Curl Command Practice
curl sends an HTTP request and writes the response to stdout or a file. This track drills methods (-X, -I), bodies (-d, -F), headers, basic auth, -o/-O downloads, and -L redirects — the flags you type against a local API, not a GUI REST client. The same invocations show up in CI, health checks, and one-off debugging.
Command Reference
output
| Command | Description |
|---|---|
curl -O <url> | Save the body using the filename from the URL. |
curl -v <url> | Print request and response details while transferring. |
curl -o <file> <url> | Write the response body to a path you choose. |
curl -i <url> | Print response headers in front of the body. |
curl -s <url> | Hide the progress meter and hide error messages. |
curl -s -o /dev/null -w "%{http_code}" <url> | Print only the HTTP status code and discard the body. |
methods
| Command | Description |
|---|---|
curl -I <url> | Fetch response headers only (HTTP HEAD), not the body. |
curl -X GET <url> | Send an explicit HTTP GET to the URL. |
curl -X POST <url> | Send an HTTP POST with no body flags. |
curl -X PATCH <url> | Send an HTTP PATCH to the URL. |
curl -X PUT <url> | Send an HTTP PUT to the URL. |
curl -X DELETE <url> | Send an HTTP DELETE to the URL. |
redirect
| Command | Description |
|---|---|
curl -L <url> | Follow HTTP 3xx Location redirects to the final response. |
curl -L -i <url> | Follow redirects and print the final headers in front of the body. |
curl -sSL <url> | Follow redirects quietly, but still print errors if the transfer fails. |
curl -L -D - <url> | Follow redirects and write response headers to stdout (before the body). |
request
| Command | Description |
|---|---|
curl <url> | GET the URL and print the response body on stdout. |
curl -H "Content-Type: application/json" -d "<json>" <url> | POST a JSON body with the application/json content type. |
curl -F "<name>=<value>" <url> | POST a multipart form field. |
curl -d "<data>" <url> | POST URL-encoded form fields from the command line. |
curl -d @<file> <url> | POST the contents of a file as the request body. |
curl -G -d "<data>" <url> | Send -d fields on the query string and keep the method as GET. |
curl -F "<name>=@<file>" <url> | Upload a local file as a multipart form part. |
headers
| Command | Description |
|---|---|
curl -H "<name>: <value>" <url> | Add one extra HTTP request header. |
curl -A "<str>" <url> | Set the User-Agent header to a custom string. |
curl -b "<name>=<value>" <url> | Send a Cookie header from a name=value pair. |
curl -b <file> <url> | Load cookies from a file and send them with the request. |
curl -c <file> <url> | Write response cookies into a cookie-jar file. |
curl --compressed <url> | Ask for a compressed response and decode gzip/deflate automatically. |
auth
| Command | Description |
|---|---|
curl -u <user>:<pass> <url> | Send HTTP basic authentication with a username and password. |
curl -k <url> | Skip TLS certificate verification (self-signed local HTTPS). |
curl -k -u <user>:<pass> <url> | Use basic auth against a host whose certificate you do not verify. |
curl -E <file> <url> | Present a client certificate file to the server. |
curl --cacert <file> <url> | Trust a custom CA certificate file for the TLS handshake. |
Key Use Cases
- POST form or JSON to a local API and see the body
- Add an Authorization or Content-Type header
- Follow 3xx redirects instead of stopping on the first Location
- Save the response under a chosen name or the remote filename
- Call an HTTPS host with a self-signed cert during local dev
- Print only the HTTP status code for a health check
Frequently Asked Questions
Does curl -d send GET or POST?
Plain -d defaults to POST with application/x-www-form-urlencoded. Add -G to put that data on the query string and keep GET.
What is the difference between curl -o and curl -O?
-o writes to the path you name. -O (--remote-name) uses the filename from the URL. Wrong flag is a miss on this track.
Why do I still get the redirect body without -L?
Without --location, curl prints the 3xx document and stops. -L follows Location until the final response.
When should I use -k?
-k/--insecure skips TLS certificate checks. Use it for a local self-signed API, not as a habit against the public internet.
Ready to master Curl commands?
Test your muscle memory with our spaced-repetition quiz system. Free forever.
