Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

REST API Tester (Online API Client)

A Postman-style API client in this tab — requests go straight from you to the API.

Developer Uses live data Free to try, no sign-up Pro tool Pro pass from ₹49

Request

Ctrl+Enter (⌘+Enter) sends. Write {{name}} to use a variable from the environment. Paste a curl … command into the URL box to import it.

Examples:

Response

Send a request to see the response here.

Code

 
Import a cURL command

Collections

Import a Postman collection (v2.0 or v2.1) or environment, an OpenAPI 3 or Swagger 2.0 description, or a HAR file saved from your browser’s DevTools — JSON or YAML. Every request is listed below; choose one to load it. The file is read on this device only.

Paste a collection instead

History

Requests you send appear here (stored only in this browser).

    Next steps

    About the REST API Tester (Online API Client)

    Build an HTTP request — method, URL, query parameters, headers, a JSON, form, multipart, raw or file body, and Bearer, Basic or API-key auth — and send it with one click or Ctrl+Enter. The response appears with its status, time, size, the headers the server exposes and a pretty-printed body (JSON numbers are shown exactly as sent, even very large IDs). Image responses are previewed and any body can be downloaded.

    Requests go straight from your browser to the API: there is no MySmartCoPilot server in between, so the page cannot be used as a proxy and never sees your data or tokens. That also means the browser’s rules apply — the API has to allow cross-origin requests (CORS), and the page explains, before you send, whether a preflight will be needed and why. Use {{variables}} with saved environments, re-run anything from History, paste a cURL command to import it, and copy every request as cURL, fetch() or Python requests code.

    Under Collections you can import a whole API at once: a Postman collection (format v2.0 or v2.1) or environment, an OpenAPI 3 or Swagger 2.0 description in JSON or YAML, or a HAR file saved from your browser’s DevTools. Every request is listed by folder; choose one to load it, with its headers, body and authentication, and the file’s variables and server address in an environment.

    How to use it

    1. Choose the method and type the URL. Query parameters typed in the URL appear in the Params tab and stay in sync both ways.
    2. Add headers, a body and authentication on the other tabs. A JSON body is checked before sending and gets Content-Type: application/json automatically.
    3. Press Send (or Ctrl+Enter / ⌘+Enter). Read the status, time and size, then switch between Pretty, Raw and Headers.
    4. Save base URLs and tokens as variables under Edit environments, write them as {{baseUrl}} in the request, and pick the environment from the list.
    5. Copy the request as cURL, fetch() or Python from the Code panel, or paste a cURL command (for example “Copy as cURL” from DevTools) into the URL box to import it.
    6. To work through a whole API, import its Postman collection, OpenAPI/Swagger file or a HAR file under Collections, fill in the variables the page names (such as {{token}}) under Edit environments, then choose requests from the list.

    Examples

    A GET request with a query string
    Input
    GET https://jsonplaceholder.typicode.com/todos?userId=1&completed=false
    Result
    200 OK · JSON array, pretty-printed · Params tab shows userId = 1, completed = false

    JSONPlaceholder is a free public test API that allows cross-origin requests.

    POST JSON with a bearer token
    Input
    POST {{baseUrl}}/orders
    Auth: Bearer {{token}}
    Body: {"sku": "A1", "qty": 2}
    Result
    curl 'https://api.example.com/orders' \
      --location \
      -H 'Authorization: Bearer …' \
      -H 'Content-Type: application/json' \
      --data-raw '{"sku": "A1", "qty": 2}'

    The page also warns that this needs a CORS preflight: the Content-Type and Authorization header are not CORS-safelisted.

    Common uses

    • Trying an endpoint while reading its documentation, without installing a desktop client.
    • Checking what an API really returns — status, headers and body — when your app shows an error.
    • Debugging CORS: seeing whether a request is “simple” or needs a preflight, and which headers cause it.
    • Converting a request from DevTools into cURL or fetch() code for a bug report or a script.
    • Re-running requests against local, staging and production with one environment switch.

    Why some requests fail in the browser but work in cURL

    Browsers protect you with the same-origin policy: a page may read a response from another site only if that site agrees, by sending Access-Control-Allow-Origin (the CORS protocol in the WHATWG Fetch Standard). For anything beyond a “simple” request — methods other than GET, HEAD and POST, custom headers such as Authorization, or a JSON Content-Type — the browser first sends an OPTIONS preflight, and the server must allow the method and headers too. When the server does not, the browser hides the whole response and reports only a network error, which is why this page lists the possible reasons instead of guessing one. Public APIs meant for browsers (and your own API with CORS enabled) work; for the rest, copy the request as cURL and run it in a terminal.

    This tester deliberately has no proxy server: a proxy would hide CORS problems you need to fix, and would be an open relay that others could abuse.

    What a browser will not send

    • The forbidden headers of the Fetch Standard — Cookie, Host, Origin, Referer, Content-Length, Connection, anything starting with Sec- or Proxy- and a few others — are dropped; the page warns when you add one.
    • CONNECT, TRACE and TRACK requests, and GET or HEAD requests with a body.
    • Cookies only go along with Send this browser’s cookies (and only if the API allows credentials); Set-Cookie in responses is never readable by a page.
    • This page is served over HTTPS, and its security policy only allows HTTPS connections: plain http:// addresses — including a local server on http://localhost — are blocked. Serve the API over HTTPS or use the cURL command.

    Your data and tokens

    Nothing passes through MySmartCoPilot: requests go from your browser to the API you name. History, environments and the current request are stored only in this browser’s local storage. By default, tokens, passwords, API keys, Authorization-style headers and secret-looking query values, form fields and JSON members (such as api_key, access_token, X-Amz-Signature, client_secret or password) are blanked before anything is saved — tick “Remember auth values” on the Auth tab only on your own device. Values written as {{variables}} are kept, because the secret itself lives in the environment. Files you attach are never stored.

    Limitations

    • Only APIs that allow cross-origin requests from this site (CORS) return readable responses. There is no server-side relay, by design.
    • Only response headers the server exposes to scripts are shown; DevTools’ Network tab shows all of them, including Set-Cookie.
    • Detailed timing (DNS, TLS, waiting) appears only when the server sends Timing-Allow-Origin; otherwise you get the total time.
    • WebSocket, Server-Sent Events and GraphQL schema browsing are not included. Imported collections are a list of requests to send one at a time: Postman pre-request and test scripts, dynamic variables such as {{$guid}}, and OAuth flows are not run.
    • OpenAPI files that refer to other files ($ref: other.yaml#/…) import without those parts; bodies are built from the examples, defaults and types in the file.
    • Request bodies up to about 100 KB are saved with history; attached files must be chosen again after a reload.

    Privacy

    Your request goes directly from your browser to the API you enter — never through MySmartCoPilot. History and environments are kept only in this browser.

    Frequently asked questions

    Why do I get “The browser could not complete the request” when the API works in Postman?

    Postman and cURL are not browsers, so CORS does not apply to them. Here the API must send Access-Control-Allow-Origin for this site (and allow the preflight for non-simple requests). Check the CORS note under the request, and the Console tab of your browser’s DevTools, which names the exact header that was missing.

    Is it safe to put my API token here?

    The token goes only from your browser to the API you call — never to MySmartCoPilot. It is not saved unless you tick “Remember auth values”. As with any web page, use test or short-lived tokens where you can, and prefer environment variables like {{token}} so tokens stay out of the URL.

    Can I test an API running on my own computer?

    Only over HTTPS: this page’s security policy allows HTTPS connections only, so http://localhost cannot be reached. Give your local server a trusted development certificate (for example with mkcert) and enable CORS for this site, or copy the request as cURL. Some browsers also ask for permission before a website may reach your local network.

    How do I import a request from my browser’s DevTools?

    In the Network tab, right-click the request and choose Copy → Copy as cURL (on Windows, pick the “bash” variant), then paste it into the URL box or into “Import a cURL command”. The method, URL, headers, body and auth are filled in; options that make no sense in a browser are listed as ignored.

    Can I import my Postman collection or an OpenAPI (Swagger) file?

    Yes. Under Collections, choose a Postman collection exported as v2.0 or v2.1 (or a Postman environment), an OpenAPI 3 or Swagger 2.0 file in JSON or YAML, or a HAR file from DevTools. Folders, headers, bodies, query parameters and Bearer, Basic or API-key authentication are imported; OpenAPI request bodies are filled from the file’s examples. The file’s variables and server address go into a new environment — fill in empty ones such as {{token}} there. The file is read in your browser and never uploaded.

    Why is the response time different from what my server logs show?

    The time here is measured in your browser from sending the request to receiving the whole body, so it includes DNS, connecting, TLS, the network round trip and any CORS preflight. Server logs usually measure only the processing time.

    Quick answers and tool search

    Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.