HTTP request builder
Compose any HTTP request — choose the method, set headers and query params, add a body, and fire it off. The full response status, headers, and body are shown instantly.
About this tool
Most API debugging comes down to one question: is the request you think you are sending the request that actually arrives. Building it by hand, one header at a time, and reading the raw response is the fastest way to find out — before adding a client library, a retry wrapper, and an abstraction layer that each modify the request in ways you did not ask for. Working at this level makes the details visible. You can see whether the Content-Type actually matches the body you sent, what the server returns for an unauthenticated call versus an unauthorised one, which headers come back, and what the response body looks like before any deserialiser has touched it. That is usually enough to distinguish a client bug from a server bug in a couple of minutes. This tool builds a request with any method, URL, query parameters, headers, and body, sends it, and shows the status, response headers, and body. Requests are proxied through this site's server rather than sent directly from your browser, so they are not subject to CORS — and so you should treat any credentials you send accordingly.
- 1
Select the HTTP method (GET, POST, PUT, etc.) from the dropdown.
- 2
Enter the target URL in the address bar.
- 3
Add any custom headers or query parameters using the key-value fields.
- 4
For POST/PUT requests, add a JSON or text body in the body panel.
- 5
Click Send — the response status, headers, and body appear immediately below.
Test REST API endpoints without installing Postman or curl.
Debug response headers from any public API.
Prototype API calls with custom headers and JSON bodies before writing code.
GET request
GET https://jsonplaceholder.typicode.com/posts/1{"id":1,"title":"sunt aut facere..."}POST with JSON body
POST /posts Body: {"title":"test"}{"id":101}Custom header
GET /users Authorization: Bearer token123200 OK with user listA POST body is ignored by the server
Cause: The Content-Type does not match the body. Sending JSON without application/json, or sending form-encoded data with a JSON content type, leaves most frameworks parsing nothing and seeing an empty body.
Fix: Set Content-Type explicitly to match what you are sending. A server that returns 200 with an empty result rather than an error is the usual signature of this mismatch.
The API returns 401 or 403 despite a correct-looking token
Cause: Header formatting. The Authorization header needs the scheme prefix — Bearer followed by a space and the token — and a copied token often carries a trailing newline or a truncated tail.
Fix: Check the exact header value, including the prefix and the absence of stray whitespace. Decode the token to confirm it has not expired and that its audience matches the API you are calling.
The response differs from what the same request returns in the browser
Cause: The browser sends cookies, an Origin header, and a full set of default headers that this builder does not. An endpoint relying on session cookies will behave differently.
Fix: Add the headers the browser would send, including any session cookie, if you need to reproduce browser behaviour exactly. For cookie-authenticated endpoints, be aware you are sending a live session credential through a third-party proxy.
These answers explain common http request builder tasks, expected input formats, and edge cases so both visitors and search engines can understand what this tool does.
Does this send real HTTP requests?
Yes. Requests are fired directly from your browser using the Fetch API. The response you see is the actual response from the server.
Why does my request fail with a CORS error?
Browsers block cross-origin requests unless the server includes the appropriate CORS headers. APIs that are not designed for browser access will be blocked. Use a server-side proxy or a CORS-enabled endpoint to work around this.
Is my request data sent to devtoolsforyou servers?
No. Requests are sent directly from your browser to the target URL. No data passes through our servers.
What HTTP methods are supported?
GET, POST, PUT, PATCH, DELETE, HEAD, and OPTIONS are all supported.