HTTP and URL tools
Debugging an API often starts with text copied from a terminal, browser DevTools or a log. It might be a cURL command, a block of response headers, a long URL with a query string or a bearer token. These tools turn that text into structured data you can read and compare.
A few rules explain most surprises. HTTP header names are case-insensitive, and some fields, such as Set-Cookie, can appear more than once. Query strings have no single standard for repeated keys, so ?tag=a&tag=b may reach your server as an array, the last value or the first value, depending on the framework. In form encoding a + means a space, while in a URL path it is a literal plus sign. A signed JWT's payload is only Base64url-encoded, not encrypted, so anyone with the token can read its claims.
Convert a cURL command to fetch, Python requests or Go code, or inspect its method, URL, headers, body and auth flags without running it. Turn a raw header block into JSON, break a URL into its parts, parse or build query strings, and URL encode values correctly. Look up the MIME type and Content-Type value for a file extension, or decode a JWT to check its claims and expiry. Nothing you paste is sent anywhere. Parsing happens in your browser.
All HTTP & URL tools
- curl→cURL to CodeTurn a cURL command into fetch, Python requests or Go, or inspect it as JSON.
- HTTP:{}HTTP Headers ParserTurn request or response headers into structured JSON.
- ://URL ParserSplit a URL into its parts, parse a query string to JSON, or build one.
- %2FURL Encode / DecodePercent-encode a query value or a full URL per RFC 3986, or decode it.
- MIME?MIME Type LookupLook up extensions and media types with charset and compression info.
- ⬡JWT DecoderRead the header, payload and signature, with an expiry check.
Related guides
- What is URL encoding? Percent-encoding, %20 and + explainedHow percent-encoding works, why spaces become %20, when + means a space, and when to use encodeURIComponent instead of encodeURI.
- Understanding JWTs: structure, claims and verificationHow a JWT is built, what each registered claim means (including jti), how HS256 and RS256 signing work, and the verification mistakes that lead to auth bypasses.