Code tool

API Tester

All entered headers, including Authorization, go to the host below. POST, PUT, PATCH and DELETE may change remote data. Every request requires confirmation. Cookies are omitted; redirects are blocked. Requests use browser fetch directly: CORS may prevent access, and only exposed response headers are visible.

In-browser processingNo account requiredPrivacy details ↗

All entered headers, including Authorization, go to the host below. POST, PUT, PATCH and DELETE may change remote data. Every request requires confirmation. Cookies are omitted; redirects are blocked. Requests use browser fetch directly: CORS may prevent access, and only exposed response headers are visible.

JSON body ≤256 KiB; request headers ≤16 KiB; response body ≤1 MiB; timeout 30 seconds. Nothing is sent before confirmation.

DestinationEnter an HTTP(S) URL to review the destination.

Enter an HTTP(S) URL to review the destination.

Local request history

Only the last 20 request times, methods, destination origins, statuses, timing and byte counts are saved on this device. URLs beyond the origin, headers, credentials and bodies are never saved or restored.

    A QUICK WALKTHROUGH

    How to use this tool

    1. Enter the destination, method, optional headers and JSON body.
    2. Review the warning and confirm each request.
    3. Inspect the response and metadata-only local history.

    Destination

    All entered headers, including Authorization, go to the host below. POST, PUT, PATCH and DELETE may change remote data. Every request requires confirmation. Cookies are omitted; redirects are blocked. Requests use browser fetch directly: CORS may prevent access, and only exposed response headers are visible.

    Response body

    JSON body ≤256 KiB; request headers ≤16 KiB; response body ≤1 MiB; timeout 30 seconds. Nothing is sent before confirmation.

    Local request history

    Only the last 20 request times, methods, destination origins, statuses, timing and byte counts are saved on this device. URLs beyond the origin, headers, credentials and bodies are never saved or restored.

    GOOD TO KNOW

    Common questions

    Visible response headers

    All entered headers, including Authorization, go to the host below. POST, PUT, PATCH and DELETE may change remote data. Every request requires confirmation. Cookies are omitted; redirects are blocked. Requests use browser fetch directly: CORS may prevent access, and only exposed response headers are visible.

    Local request history

    Only the last 20 request times, methods, destination origins, statuses, timing and byte counts are saved on this device. URLs beyond the origin, headers, credentials and bodies are never saved or restored.