cURL to Code Converter
Paste a curl command, get the same request in your language.
In Chrome, Edge or Firefox: DevTools → Network → right-click a request → Copy → Copy as cURL (bash or cmd). The command is only converted, never run, and stays in your browser.
Notes from the converter
What this request does
About the cURL to Code Converter
Paste a curl command — typed by hand, copied from API documentation, or taken from your browser with Copy as cURL — and get the same request as code: Python requests, JavaScript fetch, Node.js axios or got, Go net/http, PHP, Java, Kotlin, C#, Rust, Ruby, Swift, Dart, PowerShell, HTTPie, wget, Ansible and more, 47 targets in all. Headers, cookies, query strings, JSON and form bodies, file uploads (-F), basic auth (-u), --compressed, -k, -L, proxies and timeouts are carried over.
The command is read the way bash reads it — quotes, $'…' strings, \ line continuations, $VARIABLES — using curlconverter and the tree-sitter bash grammar, which run in your browser as WebAssembly. Windows Copy as cURL (cmd) commands with ^ escapes are decoded too. Under the code you see what the request does, with a warning when it carries credentials such as an Authorization header or session cookies. Nothing is uploaded and the request is never sent.
How to use it
- In Chrome or Edge DevTools, open the Network tab, right-click a request and choose Copy → Copy as cURL (on Windows, Copy as cURL (bash) or Copy as cURL (cmd) — both work). Or type or paste any curl command, or pick an example.
- Paste it into the box. The code appears as you type.
- Choose the language in Convert to, or click one of the popular ones. The choice is remembered.
- Read the notes under the code (options the language cannot express, environment variables the code reads) and the summary of what the request does.
- Copy the code or download it. Replace any credentials before you share it.
Examples
curl 'https://api.example.com/v1/search?q=coffee+mugs&limit=20' \ -H 'accept: application/json' \ -H 'authorization: Bearer YOUR_TOKEN' \ --compressed
import requests
headers = {
'accept': 'application/json',
'authorization': 'Bearer YOUR_TOKEN',
}
params = {
'q': 'coffee mugs',
'limit': '20',
}
response = requests.get('https://api.example.com/v1/search', params=params, headers=headers)The query string becomes params (with + decoded to a space); requests decompresses responses itself, so --compressed needs no code.
curl -X POST https://api.example.com/v1/orders \
-H 'Content-Type: application/json' \
-d '{"sku": "KB-104", "quantity": 2}'fetch('https://api.example.com/v1/orders', {
method: 'POST',
headers: {
'Content-Type': 'application/json'
},
// body: '{"sku": "KB-104", "quantity": 2}',
body: JSON.stringify({
'sku': 'KB-104',
'quantity': 2
})
});curl ^"https://api.example.com/v1/items?limit=10^" ^
-H ^"content-type: application/json^" ^
--data-raw ^"^{^\^"name^\^":^\^"Widget^\^"^}^"The same code as for: curl 'https://api.example.com/v1/items?limit=10' -H 'content-type: application/json' --data-raw '{"name":"Widget"}'cmd escapes every special character with ^; the tool decodes them the way cmd.exe and the C runtime would before converting.
Common uses
- Turning a request you made in the browser (with its headers and body) into a script or a test.
- Using the curl examples from API documentation (Stripe, GitHub, OpenAI-style APIs …) in your own language.
- Moving a Postman or terminal request into application code.
- Checking what a long copied curl command actually sends before you run it.
How curl options are read
-X/--requestsets the method;-dwithout-Xmakes it a POST,-Gsends the-ddata as a query string instead, and-I/--headmakes a HEAD request.-d/--datasends form data (application/x-www-form-urlencoded, as curl does);--data-rawsends the text as is;--data-binary @file.jsonsends a file;--data-urlencodeencodes each value. With-H 'Content-Type: application/json'the body is read as JSON and becomes a native object where the language has one (Pythonjson=,JSON.stringifyin JavaScript).-F/--formmakes amultipart/form-dataupload;-F '[email protected]'uploads the file.-u user:passwordis basic authentication;-bsends cookies;-Hadds headers.--compressed,-k/--insecure,-L/--location,-x/--proxy,--max-time,--connect-timeoutand-obecome the matching settings where the language has them — otherwise the notes say what was left out.$TOKENand${TOKEN}become reads of environment variables (os.getenv('TOKEN')in Python), and$(command)is run by the generated code; both are pointed out.
Credentials in copied commands
A command copied from DevTools carries what the browser sent: often an Authorization header, session cookies or an API key in the URL. They end up in the generated code. The summary under the code names every credential it finds — headers such as Authorization, Cookie or X-API-Key, -u passwords, cookies, URL parameters such as api_key or token, and body fields such as password — so you can replace them with environment variables before you commit or share the code. The conversion itself happens on your device; nothing is sent to MySmartCoPilot or to the API.
Limitations
- Only curl commands are converted. Commands joined with
&&, loops and functions are refused (put several commands on separate lines instead); pipes such as| jq .and redirections such as> out.jsonare left out of the code, and the notes say so. - Some curl options have no equivalent in some languages (for example a whole-request
--max-timein Python requests, or HTTP/2); the notes list what could not be carried over. - Files named with
@(uploads,--data-binary @file) are read by the generated code at run time; the tool never reads them. - The first conversion downloads the converter and its bash grammar (about 360 KB compressed); after that it works offline.
Privacy
Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot. The first conversion downloads the converter and its bash parser (about 360 KB compressed) from this site once; after that it works offline. Your command is never sent anywhere.
Frequently asked questions
Is the request sent anywhere?
No. The command is parsed and converted in your browser and never executed — nothing reaches MySmartCoPilot or the API in the command. That also means the tool cannot tell whether the request would succeed.
Which “Copy as cURL” should I use on Windows?
Either. Chrome and Edge on Windows offer Copy as cURL (bash) and Copy as cURL (cmd); the cmd version escapes characters with ^, which the tool detects and decodes. Choose Command style if the automatic detection guesses wrong.
Why is my JSON body converted to an object instead of a string?
When the command sets Content-Type: application/json and the body is valid JSON, most targets write it as a native object (json= in Python, JSON.stringify({...}) in JavaScript) and keep the original text in a comment, because the result may differ in spacing from what you pasted.
Can it convert code back to curl?
No — this tool goes from curl to code. Browser DevTools can copy any request as curl directly.
What does the warning about lowercase headers mean?
Browsers copy HTTP/2 requests with lowercase header names. Most libraries send HTTP/1.1, which is fine for almost every server; the note only tells you the protocol may differ.