HTTP Request Tester sends an API request from your browser and turns the whole exchange into a clean write-up you can paste anywhere: the request’s URL, headers and body, then the response’s status, headers and body, as Markdown or plain text. API keys, bearer tokens, cookies and passwords are replaced with REDACTED on the way out, so the write-up is safe to share. Paste a cURL command and you can export it without sending anything at all. No account, no proxy, nothing saved.
How to copy an API request as Markdown
- Open Import a cURL command and paste one — from your browser’s Network tab (right-click a request, then Copy as cURL), from API docs, or from your terminal history. Or fill in the method, URL, headers and body yourself.
- Press Send to include the response, or skip it: the write-up is ready either way.
- In Export, choose Markdown or Plain text. Hide credentials and tokens is already on.
- Copy it, or download it as a
.mdor.txtfile.
Example: a request with secrets in it
This cURL command carries an API key in its URL, a bearer token in a header and a card token in its body:
curl 'https://api.shop.example/v2/payments?api_key=key_EXAMPLE_4f9a' \
-H 'Authorization: Bearer tok_EXAMPLE_live_91c2' \
-H 'Content-Type: application/json' \
--data-raw '{"amount":4200,"currency":"gbp","card_token":"card_EXAMPLE_7d1e","customer":"cus_1042"}'Sent, it came back as a declined payment whose response included a client_secret. This is the Markdown the tool writes — generated by the same code the page runs:
# POST https://api.shop.example/v2/payments?api_key=REDACTED
Sent 2026-09-30 14:03 UTC · **402 Payment Required** · 284 ms
## Request
**Method:** POST
**URL:** https://api.shop.example/v2/payments?api_key=REDACTED
### Headers
| Header | Value |
| --- | --- |
| Authorization | REDACTED |
| Content-Type | application/json |
### Body
```json
{
"amount": 4200,
"currency": "gbp",
"card_token": "REDACTED",
"customer": "cus_1042"
}
```
## Response
**Status:** 402 Payment Required
**Time:** 284 ms · **Size:** 118 B
### Headers
| Header | Value |
| --- | --- |
| content-type | application/json |
| x-request-id | req_8Hq2 |
### Body
```json
{
"error": {
"code": "card_declined",
"message": "Your card was declined."
},
"client_secret": "REDACTED"
}
```
---
_Credentials and tokens were replaced with REDACTED._
The key, the token, the card token and the client secret are gone. The amount, the customer ID, the error code and the request ID — everything someone needs to help — are still there.
What gets hidden
- Credential headers:
Authorization,Proxy-Authorization,Cookie,Set-Cookie, and API-key, auth-token and CSRF headers. - Secrets in the URL: query parameters such as
api_key,access_token,code,signatureandX-Amz-Credential. - Secrets in bodies, sent and received: fields named like
password,token,secret,api_keyorclient_secret, in JSON and form data. - JWTs anywhere, whatever they are called.
- Copies: once a value is known to be secret, every other appearance of it is removed too.
Names, email addresses and other personal details are not secrets in this sense and stay in. Read the write-up before you post it somewhere public. Turn the option off if you need the full values for yourself.
Where a write-up saves time
Bug reports and GitHub issues. “The API returns 500” gets a question back; the exact request and response get an answer. Markdown renders as tidy header tables and formatted JSON in GitHub, GitLab, Jira, Linear and Notion. Slack and Teams threads. Paste it to a colleague without leaking your token into a channel history that is searchable for years. Support tickets and emails to an API provider, where plain text reads better than Markdown symbols. API documentation, pull requests and runbooks, where a real request and response is the clearest example there is. Stack Overflow questions, where a leaked key is public within minutes.
Sending requests from your browser
Choose a method, enter the URL, add headers such as Authorization and a JSON, form or text body, and press Send. You get the status, time, size, body and headers straight away, and the write-up updates to include them. Requests go directly from your browser to the API, so they behave like a request from any web page — which brings one important limit.
When a request is blocked: CORS
A web page can only read an API’s response if the API allows it, using CORS headers such asAccess-Control-Allow-Origin. Postman and curl are not web pages, so the rule does not apply to them — which is why a request can work there and fail here. Most large public APIs allow browser requests, including GitHub, Stripe, OpenAI, Slack, Google, Spotify and Notion; many private and internal APIs do not. When a request fails, the tool checks whether the server answered at all and tells you which case it is, and the request can still be exported or copied as cURL to run in a terminal. To turn a command into code, use thecURL to Fetch converter; to clean a whole browser recording rather than one request, use the HAR Analyzer & Sanitizer.
What stays private
The request is sent only to the address you enter, directly from your browser. Your cookies for that site are never attached, so the page cannot act as you on it, and no Referer is sent. The write-up is made in the page. Nothing is stored — no history, no saved requests — so reloading starts again. This is the only page on the site allowed to connect to other websites; every other tool is blocked from doing so by its Content Security Policy.
Browser limits worth knowing
- Headers you cannot set: Cookie, Host, Origin, Referer and a few others are controlled by the browser. The page warns when you add one.
- Headers you cannot see: only the response headers the server exposes to pages are shown.
- Plain http:// is blocked from a secure page, except for
localhost. - GET and HEAD requests cannot carry a body in a browser.
Frequently asked questions
Can I get a Markdown write-up without sending the request?
Yes. Paste a cURL command, or fill in the request, and the export is ready straight away — the response section just says it was not sent. That is often all you need for a bug report or a question, and it works for any API, including ones that block browser requests.
What exactly is hidden when I export?
Authorization and Proxy-Authorization headers, cookies, API-key and CSRF headers; tokens, codes, keys and signatures in the URL; fields such as password, access_token, refresh_token and client_secret in JSON and form bodies, in the request and the response; and anything shaped like a JWT. Every value removed is also removed wherever else it appears. Each one is replaced with REDACTED, so the reader can see something was there.
Why does a request fail here but work in Postman or curl?
Browsers only let a web page read an API’s response when the API allows it, through CORS headers. Postman and curl are not web pages, so the rule does not apply to them. Many public APIs allow it — GitHub, Stripe, OpenAI, Slack and Google among them — but plenty do not. When that is the reason, this page says so, and the request can still be exported or copied as cURL.
Does my request go through your servers?
No. The request goes straight from your browser to the address you enter, and the response comes straight back. We never see either. Nothing is saved: reloading the page forgets it.
Markdown or plain text?
Markdown for anywhere that renders it — GitHub and GitLab issues and pull requests, Jira, Confluence, Notion, Linear, Slack and most wikis — where headers become tables and bodies become formatted code blocks. Plain text for email, support forms and chat tools that show Markdown symbols literally.
Why are some headers ignored or missing?
Browsers do not let pages set a few headers themselves — Cookie, Host, Origin, Referer among them — and the page warns if you add one. In responses, a page can only read the headers the server chooses to expose, so some may be missing compared with curl.
Last updated