curl — Command Line HTTP Client & API Debugger
Complete beginner guide to curl, testing REST APIs, inspecting HTTP response headers, verifying SSL/TLS certificates, and debugging response timing with command flag breakdowns.
On this page
- What is curl?
- 1. Inspecting HTTP Response Headers Only (-I / --head)
- Flag breakdown
- 2. Following HTTP Redirects Automatically (-L / --location)
- Flag breakdown
- 3. Sending JSON POST Requests to REST APIs
- Flag breakdown
- 4. Verbose Mode: Inspecting TLS Handshakes (-v / --verbose)
- Flag breakdown
- 5. Bypassing DNS: Testing Servers before Public DNS Updates (--resolve)
- Flag breakdown
- 6. Measuring Latency and Performance Breakdown (-w)
- Flag breakdown
- Quick Reference Summary Table
What is curl?
curl (Client URL) is the industry-standard command-line tool for transferring data over network protocols (HTTP, HTTPS, FTP, SFTP, and dozens more).
It is installed by default on almost every operating system and is an indispensable tool for sysadmins and developers to test web endpoints, inspect HTTP headers, debug TLS certificates, and automate API workflows.
1. Inspecting HTTP Response Headers Only (-I / --head)
When diagnosing whether a website is up, checking caching headers, or verifying redirects, downloading the entire HTML body is wasteful.
Fetch only the HTTP status code and response headers:
curl -I https://ternis.orgFlag breakdown
-I(or--head): Issues anHTTP HEADrequest instead ofGET. The web server returns only HTTP response headers (e.g.HTTP/2 200,Content-Type,Cache-Control,Set-Cookie) and immediately closes the stream without sending the HTML body.
2. Following HTTP Redirects Automatically (-L / --location)
Websites frequently redirect visitors (e.g. from http:// to https://, or /wiki to /wiki/):
curl -IL https://ternis.org/wikiFlag breakdown
-L(or--location): Instructs curl to follow HTTP301 Moved Permanentlyor302 Foundredirects. By default, curl stops at the first response and outputs the redirect message. Combining-Iand-L(-IL) prints the complete redirect chain until it reaches the finalHTTP 200 OKpage.
3. Sending JSON POST Requests to REST APIs
To submit data to an API endpoint:
curl -X POST https://api.example.com/v1/items \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_TOKEN_HERE" \
-d '{"name": "production-node", "active": true}'Flag breakdown
-X POST(or--request POST): Specifies the HTTP method to use (defaults toGET).-H "<header>"(or--header): Appends a custom HTTP request header. Here,Content-Type: application/jsontells the server the payload format, andAuthorizationpasses credentials.-d '<data>'(or--data): Sends the specified string as the HTTP request body payload. (Note: using-dautomatically impliesPOSTin curl even if-X POSTis omitted).
4. Verbose Mode: Inspecting TLS Handshakes (-v / --verbose)
When an SSL certificate fails, an API handshake drops, or headers look incorrect:
curl -vI https://ternis.orgFlag breakdown
-v(or--verbose): Displays the entire underlying connection process:- DNS resolution and connected IP address.
- Complete TLS cryptographic handshake (negotiated TLS version, cipher suite, certificate issuer).
- Outgoing request headers (prefixed with
>). - Incoming response headers (prefixed with
<).
5. Bypassing DNS: Testing Servers before Public DNS Updates (--resolve)
When moving a website to a new server, you need to test the new server's configuration and TLS certificates before switching public DNS records:
curl -I --resolve example.com:443:203.0.113.10 https://example.comFlag breakdown
--resolve <host:port:address>: Forces curl to connect directly to IP203.0.113.10on port443while still sendingHost: example.comand SNI forexample.com. This lets you verify the new server without modifying your local/etc/hostsfile!
6. Measuring Latency and Performance Breakdown (-w)
To diagnose slow website loading times and measure latency bottlenecks:
curl -w "DNS: %{time_namelookup}s | Connect: %{time_connect}s | TLS: %{time_appconnect}s | TTFB: %{time_starttransfer}s | Total: %{time_total}s\n" \
-o /dev/null -s https://ternis.orgFlag breakdown
-w "<format>"(or--write-out): Prints formatted connection metrics to stdout.time_namelookup: Time spent resolving DNS.time_connect: Time spent establishing the TCP connection.time_appconnect: Time spent completing the TLS/SSL handshake.time_starttransfer: Time To First Byte (TTFB).time_total: Total roundtrip time in seconds.-o /dev/null(or--output): Discards the downloaded HTML body so it doesn't flood your screen.-s(or--silent): Hides the progress meter.
Quick Reference Summary Table
| Flag | Long Flag | Purpose |
|---|---|---|
-I | --head | Fetch HTTP response headers only |
-L | --location | Follow HTTP 301/302 redirects |
-v | --verbose | Print detailed connection, TLS handshake, and header logs |
-s | --silent | Mute progress bar and informational messages |
-S | --show-error | Show errors even when -s is active |
-o <file> | --output | Save response to a file instead of stdout |
-O | --remote-name | Save file using the remote server's filename |
-d <data> | --data | Send POST payload data |
-H <hdr> | --header | Add custom HTTP request header |
-k | --insecure | Allow self-signed or invalid SSL certificates (testing only!) |