cURL Probe
Google Cloud • AI & Developer Infrastructure
No Probe Executed Yet
Click "Send Request" above or press Cmd+Enter to dispatch the HTTP probe and inspect the live response.
cURL Probe & HTTP Verification Architecture
cURL Probe translates shell commands into client-side browser fetch requests, displays round-trip network latency, formats JSON bodies, and bundles request-response snapshots into compressed URL hashes without a backend database.
How It Works (In-Memory Execution)
- Shell Tokenization: Parses multi-line bash or PowerShell cURL commands into structured HTTP verbs, target URIs, custom headers, and payload data entirely inside browser memory.
- Direct Browser Probe: Executes the HTTP request through standard browser fetch APIs, measuring millisecond precision latency via performance.now().
- Header & Body Inspection: Automatically detects JSON responses, prettifies objects with syntax highlights, and tabulates response headers.
- State Compression: Encodes the full request parameters and response snapshot into a URL hash via LZ-String for frictionless collaboration with zero remote database storage.
Supported cURL Parameters & Flags
| Parameter / Token | Description | Example |
|---|---|---|
| -X, --request <METHOD> | Specifies custom request method (GET, POST, PUT, DELETE, PATCH, etc.) | curl -X POST https://api.site.com |
| -H, --header <HEADER> | Appends extra request header in Key: Value format | curl -H "Authorization: Bearer token" |
| -d, --data <DATA> | Sends HTTP POST data payload. Defaults method to POST if unspecified | curl -d '{"key":"value"}' https://api.site.com |
| --data-raw <DATA> | Sends raw data without interpreting the leading @ character as a file path | curl --data-raw "query={id}" https://api.site.com |
| -A, --user-agent <NAME> | Specifies custom User-Agent identifier sent to the remote HTTP server | curl -A "CustomBot/1.0" https://api.site.com |
| -u, --user <USER:PWD> | Sets username and password, translated to Basic HTTP Authentication header | curl -u admin:secret https://api.site.com |
| -k, --insecure | Terminal flag allowing insecure SSL connections. In browser, managed by browser security | curl -k https://self-signed.local |
Frequently Asked Questions
Q: Are my API keys, tokens, or request payloads uploaded to DevCraft servers?
No. DevCraft operates 100% in-memory within your browser RAM. HTTP requests are dispatched directly from your browser fetch runtime to the target endpoint. No third-party proxy, database, or logging mechanism ever sees your tokens.
Q: Why do I see a CORS error when probing certain APIs?
CORS (Cross-Origin Resource Sharing) is a security mechanism enforced by web browsers. When your browser sends an HTTP request to another domain, the destination server must return an 'Access-Control-Allow-Origin' header permitting browser requests. Native terminal cURL bypasses this because it is not a web browser. When CORS occurs, you can click 'Copy cURL' to test in your terminal, or paste the terminal response snapshot directly into the tool.
Q: Can I probe local development APIs (e.g., http://localhost:3000)?
Yes! Because the HTTP probe runs inside your local browser instance, it can reach your local development servers, Docker containers, and private LAN endpoints as long as your local server allows CORS.
Q: Does opening a shared link automatically trigger the HTTP request?
No. To protect recipients against unexpected server side effects (such as accidental DELETE or POST actions), opening a shared link loads the cURL configuration and response snapshot passively. A fresh probe only executes when the recipient clicks 'Send Request' or 'Probe Again'.