How to use it
- In Chrome, Edge or Firefox open DevTools (F12), go to the Network tab and reload the page.
- Right-click the request you want and choose Copy > Copy as cURL (bash).
- Paste it above and press Convert. You get the same request for
requestsand forhttpx. - Delete the headers you do not need. Browsers send a dozen; most APIs only care about a few (auth, cookies, content type, sometimes a CSRF token or
Referer).
How the output maps to curl
| curl | requests / httpx |
|---|---|
-H 'Name: value' | headers={...} |
?a=1&b=2 in the URL, -G -d | params={...} |
-b 'k=v; k2=v2' or a Cookie: header | cookies={...} |
-d / --data-raw with a JSON body, --json | json=... (a Python dict) |
-d 'a=1&b=2' (form encoded) | data={...} |
any other -d body | data="..." (requests) / content="..." (httpx) |
-F 'file=@photo.jpg' | files={...} |
-u user:pass | auth=("user", "pass") |
-x host:port | proxies= (requests) / proxy= (httpx) |
-k | verify=False |
-L | default in requests; follow_redirects=True in httpx |
A timeout=30 is always added: neither library has a timeout by default, so a stuck server would hang your script forever.
Common mistakes
- Copying expired credentials. Cookies and bearer tokens from DevTools stop working after logout or expiry. Log in from code with a
requests.Sessioninstead when you need it to keep working. - Keeping
Content-LengthorHost. The converter drops them because the library computes them; a stale length breaks the request. - Sending JSON as
data=.data=dictform-encodes the body. Usejson=for JSON APIs. - Leaving
verify=Falsein.-kturns off certificate checks; fix the certificate problem instead of shipping that. - Pasting secrets into online converters. This one does not store anything, but treat any token you paste anywhere as exposed and rotate it if it matters.
FAQ
Is my curl command stored or logged?
No. The command is sent in the body of a POST request, converted in memory and returned in the page. It is never written to disk or put in a URL, so tokens in it do not end up in server logs or browser history. Still, rotate any real secret you paste into a website.
Why does the Python code use json= instead of data=?
When the body is valid JSON, json= lets requests and httpx serialise it and set the Content-Type: application/json header for you, so the code stays readable and you can edit the body as a Python dict.
What is the difference between the requests and httpx versions?
They are almost the same. httpx does not follow redirects unless you pass follow_redirects=True, uses content= for raw bodies and proxy= for a single proxy, and also has an async client (httpx.AsyncClient) and optional HTTP/2.
Which curl options are supported?
-X, -H, -d / --data / --data-raw / --data-binary / --data-urlencode, --json, -F, -u, -b, -A, -e, -G, -L, -k, -I, --compressed, -x and query strings in the URL. Output-only options such as -s, -v and -o are ignored, and anything unknown is listed in the notes.
Does it work with Chrome's Copy as cURL (cmd) or PowerShell output?
Yes for bash and cmd formats: line continuations (\, ^ and `) and cmd's ^ escaping are handled. Chrome's PowerShell format is a different syntax (Invoke-WebRequest), so pick "Copy as cURL (bash)" instead.