⇄ Code & API Conversion

cURL to C# HttpClient Converter (and fetch, Python, Go, PHP)

Paste a curl command — including Chrome's "Copy as cURL" for bash or Windows cmd — and get C# HttpClient code, or JavaScript fetch, axios, Python requests, PHP or Go.

C# HttpClient first bash, cmd & PowerShell input Best-effort redaction 6 languages

Loading cURL Converter…

What this page sends

  • Your input: The command is parsed in this tab and the request itself is never executed. With redaction on (the default), recognizable credentials are replaced before code is generated. Detection is best-effort; review generated code and share links before copying or sharing.
  • Share links: Share links put a Base64 copy of your input and output in the URL itself (after #d=). Anyone with the link can read it, so don't share a link that contains secrets.
  • Editor: On desktop screens the code editor (Monaco) is downloaded from cdn.jsdelivr.net; phones get a built-in lightweight editor instead.
  • Page load: Loading the page requests HTML, scripts and images from ByteKiln, fonts from Google Fonts, and sends Google Analytics page views, tool-usage events and catalog interactions (tool/category IDs, result status and whether a click followed search — never your input, output or search terms). Privacy & sharing

How the cURL to C# HttpClient Converter (and fetch, Python, Go, PHP) Works

"Copy as cURL" is the fastest way to capture a request exactly as the browser sent it — the URL, method, every header and the body — but curl syntax is not something you can paste into a C# project. Translating it by hand means untangling shell quoting first: bash single quotes and $'…' strings, Windows cmd's ^ escapes in Chrome's cmd variant, or PowerShell backticks. Then each curl flag has to be mapped onto the target library correctly. -d implies POST and a form-urlencoded body, -G moves that data into the query string, -F builds multipart form data, -u is basic authentication, and --compressed means the client must decompress the response. In .NET there are extra traps: content headers must live on HttpContent, a manually set Cookie header is ignored unless the cookie container is turned off, and a new HttpClient per request exhausts sockets. This converter parses the command with the same quoting rules as the shell it came from, builds a neutral description of the request, and generates idiomatic code for C# HttpClient, JavaScript fetch, Node axios, Python requests, PHP cURL and Go net/http — with anything that could not be translated listed instead of silently lost.

Reading the command

The input style is detected from its line continuations (\, ^ or `) and quoting. bash input supports single, double and $'…' ANSI-C strings; cmd input is un-escaped the way cmd.exe does and then split with the Windows argument rules, so Chrome's \^" sequences come out as plain quotes; PowerShell input supports '' and backtick escapes. Only the first command of a chain (&&, |, ;) is used, and you are told when that happens.

Understanding curl options

Long and short options are both read, including combined flags like -sSL, attached values like -XPOST and --opt=value. -d, --data-raw, --data-binary, --data-urlencode and --json follow curl's own rules for methods, content types and @file references, -G builds the query string, -T uploads a file with PUT, and credentials in the URL become basic authentication.

Generating C#

The C# output uses a single static HttpClient, an HttpRequestMessage with the right HttpMethod, TryAddWithoutValidation for browser headers such as sec-ch-ua that would fail strict validation, content headers on the content, FormUrlEncodedContent or MultipartFormDataContent where appropriate, AutomaticDecompression for --compressed, UseCookies = false when a Cookie header is present, and EnsureSuccessStatusCode.

Credentials

Authorization, Cookie and API-key style headers, basic-auth passwords, token-like query parameters and password-like form or JSON fields are detected. With redaction on (the default) their values are replaced before code is generated, and the share link is built from a redacted curl command reconstructed from the parsed request — never from your original paste.

Limitations

  • Files referenced with -d @file, --data-binary @file and -F field=@file are not read; the generated code has a placeholder path for you to fill in.
  • Options with no equivalent in the generated code — --retry, --limit-rate, proxies, client certificates, cookie jars — are listed as not converted rather than approximated.
  • The request is never executed, so the tool can't tell whether it works or what the response looks like.
  • Generated code follows each library's common usage; production code still needs your error handling, timeouts and retries.
  • Credential redaction uses recognizable names and patterns. Unusual secret fields may survive; review generated code and the share preview before copying or sharing.

FAQ

Short answers for the things developers usually ask before trusting a tool.

Is my curl command or token uploaded anywhere?

No. The command is parsed and the code generated in your browser, and the request itself is never sent. "Redact credentials" is on by default, replacing Authorization and Cookie headers, API-key headers, basic-auth passwords and secret-looking query parameters or fields with REDACTED. Redaction is best-effort: unusual credential names may be missed. Review generated code and the share preview before copying or sharing; sharing is disabled when a recognized credential is present and redaction is off.

How do I copy a request from Chrome, Edge or Firefox as curl?

Open DevTools, go to the Network tab, right-click the request and choose Copy → Copy as cURL. On Windows, Chrome offers both "Copy as cURL (cmd)" and "Copy as cURL (bash)"; this tool reads both, plus curl.exe commands written for PowerShell with backtick line continuations.

Why does the C# code use one static HttpClient?

Creating a new HttpClient for every request leaves sockets in TIME_WAIT and can exhaust them under load. The generated code keeps one shared static client and creates a new HttpRequestMessage per call. In an ASP.NET Core app, register a typed or named client with IHttpClientFactory instead.

Why is Content-Type set on request.Content instead of request.Headers?

In .NET, Content-Type, Content-Length and the other content headers belong to HttpContent. Adding them to request.Headers throws "Misused header name". The converter moves them onto the content object, and if the curl command sets Content-Type without sending a body, it leaves a comment explaining why the header was dropped.

What happens with -k / --insecure?

Disabling certificate validation is included only as commented-out code with a warning, in every language. Leaving it active by default would make it too easy to ship code that accepts any certificate, which defeats HTTPS.

What about -d @file, -F file=@photo.jpg and flags that have no equivalent?

The browser cannot read files from your disk, so file references are kept as paths the generated code opens when it runs — make sure the path is valid there. Flags such as --retry or --proxy that the target language can't express directly are listed under the output as ignored, rather than silently dropped.

Related tools

Useful follow-ups when one conversion usually turns into three more.

Want the background and worked examples? There's a longer write-up.

Read the cURL Converter guide