Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

cURL (usually written curl by its project) is a command-line program for transferring data to or from a URL. You give it a URL and options, and it sends or receives data using protocols supported by your installed build. It is powered by libcurl, a library that applications can use directly.

Unlike a browser, curl does not render pages, run a visual interface, or interpret the returned document for you. Its output normally goes to standard output—the terminal—unless you save it to a file or hand it to another command.

What curl does

At its core, curl performs URL-based transfers. A transfer can download a document, upload a file, submit an API request, inspect response headers, or exchange data with a service. The command-line program is the user-facing tool; libcurl is the reusable client library behind it and is available to software developers building their own applications.

The protocols available depend on how your particular build was compiled. Common installations support HTTP and HTTPS, and may also support FTP, FTPS, IMAP, LDAP, MQTT, POP3, RTSP, SCP, SFTP, SMTP, TELNET, TFTP and WebSocket variants. Run curl --version to see the installed version, linked libraries, features and protocol list rather than assuming every build supports every scheme.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Your first curl command

  1. Open a terminal. On Windows, use PowerShell, Windows Terminal or another shell with curl available.
  2. Request a URL: curl https://example.com.
  3. Read the result. The response body is written to standard output, so HTML or text appears in the terminal.

That command transfers the response; it does not open a graphical browser window. If the response is binary data, your terminal may display unreadable characters, so save it instead.

Save to a chosen filename

Use --output (short form -o) when you want a predictable local name:

curl --output page.html https://example.com

Use --remote-name (short form -O) to derive the filename from the URL:

curl --remote-name https://example.com/archive.zip

If a URL redirects and you intend to follow the destination, add --location (short form -L):

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -L --output page.html https://example.com

curl does not follow HTTP redirects by default. Making that choice explicit prevents an unexpected transfer to a different URL.

How curl differs from a browser

Task curl Browser
Transfer an HTTP response Yes; output is data for the terminal, file or script Yes, while presenting it visually
Render HTML and CSS No Yes
Run page JavaScript and interact with controls No browser rendering or interaction model Yes
Follow links automatically No; a command or script must request each URL Users click links; crawlers may automate navigation
Repeat a precise API request Yes, and it is easy to script Possible through developer tools, but not its primary interface

A page that depends on JavaScript to create its content may return only a shell of HTML to curl. That is expected: curl transfers the server response and does not parse or otherwise understand the content it receives in the way a browser does.

curl and wget are not interchangeable

The curl project states that “curl is not a Wget clone.” curl is aimed at single-shot transfers and programmable requests. The command itself does not recursively fetch linked pages or mirror an entire website. A shell or application can orchestrate many curl requests, but that is different from a built-in recursive crawler.

Choose curl when you need an exact, repeatable transfer, API call, upload, download or protocol-level inspection. Choose a recursive downloader or mirroring tool when the job is to traverse links and reproduce a site structure. Choose a browser when the job requires rendering, JavaScript, cookies managed through a user interface or human interaction.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Requests, uploads and response inspection

Inspect headers without saving the body

--head (or -I) asks for response headers, which is useful for checking status codes, content types, caching information and redirects:

curl --head https://example.com

For verbose connection details, use --verbose (or -v). It can show request and response headers and connection negotiation; avoid sharing verbose output if it contains cookies or authorization data.

Send form data

Use --data (or -d) for a request body. For example:

curl -X POST https://api.example.test/items 
  -H "Content-Type: application/json" 
  --data '{"name":"sample"}'

Use the API’s documented method, media type and authentication scheme. curl does not decide whether a request is safe or semantically correct for a particular service.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Upload a file

Many APIs accept a file with --upload-file (or -T):

curl -T report.csv https://uploads.example.test/report.csv

The server must support the method and destination format. Check its documentation before sending confidential data.

Redirects, TLS and authentication defaults

Redirects are opt-in

Use -L only when following redirects is part of your intended workflow. A redirect can change the host, path or protocol, so inspect where it leads when requests carry credentials or sensitive data.

Certificate verification is enabled

For secure protocols, curl verifies server certificates by default. The -k or --insecure option disables certificate verification (and known-host verification for SFTP or SCP). That makes the transfer insecure; it is not a routine fix for certificate errors. Prefer correcting the trust store, hostname, system clock or server certificate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Protect credentials

Basic authentication and FTP passwords can be sent in cleartext when the underlying connection is not protected. Use an appropriate secure protocol and authentication method. Secrets placed directly in a command can also appear in process listings or shell history. Where supported, read options from a protected configuration file or standard input, restrict its permissions and avoid pasting credentials into shared logs.

Output, errors and scripting behavior

By default, the response body goes to standard output and diagnostics go to standard error. This separation lets scripts redirect the body while retaining errors:

Rank #4
Sale
Haofy Legal Pads A4 Size, 4 Pack Colored Notepads (4pcs 21.4x29.6cm 50
  • Sturdy Backing Support: Place on lap or outdoor bench without curling, stiff cover prevents page flapping in breeze, maintains flat writing surface for park sketching and commute journaling.
  • Red Margin Guidance: Left column reserved for annotations or page numbers, right space holds 27 clean lines, reduces eye strain during lengthy study sessions and project brainstorming.
  • Tear-Off Top Binding: Remove sheets cleanly along score lines, no loose fragments or damaged corners, paper accepts pencil and rollerball ink evenly for daily schedules.
  • Designated Header Zone: Top section marked for date and subject, color-coded covers help separate courses or clients, simplifies folder organization after semester ends.
  • Multi-Purpose 4-Pack: Four vibrant notepads for dorm desks, office cubicles, or home command centers, 200 total sheets support semester-long note-taking without restock.
curl --fail --silent --show-error --output result.json https://api.example.test/data
  • --fail makes HTTP errors produce a failing exit status instead of treating an error page as a successful document.
  • --silent suppresses the progress meter.
  • --show-error keeps useful diagnostics when silent mode is enabled.
  • --output writes the body to the named file.

For large interactive downloads, omit --silent so the progress meter remains visible. In automation, check curl’s exit status and validate the response content or status code required by your application.

Checking your installation and choosing options

Start with:

curl --version

This reports the version, supported protocols and build features. Option names can vary by version, so consult the man page installed with your build when a script must run across different operating systems or distributions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Before writing a command, decide:

  • Is the task a download, upload, API request or diagnostic inspection?
  • Does the installed build support the required protocol?
  • Should the body appear in the terminal or be written to a file?
  • Should redirects be followed?
  • Which authentication and certificate checks must remain enabled?
  • Will the command run interactively, in a script or in a CI job with different timeout and logging needs?

Security rules worth remembering

  • Do not run curl command lines or configuration files supplied by untrusted sources. A command can download content and pipe it into a shell, which may execute code.
  • Read a command’s switches before running it, especially options that write files, follow redirects, disable verification or execute another program.
  • Keep tokens, passwords and cookies out of public examples and build logs.
  • Do not use --insecure merely to make a failed TLS connection proceed.
  • Use HTTPS or another protected protocol when credentials or private data are involved.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Common problems and fixes

The terminal shows HTML instead of a file

That is curl’s normal output behavior. Add -o filename or -O to save the response.

The result is a redirect page or the wrong content

Inspect headers with -I, then add -L if following the redirect is intentional. Do not blindly follow redirects for requests carrying secrets.

Certificate verification fails

Check the URL hostname, system time, certificate chain and local trust store. Keep verification enabled. Use -k only for a deliberately understood, isolated test where the security consequence is acceptable.

The page is incomplete compared with a browser

The server may rely on JavaScript, client-side API calls, cookies or browser interaction. curl transfers the response but does not render or execute it. Use a browser automation tool for that workflow, or call the underlying API directly if one is documented.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The command says a protocol is unsupported

Run curl --version. Your build may have been compiled without that protocol or feature; install or select a build that supports the required capability.

Credentials appear in logs

Remove secrets from command arguments and use the service’s safer authentication mechanism, protected configuration files or standard input. Review shell history and CI logs after an accidental exposure.

Using curl with a screenshot API

curl is useful when you want to make a repeatable HTTP request from a script. For a website screenshot, however, the endpoint must perform browser-style loading and capture on the server; curl alone will only download whatever response an endpoint returns.

Or skip the browser setup

ScreenshotNeo is a website screenshot API and MCP server. A single GET request returns a PNG, JPEG, WebP or PDF. Its capture flow accepts cookie and consent banners like a visitor, then removes more than 60 known consent platforms, newsletter popups and chat widgets before the shot. Bot checks, CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and the response identifies the result with X-Page-Verdict and X-Billed headers.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Using the documented API (docs):

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

ScreenshotNeo also provides the tools take_screenshot, get_page_info and capture_pdf through an MCP server for Claude, Cursor and other MCP clients. Every plan includes its features. The Free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.

Where curl came from and where to learn more

Daniel Stenberg extended Rafael Sagula’s HttpGet tool; the first release with Stenberg’s additions was version 0.2 on December 17, 1996. The project provides an official tutorial, a reference man page and Everything curl, a free online book and PDF covering curl, libcurl, building and contributing. Because releases and build features change, use the documentation that matches your installed version.

Frequently Asked Questions

Does curl require an internet browser to work?

No. curl is a terminal program that opens network connections itself; a browser is only needed when the task requires visual rendering or interactive page behavior.

Can curl download a complete website?

Not by itself. The curl command performs individual transfers; recursive traversal and mirroring require a different tool or a script that coordinates multiple requests.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Is libcurl the same thing as curl?

No. curl is the command-line application. libcurl is the library that curl uses and that other applications can embed.

Why does curl sometimes return a page different from the one I see?

A browser may execute JavaScript, manage cookies, follow interaction flows or render content generated after load. curl normally transfers the server’s direct response without those browser behaviors.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.