Skip to content

HTTP Request Tester

Sends an HTTP request from your browser — built by hand or pasted as cURL — and writes the request and response up as Markdown or plain text, with tokens and passwords hidden.

Sent only where you point it

Your request is sent straight from your browser to the address you enter, and nowhere else. Nothing passes through our servers, and nothing is saved: closing the page forgets it. How this works

Try:
Import a cURL command
Copy one from your browser’s Network tab with “Copy as cURL”, or from API docs.

Request

    Requests go straight from your browser to the address you enter, without passing through our servers. Your cookies for that site are not sent, and nothing here is saved: reloading the page clears it.

    HTTP Request Tester sends an API request from your browser and turns the whole exchange into a clean write-up you can paste anywhere: the request’s URL, headers and body, then the response’s status, headers and body, as Markdown or plain text. API keys, bearer tokens, cookies and passwords are replaced with REDACTED on the way out, so the write-up is safe to share. Paste a cURL command and you can export it without sending anything at all. No account, no proxy, nothing saved.

    How to copy an API request as Markdown

    1. Open Import a cURL command and paste one — from your browser’s Network tab (right-click a request, then Copy as cURL), from API docs, or from your terminal history. Or fill in the method, URL, headers and body yourself.
    2. Press Send to include the response, or skip it: the write-up is ready either way.
    3. In Export, choose Markdown or Plain text. Hide credentials and tokens is already on.
    4. Copy it, or download it as a .md or .txt file.

    Example: a request with secrets in it

    This cURL command carries an API key in its URL, a bearer token in a header and a card token in its body:

    curl 'https://api.shop.example/v2/payments?api_key=key_EXAMPLE_4f9a' \
      -H 'Authorization: Bearer tok_EXAMPLE_live_91c2' \
      -H 'Content-Type: application/json' \
      --data-raw '{"amount":4200,"currency":"gbp","card_token":"card_EXAMPLE_7d1e","customer":"cus_1042"}'

    Sent, it came back as a declined payment whose response included a client_secret. This is the Markdown the tool writes — generated by the same code the page runs:

    # POST https://api.shop.example/v2/payments?api_key=REDACTED
    
    Sent 2026-09-30 14:03 UTC · **402 Payment Required** · 284 ms
    
    ## Request
    
    **Method:** POST  
    **URL:** https://api.shop.example/v2/payments?api_key=REDACTED
    
    ### Headers
    
    | Header | Value |
    | --- | --- |
    | Authorization | REDACTED |
    | Content-Type | application/json |
    
    ### Body
    
    ```json
    {
      "amount": 4200,
      "currency": "gbp",
      "card_token": "REDACTED",
      "customer": "cus_1042"
    }
    ```
    
    ## Response
    
    **Status:** 402 Payment Required  
    **Time:** 284 ms · **Size:** 118 B
    
    ### Headers
    
    | Header | Value |
    | --- | --- |
    | content-type | application/json |
    | x-request-id | req_8Hq2 |
    
    ### Body
    
    ```json
    {
      "error": {
        "code": "card_declined",
        "message": "Your card was declined."
      },
      "client_secret": "REDACTED"
    }
    ```
    
    ---
    
    _Credentials and tokens were replaced with REDACTED._
    

    The key, the token, the card token and the client secret are gone. The amount, the customer ID, the error code and the request ID — everything someone needs to help — are still there.

    What gets hidden

    Names, email addresses and other personal details are not secrets in this sense and stay in. Read the write-up before you post it somewhere public. Turn the option off if you need the full values for yourself.

    Where a write-up saves time

    Bug reports and GitHub issues. “The API returns 500” gets a question back; the exact request and response get an answer. Markdown renders as tidy header tables and formatted JSON in GitHub, GitLab, Jira, Linear and Notion. Slack and Teams threads. Paste it to a colleague without leaking your token into a channel history that is searchable for years. Support tickets and emails to an API provider, where plain text reads better than Markdown symbols. API documentation, pull requests and runbooks, where a real request and response is the clearest example there is. Stack Overflow questions, where a leaked key is public within minutes.

    Sending requests from your browser

    Choose a method, enter the URL, add headers such as Authorization and a JSON, form or text body, and press Send. You get the status, time, size, body and headers straight away, and the write-up updates to include them. Requests go directly from your browser to the API, so they behave like a request from any web page — which brings one important limit.

    When a request is blocked: CORS

    A web page can only read an API’s response if the API allows it, using CORS headers such asAccess-Control-Allow-Origin. Postman and curl are not web pages, so the rule does not apply to them — which is why a request can work there and fail here. Most large public APIs allow browser requests, including GitHub, Stripe, OpenAI, Slack, Google, Spotify and Notion; many private and internal APIs do not. When a request fails, the tool checks whether the server answered at all and tells you which case it is, and the request can still be exported or copied as cURL to run in a terminal. To turn a command into code, use thecURL to Fetch converter; to clean a whole browser recording rather than one request, use the HAR Analyzer & Sanitizer.

    What stays private

    The request is sent only to the address you enter, directly from your browser. Your cookies for that site are never attached, so the page cannot act as you on it, and no Referer is sent. The write-up is made in the page. Nothing is stored — no history, no saved requests — so reloading starts again. This is the only page on the site allowed to connect to other websites; every other tool is blocked from doing so by its Content Security Policy.

    Browser limits worth knowing

    Frequently asked questions

    Can I get a Markdown write-up without sending the request?

    Yes. Paste a cURL command, or fill in the request, and the export is ready straight away — the response section just says it was not sent. That is often all you need for a bug report or a question, and it works for any API, including ones that block browser requests.

    What exactly is hidden when I export?

    Authorization and Proxy-Authorization headers, cookies, API-key and CSRF headers; tokens, codes, keys and signatures in the URL; fields such as password, access_token, refresh_token and client_secret in JSON and form bodies, in the request and the response; and anything shaped like a JWT. Every value removed is also removed wherever else it appears. Each one is replaced with REDACTED, so the reader can see something was there.

    Why does a request fail here but work in Postman or curl?

    Browsers only let a web page read an API’s response when the API allows it, through CORS headers. Postman and curl are not web pages, so the rule does not apply to them. Many public APIs allow it — GitHub, Stripe, OpenAI, Slack and Google among them — but plenty do not. When that is the reason, this page says so, and the request can still be exported or copied as cURL.

    Does my request go through your servers?

    No. The request goes straight from your browser to the address you enter, and the response comes straight back. We never see either. Nothing is saved: reloading the page forgets it.

    Markdown or plain text?

    Markdown for anywhere that renders it — GitHub and GitLab issues and pull requests, Jira, Confluence, Notion, Linear, Slack and most wikis — where headers become tables and bodies become formatted code blocks. Plain text for email, support forms and chat tools that show Markdown symbols literally.

    Why are some headers ignored or missing?

    Browsers do not let pages set a few headers themselves — Cookie, Host, Origin, Referer among them — and the page warns if you add one. In responses, a page can only read the headers the server chooses to expose, so some may be missing compared with curl.

    Last updated

    Missing a feature, or need a tool we don’t have? Suggest it.