Paste your command into the input box. Multi-line commands with trailing backslashes are recognized. Use the SAMPLE buttons to load typical patterns such as POST JSON, GET, FORM or BASIC AUTH if you want to see how a given flag is translated.
-
Choose the output language
Select FETCH, AXIOS, PYTHON, GO, PHP or RUBY. The code regenerates immediately whenever you change the target or edit the command. Any unsupported or partially supported options are listed as warnings above the output.
-
Copy the code
Press COPY to put the generated snippet on your clipboard and paste it into your project. Add error handling, types and timeouts as needed for your codebase.
Category Network