cURL Commands Without Memorizing the Flags
A practical way to read someone else's curl command and build your own — what the common flags actually mean, and two tools that do the tedious part for you.
Someone drops a curl command in a Slack thread or an API doc, and it looks like this:
curl -sS -X POST https://api.example.com/v1/users -H "Authorization: Bearer eyJhbGciOi..." -H "Content-Type: application/json" -d '{"name":"Ada Lovelace","role":"admin"}' --compressed -L
You can probably guess it's making a request to create a user. But which part is the auth token, which flag makes it a POST instead of a GET, and what does -sS even mean stacked together like that? curl has been around since 1998 and accumulated an enormous flag surface in that time — man curl runs to thousands of lines. Nobody has all of it memorized, and nobody needs to. What's actually useful is knowing how to read a command piece by piece, and knowing when to just build one instead of writing it by hand.
Reading a curl command like a sentence
A curl command is really just: the URL, how to talk to it (method, headers, body), and how to behave while doing it (follow redirects, stay quiet, skip cert checks). Once you split it that way, the example above stops being a wall of dashes:
https://api.example.com/v1/users— the URL. Everything else modifies how this gets requested.-X POST— the method. Without this, curl defaults to GET, or POST automatically once you add-d.-H "Authorization: Bearer ..."and-H "Content-Type: application/json"— two headers, one for auth, one telling the server the body is JSON.-d '{"name":"Ada Lovelace","role":"admin"}'— the request body, sent as-is.--compressed— asks for (and auto-decompresses) a gzip'd response.-L— follow redirects if the server sends one.-sS— this is two bundled single-letter flags,-s(silent, hide the progress meter) and-S(but still show errors if something fails). curl lets you stack single-character flags like this instead of writing-s -S.
That's the whole command, and it reads the same way every curl command does: URL plus method plus headers plus body plus behavior flags. Once that shape is familiar, the only real work left is knowing what each individual flag means — which is where a lookup beats memorization. Paste any command into the Curl Command Explainer and it breaks down every flag in that order, expands bundled short flags like -sS into their separate meanings, and tells you the method curl will actually use (including the cases where it's implied rather than explicit, like a plain -d turning a request into a POST).
The flags that come up constantly
A handful of flags cover most real-world commands:
-X/--request— the HTTP method. Skip it for GET; curl also infers POST automatically the moment you add-d.-H/--header— one custom header per flag. Repeat it for each header you need.-d/--data,--data-raw,--data-binary— the request body, with slightly different rules about escaping and whether a leading@means "read this from a file."-F/--form— a multipart form field; add@before a value to upload a file under that field.-u/--user— HTTP Basic auth asuser:password. Bearer tokens instead go through a plain-H "Authorization: Bearer ..."header, since curl has no dedicated bearer flag.-L/--location— follow redirects. Without it, curl stops at the first 3xx and shows you the redirect response instead of chasing it.-k/--insecure— skip TLS certificate verification. Fine for a self-signed cert on localhost, a real gap in production.-o/--output— write the response to a file instead of printing it to the terminal;-Odoes the same but names the file from the URL.-s/--silentand-v/--verbose— opposite ends of the noise dial. Silent hides the progress meter; verbose prints the full request and response, headers included, which is the fastest way to debug why a request isn't behaving the way you expect.
That's a small enough set to actually remember. Everything past it — retry policy, TLS version pinning, proxy auth, parallel transfers — is real but rare, and worth looking up the one time you need it rather than carrying around in your head.
When it's faster to just build the command
Reading is one skill; writing is another, and it's the one that actually eats time — getting quote-escaping right for a JSON body, remembering whether it's --data or --data-raw for this particular case, not forgetting the Content-Type header that makes a JSON POST actually get parsed as JSON server-side. The Curl Command Generator skips all of that: pick a method, fill in the URL, add headers or pick Basic/Bearer auth from two buttons, choose a body type (raw, JSON, URL-encoded form, or multipart), and toggle the options you want (follow redirects, skip TLS verify, compressed, verbose). It handles the shell-quoting itself — every value gets wrapped in single quotes with any embedded quotes escaped correctly, which is the part that trips people up when they hand-write these — and hands back a copy-ready command, either as one line or spread across several with \ continuations for readability.
Neither tool sends anything anywhere. The explainer only parses text you paste; the generator only assembles text from the fields you fill in. The actual request only happens when you paste the result into your own terminal and hit enter.
After you run it
Once the command runs, curl hands you back a status code, and that's its own small vocabulary — a 401 means something different from a 403, and a 502 means something completely different from a 500. If the response comes back with a code you don't immediately recognize, the HTTP Status Code Lookup tool covers the full range with a plain-English explanation for each one, so you're not stuck guessing whether the problem is on your end or the server's.
Tools used in this guide
Curl Command Explainer
Paste a curl command and see every flag explained in plain English, with the derived method, URL, and header count.
Curl Command Generator
Build a curl command from a method, URL, headers, auth, and body — pick the options you need and copy the result.
HTTP Status Code Lookup
Search HTTP status codes by number or name to see their meaning.