Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use cURL’s request option and the URL of the resource you want to remove:

curl --request DELETE https://api.example.com/resource/123

The shorter equivalent is curl -X DELETE https://api.example.com/resource/123. Replace the example URL with the API endpoint documented for your resource. Verify the URL, credentials, and recovery plan before running it: DELETE is intended to remove the identified resource, and cURL cannot determine whether the server completed your application’s business-level deletion.

What a cURL DELETE command does

The HTTP DELETE method asks a server to delete the resource identified by the request URL. cURL sends the method and handles the HTTP exchange; the API decides what deletion means, which credentials are allowed, and what response indicates success.

Use the explicit form for clarity

curl --request DELETE https://api.example.com/resource/123

--request (also written -X) changes the method word sent in the request. It does not redesign the rest of the command. Options that add data, follow redirects, or alter headers still apply, so do not copy a POST command and merely change its method unless the API documents every resulting requirement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Short form

curl -X DELETE https://api.example.com/resource/123

Both forms send DELETE. The long form is often easier to read in scripts and code reviews; the short form is convenient at an interactive shell.

Build the request from the API contract

1. Identify the exact resource URL

Place the resource identifier in the path required by the service, including any version prefix, account scope, or parent resource:

curl --request DELETE https://api.example.com/v1/projects/project_123/files/file_456

Do not substitute a collection URL for an item URL unless the documentation explicitly defines collection deletion. Treat query parameters as part of the resource identity and quote a URL when the shell could interpret characters such as &.

2. Add the required headers

Use --header (or -H) for media types, authorization, and other headers required by the endpoint:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl --request DELETE 
  --header 'Accept: application/json' 
  --header 'Authorization: Bearer REDACTED_TOKEN' 
  https://api.example.com/resource/123

Accept describes the response representation you want. The authorization scheme must match the service: a bearer token, an API key header, a signed request, or another mechanism documented by that API. Never publish a real secret in a script, article, ticket, or shell transcript.

Basic authentication with --user

For services that require HTTP username-and-password authentication, cURL supports --user (or -u):

curl --request DELETE 
  --user "$API_USER:$API_PASSWORD" 
  https://api.example.com/resource/123

Supplying values through environment variables avoids putting the literal password in the command line. Your shell, operating system, CI system, and API provider may still log credentials in other ways, so use the secret-storage mechanism appropriate for your environment.

Can a DELETE request contain JSON?

HTTP does not define generally applicable semantics for a DELETE request body. Servers may reject a body, ignore it, or assign private semantics. If an endpoint explicitly documents JSON in a DELETE request, follow that contract exactly and test against a non-production resource first:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl --request DELETE 
  --header 'Content-Type: application/json' 
  --header 'Accept: application/json' 
  --header 'Authorization: Bearer REDACTED_TOKEN' 
  --data '{"reason":"duplicate record"}' 
  https://api.example.com/resource/123

Do not assume this pattern is portable between APIs. If the documentation does not specify a body, omit --data. A body can also interact with proxies, gateways, and redirect handling in unexpected ways.

See what the server returned

By default, cURL writes a response body to standard output and reports transfer errors on its diagnostic stream. Choose output behavior deliberately when validating a destructive call.

Show response headers and body

curl --request DELETE 
  --include 
  --header 'Authorization: Bearer REDACTED_TOKEN' 
  https://api.example.com/resource/123

--include (or -i) prints response headers before the body. This helps you inspect the status and any request identifier supplied by the API.

Save the response

curl --request DELETE 
  --header 'Authorization: Bearer REDACTED_TOKEN' 
  --output delete-response.json 
  https://api.example.com/resource/123

Use --output (or -o) when another program must process the response or when you need an audit artifact. An empty response is valid for some APIs, so do not assume that no body means failure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Make failures visible in automation

curl --fail-with-body --silent --show-error 
  --request DELETE 
  --header 'Authorization: Bearer REDACTED_TOKEN' 
  --output delete-response.json 
  https://api.example.com/resource/123

--silent --show-error suppresses the progress meter while retaining diagnostics. --fail-with-body makes HTTP failure responses fail the command while preserving the response body for troubleshooting. Check the command’s exit status in your script, then interpret the HTTP response according to the API’s contract; a successful HTTP exchange is not proof that a business workflow accepted the deletion.

Redirects need special care

Enable automatic redirects only when you understand the endpoint’s behavior:

curl --location --request DELETE https://api.example.com/resource/123

When cURL follows redirects, a method specified with --request is used for subsequent requests as well. A redirect can therefore send DELETE to a different location and create another destructive request. First run without --location and inspect the response in a safe environment. Add it only when the API documents the redirect target and method behavior.

Understand idempotence without treating DELETE as safe

DELETE is idempotent but unsafe. Repeating the same request is defined to have the same intended effect, yet the first successful request can still remove data. Idempotence is useful for retry logic only after you understand the API’s behavior for missing resources, asynchronous deletion, soft deletion, and authorization changes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Confirm the hostname, path, query string, and resource identifier.
  • Confirm that the token or account has the intended scope.
  • Check whether the API offers a dry run, archive, undo, or soft-delete mode.
  • Know how to recover before sending the request.
  • Use a non-production identifier while developing the command.

Safe shell patterns for repeatable commands

Use variables and a quoted URL

API_URL='https://api.example.com/resource/123'
TOKEN="$API_TOKEN"
curl --fail-with-body --silent --show-error 
  --request DELETE 
  --header "Authorization: Bearer $TOKEN" 
  --header 'Accept: application/json' 
  "$API_URL"

Quoting the URL prevents shell expansion. Keep the token outside source control and inject it through your operating system’s or CI provider’s secret mechanism.

Log enough to diagnose, not enough to leak secrets

Capture the endpoint, timestamp, command exit status, and server request identifier when available. Redact authorization headers and response fields that contain credentials or personal data. Avoid verbose traces in shared logs until you have confirmed that sensitive headers are not exposed.

Rank #4
Sale
Haofy Legal Pads A4 Size, 4 Pack Colored Notepads (4pcs 21.4x29.6cm 50
  • Sturdy Backing Support: Place on lap or outdoor bench without curling, stiff cover prevents page flapping in breeze, maintains flat writing surface for park sketching and commute journaling.
  • Red Margin Guidance: Left column reserved for annotations or page numbers, right space holds 27 clean lines, reduces eye strain during lengthy study sessions and project brainstorming.
  • Tear-Off Top Binding: Remove sheets cleanly along score lines, no loose fragments or damaged corners, paper accepts pencil and rollerball ink evenly for daily schedules.
  • Designated Header Zone: Top section marked for date and subject, color-coded covers help separate courses or clients, simplifies folder organization after semester ends.
  • Multi-Purpose 4-Pack: Four vibrant notepads for dorm desks, office cubicles, or home command centers, 200 total sheets support semester-long note-taking without restock.

Equivalent requests in Python and Node.js

These examples are useful when a script must perform the same API operation without invoking a shell. They still require the endpoint’s authentication and body rules.

Python

import os
import requests

url = 'https://api.example.com/resource/123'
headers = {
    'Accept': 'application/json',
    'Authorization': f"Bearer {os.environ['API_TOKEN']}",
}
response = requests.delete(url, headers=headers, timeout=30)
print(response.status_code)
print(response.text)

Check the returned status and response body against the API documentation. A timeout means the client did not receive a complete result; it does not prove that the server did nothing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Node.js

const url = 'https://api.example.com/resource/123';
const response = await fetch(url, {
  method: 'DELETE',
  headers: {
    'Accept': 'application/json',
    'Authorization': `Bearer ${process.env.API_TOKEN}`
  }
});
console.log(response.status);
console.log(await response.text());

Use the same caution about retries and timeouts as with cURL. Do not automatically repeat a timed-out destructive request until you know whether the endpoint is safe to retry.

Or skip the browser setup

If your goal is to obtain a clean screenshot of an API page or documentation URL while developing an integration, ScreenshotNeo provides a single HTTP call rather than a browser setup. Its API accepts a URL and returns PNG, JPEG, WebP, or PDF output.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo documentation for request options. Before capture, it can accept cookie or consent banners and remove more than 60 known consent platforms, newsletter popups, and chat widgets; each cleanup step can be disabled. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and each response identifies the result with X-Page-Verdict and X-Billed headers. An MCP server exposes take_screenshot, get_page_info, and capture_pdf tools to Claude, Cursor, and other MCP clients. The Free plan includes 1,000 screenshots per month without a card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account to get started.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting common DELETE failures

The server says the method is not allowed

Confirm that the URL identifies an endpoint supporting DELETE, not a read-only collection or web page. Check the API version and required path parameters. Changing -X to --request will not make an unsupported endpoint accept DELETE.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

You receive an authentication or authorization error

Verify the header spelling, authentication scheme, token expiration, account or project scope, and whether the token is being expanded by the shell. Remove the secret from diagnostic output before sharing logs.

The request is rejected because of its body

Remove --data unless the API explicitly documents a DELETE body. If a body is required, add the documented Content-Type, JSON shape, and encoding exactly, then test with a disposable resource.

The command follows an unexpected redirect

Run without --location, inspect the response, and verify the redirect destination. Automatic redirect following can carry DELETE to later locations.

The command exits successfully but the item remains

Read the response body and status according to the service documentation. The operation may be asynchronous, may implement a soft delete, or may have been accepted for a different resource. cURL reports the transport exchange; it does not verify your application’s final state.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The connection times out

Check DNS, network access, TLS or proxy configuration, and the API’s availability. A timeout leaves the outcome uncertain, so query the resource or use the provider’s operation-status mechanism before retrying a destructive call.

DELETE command checklist

  1. Confirm the exact resource URL and environment.
  2. Confirm authorization scope and required headers.
  3. Omit a body unless the API documents one.
  4. Run once against a disposable resource.
  5. Keep redirects disabled until their behavior is understood.
  6. Capture the response and command exit status.
  7. Verify the resource state using the API’s documented method.

Frequently asked questions

Is -X DELETE different from --request DELETE?

No. They are short and long spellings for selecting the DELETE method. Neither option supplies authentication, headers, a body, or redirect policy.

Should I retry a failed DELETE automatically?

Only after the API documents retry behavior and you can determine whether the first request reached the server. Idempotence does not make an operation harmless.

Does cURL delete a local file with this command?

No. This command sends an HTTP request to the URL. A local file is removed only by a separate operating-system command or program.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do I know deletion really happened?

Use the endpoint’s documented response and verification flow, such as a subsequent resource lookup or operation-status request. cURL alone cannot infer business-level completion.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.