Curl Command Converter

Turn curl into fetch / axios / requests / Go code, with the parsed request shown first.

The API docs only give curl, your project speaks axios; the incident email contains a curl one-liner you must reproduce in Python. Hand-translating curl is busywork that fails in predictable places: quote escaping, the implicit POST, header casing. This tool tokenizes the command with real shell rules (single quotes, double quotes, $'…', backslash continuations), normalizes it into a structured request, then emits runnable code for each target.

The parsed request is shown first — method, URL, headers, body, basic auth — so you can confirm what the tool understood before reading the generated code. Flags that cannot be mapped silently (like -F's multipart semantics) are never dropped: they surface in an "unmapped" list with per-flag guidance.

Quoting is the number-one curl trap

The single quotes in examples are shell syntax: JSON bodies typically wear single quotes outside and double quotes inside, which breaks the moment you paste into Windows CMD or PowerShell. This tool follows POSIX rules — " and \ inside double quotes, \n and \t inside $'…' — and joins backslash-newline continuations exactly as the shell would.

The implicit POST

curl defaults to GET, but the moment -d/--data appears the method becomes POST — docs routinely omit the -X POST. The tool reproduces the real semantics: data present with no explicit -X generates a POST, multiple -d values join with & as curl does, and --json also injects the Content-Type header.

Frequently asked questions

Which flags are supported?
The everyday set: -X/--request, -H/--header, the -d family (--data/--data-raw/--data-binary/--json), -F (mapped to guidance), -u/--user, -A/-e/-b (as headers), -k, -L, -I, -G. Unrecognized flags land in the unmapped list rather than vanishing.
Is a curl command with secrets safe here?
Parsing and generation run locally; the command never leaves the page. The generated code does embed the secret verbatim — swap in environment variables before committing.
Why is there no "skip certificate check" in the fetch output?
Browsers do not allow fetch to bypass certificate validation — that is the security meaning of -k. Trust the certificate at the OS level instead; the generated code comments explain this.

Related tools