dev/converter
cURL Converter - Free & Instant | Smocky
Reads a cURL command (bash, zsh, or Windows cmd), a HAR archive, a raw HTTP request, an HTTP request file (.http), or a Postman collection (v2.1 or v2.0). Pasted text and files are read in your browser and the request is never sent. Generated request code is a starting point to review, not a verified client.
Frequently asked questions
Why does the generated code turn off redirects?
cURL does not follow redirects unless you pass -L, so each Output target is told the same: fetch uses redirect: "manual", Axios maxRedirects: 0, Python requests allow_redirects=False, Go a CheckRedirect that returns http.ErrUseLastResponse, and Guzzle allow_redirects => false. HTTPie already stops at the first response. With -L the code follows redirects instead. In a browser, fetch with redirect: "manual" returns an opaque response rather than the redirect itself.
How is -k (--insecure) converted?
Each target gets its own way to skip TLS certificate checks: an https.Agent with rejectUnauthorized: false for Axios, verify=False for Python requests, InsecureSkipVerify: true in a Go tls.Config, verify => false for Guzzle, and --verify=no for HTTPie. JavaScript fetch has no such setting, so the Tool warns that -k is not reproduced there.
What happens to files named with @ or -F?
A value such as -d @body.json or -F [email protected] is a File reference: a local file the Tool cannot read. Data read from a file appears as a marked placeholder like <contents of body.json>. Multipart files are opened by path at run time (openAsBlob in Node.js, open() in Python, os.Open in Go, fopen in PHP, [email protected] in HTTPie); browser fetch gets a marked empty Blob to replace. Every File reference is listed as a warning.
Are shell variables like $TOKEN expanded?
No. $TOKEN, ${TOKEN}, $(command), backticks, and cmd %VAR% references are kept as literal text, because the Tool never runs a shell. Each one is reported with its position so you can replace it with the real value.
Which shells can I paste from?
bash and zsh quoting, including backslash line continuations and $'...' strings, and Windows cmd as produced by Chrome DevTools "Copy as cURL (cmd)", with ^ escapes and continuations. PowerShell commands such as Invoke-WebRequest are rejected; copy the request as cURL (bash) or cURL (cmd) instead. Pipes, &&, ;, redirection, and --next are rejected because one cURL command describes one request.
Are my tokens and cookies safe?
The command is parsed in your browser and the request is never sent. Authorization headers, cookies, and -u credentials are copied into the Generated request code unchanged, and the Tool shows a notice when they are present so you can remove them before sharing the code.
Which request formats can I convert?
A cURL command, a HAR archive exported from browser DevTools, a raw HTTP request, an HTTP request file (.http) from VS Code REST Client or JetBrains, and a Postman collection (v2.1 or v2.0). The Input format is detected automatically and shown; choose it yourself when text could be read more than one way. HAR, .http, and Postman sources can hold many requests: pick one from the list, and filter it by method, URL, or name.
Is it safe to open a HAR file here?
HAR archives usually contain live session cookies and tokens, so the Tool warns about it. The file is read in your browser and never uploaded. Each HAR entry becomes one request: HTTP/2 pseudo-headers such as :authority and the content-length header are dropped, the Cookie header is used rather than the cookies list, and recorded responses are ignored.
How are Postman variables, auth, and scripts handled?
Postman collection variables are substituted; a {{variable}} that only an environment defines stays literal with a warning. Auth is inherited from the folder or collection as Postman does. Basic, bearer, and API key auth are converted; OAuth 1.0 and 2.0, digest, AWS Signature, and other auth types are listed as not converted. Disabled headers, query params, and form fields are skipped, and pre-request and test scripts are ignored with a warning. Postman v1 collections are rejected; export as v2.1.
What about .http file variables and names?
File variables such as @host = api.example.com are substituted wherever {{host}} appears, and # @name login names the request in the list. A dynamic variable like {{$guid}} or {{$dotenv KEY}} is generated by the HTTP client when it sends the request, so it stays literal with a warning. A body of < ./payload.json becomes a File reference, response handler scripts are ignored, and requests follow redirects unless marked # @no-redirect, as in the HTTP clients.
How does a raw HTTP request get its URL?
A request line with a full URL, such as GET https://api.example.com/items HTTP/1.1, is used as-is. A request line with only a path, such as POST /login HTTP/1.1, is combined with the Host header; a raw request does not say whether it used HTTP or HTTPS, so https:// is assumed and noted. Content-Length is dropped because every client recomputes it.
Can I get a cURL command back?
Yes. Choose cURL as the Output target to turn a HAR entry, raw request, .http request, or Postman request into a cURL command. It uses POSIX quoting for bash and zsh by default, or Windows cmd quoting with ^ escapes, as Chrome's "Copy as cURL (cmd)" does. Either one can be pasted back into the Tool and reads as the same request.
What are the limits?
A pasted command or source can contain up to 100,000 UTF-16 code units; opened or dropped files can be up to 10 MiB and hold up to 5,000 Request entries. A command can contain up to 1,000 headers and data parts, and Generated request code up to 1,000,000 code units. Oversized input is reported rather than truncated. Options that only change what cURL prints, such as -s or -o, are noted as having no effect; other cURL options the Tool does not convert are listed as warnings.