cURL to Fetch Converter

Paste a cURL command and get clean JavaScript fetch() code — parsed locally, never sent to a server. Safe for commands containing API keys.

Advertisement

How it works

Paste any cURL command — multi-line commands with \ continuations work too. The converter tokenizes it like a shell would, then maps each piece to the fetch() equivalent: -X becomes method, every -H becomes a headers entry, -d becomes the body, and -u user:pass becomes a Base64 Authorization header. A JSON body is pretty-printed inside JSON.stringify(...); multipart -F fields become FormData.

Private by design

Most "curl to code" sites upload your command to their server — a problem when the command carries a Bearer , cookies, or API keys. This page has no backend: conversion is plain JavaScript running on your machine. Paste secrets with confidence.

FAQ

Is my cURL command sent to a server?
No. Parsing happens entirely in your browser with JavaScript — nothing is uploaded or stored. That matters because cURL commands often contain API keys, tokens, and cookies.
Which cURL options are supported?
The converter understands the URL, -X/--request, -H/--header, -d/--data (and --data-raw, --data-binary, --data-urlencode), --json, -F/--form, -u/--user, -b/--cookie, -A/--user-agent, -e/--referer, -G/--get, -I/--head, -k/--insecure, -L/--location, and --url. Anything else is ignored and listed in the notes.
Why is there a warning about the Cookie header?
Cookie is a forbidden header name in browsers, so fetch() silently strips it. The generated code is correct for Node.js 18+ and other server runtimes; in a browser, rely on real cookies with credentials: 'include' instead.
Does -d really mean POST?
Yes. curl switches to POST when you pass -d without -X, and sends the body as application/x-www-form-urlencoded unless you set your own Content-Type. The converter mirrors both defaults, and with -G it moves the data into the query string instead.
Advertisement