HTTP conversion workflow
Convert cURL to Fetch without changing bodies or hiding browser limits
A command that works in a terminal can still fail in browser Fetch. Convert the request description, then check the browser's rules separately.
Content updated: · Maintainer and corrections
Use one static POSIX command
Supported options are -X/--request, -H/--header, -d/--data, --data-raw, literal --data-binary, --json, -I/--head, -L/--location and --url. POSIX single/double quotes and backslash-newline continuations are parsed as data, up to 128 KiB UTF-8. Quote URLs containing shell metacharacters. Only ASCII space/tab delimit words. Bare internal newlines are rejected; quoted newlines and backslash-newline continuations are preserved.
Environment expansion, command substitutions, backticks, pipelines, redirection, multiple URLs, unknown options and @file inputs stop conversion. --data-raw preserves an initial @ literally. User/password authentication via -u and mixed ordinary/JSON data modes are intentionally unsupported.
Preserve the bytes represented by the body
Ordinary repeated data parts join with &, while repeated --json parts concatenate directly. Data implies POST unless an explicit method is supplied. Ordinary data defaults to application/x-www-form-urlencoded; --json supplies application/json Content-Type and Accept unless overridden.
The converter never parses and reserializes JSON. A value such as 222222222222222222 must stay exactly as written instead of being rounded through a JavaScript Number. GET and HEAD bodies are rejected because browser Fetch cannot represent them. Custom method case is preserved. Explicit DELETE/GET/HEAD/OPTIONS/POST/PUT must use uppercase, since Fetch otherwise normalizes these methods and changes the source spelling.
Review headers, redirects and CORS
Header pairs retain source order and duplicates in generated code, although the browser may combine them. Browser-controlled headers, including Cookie, Host, Origin and Content-Length, are omitted with visible warnings. This does not reproduce terminal cookies or credentials.
Fetch uses redirect:manual by default to mirror cURL without -L. Manual redirect responses can be opaque; -L selects follow. CORS, TLS and browser credential policies still apply. No no-cors workaround is added, and CONNECT, TRACE and TRACK are rejected.
Redact before sharing
Known sensitive headers such as Authorization and X-API-Key become [REDACTED] in preview, copy and download until you explicitly reveal them. The source textarea remains visible. This is not complete private-data detection: query strings, bodies and custom headers can still disclose secrets.
The tool never executes cURL or Fetch, contacts the represented API, uploads inputs, stores them or inserts them in URLs or input analytics. Editing removes exports and resets reveal. Source snapshot: 2026-10-09. Review exported code before running it elsewhere.
Data provenance