---
title: "cURL HTTP Cheatsheet | FindUtils"
description: "GET, POST JSON, headers, auth, redirects, TLS, and useful script flags"
url: https://findutils.com/cheatsheets/curl-http/
---

# cURL HTTP Cheatsheet

GET, POST JSON, headers, auth, redirects, TLS, and useful script flags 36 commands in 7 sections, filed under [Web Development](https://findutils.com/cheatsheets/web/).

## Requests

- `curl https://example.com/`: GET a URL
- `curl -I https://example.com/`: Headers only (HEAD)
- `curl -i https://example.com/`: Include response headers
- `curl -X PUT URL`: Set the HTTP method
- `curl -X DELETE URL`: DELETE a resource
- `curl -X PATCH URL`: PATCH a resource

## Bodies

- `curl -d "a=1&b=2" URL`: POST form-encoded data
- `curl -d @file.txt URL`: POST body from a file
- `curl --json '{"ok":true}' URL`: POST JSON with type headers
- `curl --json @data.json URL`: POST JSON from a file
- `curl -F "file=@photo.png" URL`: Multipart file upload
- `curl --data-urlencode "q=a b" URL`: URL-encode a field

## Headers and auth

- `curl -H "Accept: application/json" URL`: Add a request header
- `curl -H "Authorization: Bearer TOKEN" URL`: Send a bearer token
- `curl -u user:pass URL`: HTTP Basic auth
- `curl -A "MyAgent/1.0" URL`: Set User-Agent
- `curl -e https://referrer.example/ URL`: Set Referer
- `curl -b "sid=abc" URL`: Send a Cookie header

## Output

- `curl -o file.bin URL`: Write the body to a file
- `curl -O URL`: Save using the remote filename
- `curl -sS URL`: Silent progress, still show errors
- `curl -v URL`: Verbose request and response
- `curl -w "%{http_code}\n" -o /dev/null -s URL`: Print the status code
- `curl --compressed URL`: Ask for compressed content

## Redirects and TLS

- `curl -L URL`: Follow redirects
- `curl -k URL`: Skip TLS certificate check
- `curl --cacert ca.pem URL`: Trust a custom CA file
- `curl --cert client.pem --key key.pem URL`: Send a client certificate
- `curl --tlsv1.2 URL`: Require TLS 1.2 or newer where supported

## Timeouts and scripts

- `curl --connect-timeout 5 URL`: Cap the connect phase
- `curl --max-time 30 URL`: Cap the whole transfer
- `curl -f URL`: Fail on HTTP error status
- `curl --fail-with-body URL`: Fail on HTTP error, keep the body
- `curl -fsSL URL`: Silent, fail, show errors, follow redirects
- `curl -D headers.txt URL`: Write response headers to a file

## Sources

- `https://curl.se/docs/manpage.html`: curl manual: HTTP requests, redirects, authentication, TLS, and script options.

## Related

- Cheatsheet: [React Hooks](https://findutils.com/cheatsheets/react-hooks/)
- Cheatsheet: [CSS Flexbox](https://findutils.com/cheatsheets/css-flexbox/)
- Cheatsheet: [CSS Grid](https://findutils.com/cheatsheets/css-grid/)
- Guide: [HTTP Request Builder: Send Public HTTP Calls Safely](https://findutils.com/guides/http-request-builder-guide/)
- Guide: [Postman to cURL Guide: Convert Collections into Portable Commands](https://findutils.com/guides/postman-to-curl-guide/)
- Guide: [HAR Viewer: Inspect DevTools Logs in Your Browser](https://findutils.com/guides/har-viewer-guide/)
- Tool: [HTTP Status Code Lookup](https://findutils.com/network/http-status-code-lookup/)
- Tool: [HTTP Request Builder](https://findutils.com/developers/http-request-builder/)
- Tool: [Security Headers Analyzer](https://findutils.com/network/security-headers-analyzer/)
