Developer tool · runs in your browser
Convert a cURL command to Python, JavaScript, PHP or Go
Paste a command from your browser's network tab, API docs or terminal. The code updates as you type, with headers, auth and body carried over.
Free · no account · no job limit · nothing is uploaded
Line breaks with a trailing backslash, quotes and a leading $ prompt are read the way a shell reads them.
Python · requests
JavaScript · fetch
PHP · curl
Go · net/http
Request details: method, URL, body and headers
| Name | Value |
|---|
What you get from one pasted command
Code in four languages
- Python with
requests - JavaScript with
fetch - PHP with the curl extension
- Go with
net/http
A readable summary
- Method, URL and body type at a glance
- A table of every header the request sends
- Long token values shortened in the table only, never in the code
Warnings you can act on
- A note when the command carries a token, cookie or password
- A list of flags that were ignored, instead of silently dropping them
- Comments where a language cannot copy curl exactly
How the command is read
Quotes and line breaks like a shell
The command is parsed the way sh reads it, not with a pattern match. Single quotes protect everything inside them. Double quotes let escaped quotes and backslashes through. A backslash at the end of a line joins it to the next. That matters for the awkward cases: a header value with a quote in it, a JSON body with escaped quotes inside, or a password with a dollar sign.
Flags that are converted
-X, -H, -d with --data, --data-raw, --data-binary, --data-ascii and --data-urlencode, -F and --form-string, -u, -G, -I, -A, -b, -e, --json, --oauth2-bearer, --compressed, -L, -k, -m, --url and a bare URL anywhere in the command. Anything else is listed above the output as ignored.
Where the method comes from
An explicit -X always wins. Without it, -I means HEAD, a body from -d, -F or --json means POST, and everything else is GET. -G moves the -d data into the query string and keeps the method as GET.
What cannot be copied exactly
A browser's fetch cannot skip certificate checks, so -k becomes a comment in the JavaScript output. @filename in a body or form part stays a filename with the code to open it, because this page never reads your files. --compressed is already the default in Python, JavaScript and Go, so only the PHP output sets it.
Tokens stay in the code
A command copied from a browser's network tab usually carries a session cookie or a bearer token, and that token works until it expires. The generated code keeps it unchanged so you can test straight away. Move it into an environment variable before you commit the code or paste it into a chat.
Questions before you run it
Which languages does the converter write?
Python with requests, JavaScript with fetch, PHP with its curl extension and Go with net/http. All four are written at once from the same command; the tabs only change which one you see.
Does it keep authentication?
Yes. Authorization headers, basic auth from -u, tokens from --oauth2-bearer and cookies from -b are carried into the code with their values unchanged. When the command holds something that looks like a credential, the page says so above the output.
Can I paste a multiline command?
Yes. Paste it exactly as it appears in your terminal or docs. Backslash line continuations, single and double quotes, escaped quotes inside a JSON body and a leading $ prompt are all handled.
What happens to flags such as --compressed or -k?
--compressed is the default in Python, JavaScript and Go, so only the PHP output sets it. -k turns off certificate checks in Python, PHP and Go; fetch cannot do that, so the JavaScript output gets a comment instead. Flags the page does not convert are listed above the output.
Is my cURL command sent to a server?
No. Parsing and code generation run in your browser. Your endpoints, headers and tokens stay on your device.