Skip to content
UniKit

HTTP request builder

Assemble an HTTP request visually — method, URL, query parameters, headers, a JSON / form / text body and Bearer or Basic auth — and get the final URL, the complete header list and paste-ready curl, fetch, Python requests and raw HTTP output, plus warnings for header injection, bodies on GET and credentials over plain http. Code only, no requests are sent.

Runs in your browserEvery computation happens in your browser — your data never leaves this device.

Request parameters

Everything is assembled locally: no request is sent and the target server is never contacted — the output is just code you run yourself.

Query parameters
Headers

Result

Final URLhttps://api.example.com/v1/users?page=1
Warnings(1)

· The request contains Authorization / Cookie — redact it before pasting into scripts or logs.

Final headers(3)
Content-Typeapplication/json
X-Request-Idabc123
AuthorizationBearer test-token
Final body{"name":"Ada"}
Output format
curl -X POST 'https://api.example.com/v1/users?page=1' \
  -H 'Content-Type: application/json' \
  -H 'X-Request-Id: abc123' \
  -H 'Authorization: Bearer test-token' \
  --data-raw '{"name":"Ada"}'

What this tool does

  • Hand-writing curl for docs or a bug report tends to drop the Content-Type or mangle the quoting — assemble the request here and copy a correct one.
  • Move a working request to another stack: export the same parameters as curl, fetch, Python requests and a raw HTTP message instead of translating by hand.
  • Debug “what the server received is not what I meant”: inspect the final URL encoding, the final header list and the final body to see whether an auto-added Content-Type overrode yours.
  • Security sanity check: a stray newline pasted into a header is rejected outright (header injection), and Authorization over plain http raises a warning.

Example

Input

Method POST; URL https://api.example.com/v1/users; query page=1; header X-Request-Id: abc123; JSON body {"name":"Ada"}; auth Bearer test-token

Output

curl -X POST 'https://api.example.com/v1/users?page=1' \
  -H 'Content-Type: application/json' \
  -H 'X-Request-Id: abc123' \
  -H 'Authorization: Bearer test-token' \
  --data-raw '{"name":"Ada"}'

The Content-Type is auto-added from the body type and placed first; switching to Python emits requests.post(..., params=[("page", "1")], headers={...}, data=...).

Frequently asked questions

Does this tool send the request for me?

No. It only assembles parameters into a request and code snippets — no request is sent and the target server is never contacted, so nothing probes your service or leaves an access log entry. To actually fire it, copy the curl command into a terminal or the fetch snippet into a browser console.

Why are newlines rejected in headers?

HTTP header fields are separated by CRLF. If a value can smuggle CRLF in, it can inject an extra header or even a whole response — that is header injection (HTTP request/response splitting). The tool therefore validates values before generating anything, and also checks that header names match the RFC 9110 token syntax.

How are query parameters encoded?

As RFC 3986 percent-encoding: bytes are taken as UTF-8 and unsafe characters are escaped, so a space becomes %20 rather than + (the + shorthand only means space in form encoding). Any query string already present in the URL is kept first and the parameters you enter are appended after it.

Is the JSON body reformatted?

No — it is emitted exactly as typed; the tool only checks whether it parses as JSON (an invalid body gets a warning but is still emitted). That way you can paste snippets with template variables safely. Switching the type to Form serializes each `name=value` (or `name: value`) line into `application/x-www-form-urlencoded` text.

How is the Basic auth header computed?

Per RFC 7617 the string `username:password` is UTF-8 encoded and base64-encoded with standard `=` padding, giving `Authorization: Basic <base64>`. Remember base64 is not encryption — anyone who sees the request can recover the credentials, so always use https.

Keywords:http request buildercurl generatorfetch snippetpython requestsraw http messageheader injectionHTTP 请求构建curl 生成请求头查询参数Bearer 认证原始报文

Related tools