Client-Side In-MemoryHTTP/1.1 & Fetch Engine

cURL Probe

Ad

Google Cloud • AI & Developer Infrastructure

Learn More
Paste Raw cURL Command
Presets:
Target HTTP Endpoint
Zero server logs. Preserves all raw auth tokens.
Response TelemetryAwaiting request execution...

No Probe Executed Yet

Click "Send Request" above or press Cmd+Enter to dispatch the HTTP probe and inspect the live response.

Zero-Backend HTTP Probe

cURL Probe & HTTP Verification Architecture

cURL Probe translates shell commands into client-side browser fetch requests, displays round-trip network latency, formats JSON bodies, and bundles request-response snapshots into compressed URL hashes without a backend database.

How It Works (In-Memory Execution)

  1. Shell Tokenization: Parses multi-line bash or PowerShell cURL commands into structured HTTP verbs, target URIs, custom headers, and payload data entirely inside browser memory.
  2. Direct Browser Probe: Executes the HTTP request through standard browser fetch APIs, measuring millisecond precision latency via performance.now().
  3. Header & Body Inspection: Automatically detects JSON responses, prettifies objects with syntax highlights, and tabulates response headers.
  4. State Compression: Encodes the full request parameters and response snapshot into a URL hash via LZ-String for frictionless collaboration with zero remote database storage.

Supported cURL Parameters & Flags

Parameter / TokenDescriptionExample
-X, --request <METHOD>Specifies custom request method (GET, POST, PUT, DELETE, PATCH, etc.)curl -X POST https://api.site.com
-H, --header <HEADER>Appends extra request header in Key: Value formatcurl -H "Authorization: Bearer token"
-d, --data <DATA>Sends HTTP POST data payload. Defaults method to POST if unspecifiedcurl -d '{"key":"value"}' https://api.site.com
--data-raw <DATA>Sends raw data without interpreting the leading @ character as a file pathcurl --data-raw "query={id}" https://api.site.com
-A, --user-agent <NAME>Specifies custom User-Agent identifier sent to the remote HTTP servercurl -A "CustomBot/1.0" https://api.site.com
-u, --user <USER:PWD>Sets username and password, translated to Basic HTTP Authentication headercurl -u admin:secret https://api.site.com
-k, --insecureTerminal flag allowing insecure SSL connections. In browser, managed by browser securitycurl -k https://self-signed.local

Frequently Asked Questions

Q: Are my API keys, tokens, or request payloads uploaded to DevCraft servers?

No. DevCraft operates 100% in-memory within your browser RAM. HTTP requests are dispatched directly from your browser fetch runtime to the target endpoint. No third-party proxy, database, or logging mechanism ever sees your tokens.

Q: Why do I see a CORS error when probing certain APIs?

CORS (Cross-Origin Resource Sharing) is a security mechanism enforced by web browsers. When your browser sends an HTTP request to another domain, the destination server must return an 'Access-Control-Allow-Origin' header permitting browser requests. Native terminal cURL bypasses this because it is not a web browser. When CORS occurs, you can click 'Copy cURL' to test in your terminal, or paste the terminal response snapshot directly into the tool.

Q: Can I probe local development APIs (e.g., http://localhost:3000)?

Yes! Because the HTTP probe runs inside your local browser instance, it can reach your local development servers, Docker containers, and private LAN endpoints as long as your local server allows CORS.

Q: Does opening a shared link automatically trigger the HTTP request?

No. To protect recipients against unexpected server side effects (such as accidental DELETE or POST actions), opening a shared link loads the cURL configuration and response snapshot passively. A fresh probe only executes when the recipient clicks 'Send Request' or 'Probe Again'.