Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

For the command line, curl https://example.com/ makes a basic HTTPS request. Keep certificate checks enabled, and remember that your installed curl build determines which protocols and features are available. This FAQ focuses mainly on the curl command-line tool; when behavior belongs to the library, it names libcurl.

What is curl?

curl is a command-line tool for transferring data to or from servers using URLs and protocols supported by the installed build. It is commonly used to make HTTP requests, download files, work with proxies and cookies, and test services. The curl project overview describes capabilities including HTTP(S), file-transfer protocols, authentication, proxies, and HTTP/2 and HTTP/3, but availability depends on how the particular binary was built: curl documentation.

curl is not the same thing as libcurl. The curl executable is a program you run in a terminal; libcurl is a client-side transfer library that applications use through its API. Language bindings also let applications call libcurl from languages other than C. Command-line switches and libcurl API options are not interchangeable, and an application embedding libcurl may expose only the controls its developers chose to implement.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do I make a basic HTTPS request?

Run curl https://example.com/. By default, the response body is written to standard output, so this form is useful for checking a page or API endpoint. To save a response to a file using the remote filename when available, use curl -O https://example.com/file.zip. To choose a local filename, use curl -o page.html https://example.com/.

HTTPS protects the connection only if the client verifies the server certificate and hostname. Do not disable either check as a routine workaround: the official libcurl HTTPS example warns that disabling peer or hostname verification makes the connection insecure. If a server uses a private certificate authority that is not in the default trust bundle, configure the correct CA certificate or CA path instead of bypassing verification: libcurl HTTPS example.

What should I do about a certificate error?

A certificate error means curl could not establish the expected trusted identity for the HTTPS connection. The exact cause depends on the message and the machine, so check the relevant conditions rather than immediately suppressing the error:

  • Confirm the computer’s date and time are correct; certificates are valid only within a time window.
  • Check that the URL uses the hostname covered by the server certificate, rather than an IP address or a different alias.
  • Check whether the server presents a valid certificate chain and whether the issuing CA is trusted by this system.
  • If the site uses a private CA, obtain its certificate from the organization responsible for the service and configure curl to trust it. With libcurl, the HTTPS example documents CA path configuration for certificates outside the default bundle.

-k and --insecure disable certificate verification for a command-line request. This may help isolate a problem in a controlled test, but it removes a security check and should not be used to make ordinary requests safe. A successful transfer with verification disabled does not establish that the server identity was trustworthy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do I send POST data?

For a command-line form-style request, -d sends data in a POST request. For example:

Rank #2
Sale
Curly Girl: The Handbook
  • Workman publishing
  • Binding: paperback
  • Language: english
curl -d 'name=Ada&role=developer' https://example.com/submit

Use the encoding and content type the server expects. Form fields with reserved characters should be encoded correctly; for individual fields, --data-urlencode can handle URL encoding. If the API expects JSON rather than form data, send JSON and set its content type explicitly:

curl -H 'Content-Type: application/json' 
  -d '{"name":"Ada","role":"developer"}' 
  https://example.com/api

In libcurl, CURLOPT_POST selects a regular HTTP POST, and the body can be supplied with CURLOPT_POSTFIELDS or related options. The documented default content type associated with this option is application/x-www-form-urlencoded; applications can set another header when the endpoint requires it: CURLOPT_POST documentation.

Why can a POST turn into GET after a redirect?

Sending a POST and deciding what to do with that POST after a redirect are separate behaviors. With libcurl’s documented defaults, following a 301, 302, or 303 response converts POST to GET, matching common browser behavior. For an API that requires the POST method and body to be preserved, use the documented POST redirect setting deliberately and verify the server’s intended redirect semantics: CURLOPT_POSTREDIR documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This redirect control applies to POST configured with CURLOPT_POST or CURLOPT_MIMEPOST; it does not apply in the same way when an application merely changes a method name using CURLOPT_CUSTOMREQUEST. Do not assume that setting a custom method string alone configures how the body or redirect is handled.

Are redirects safe when credentials are attached?

Redirects are not automatically unsafe, but a redirect target and the credentials attached to a request deserve attention. Check whether redirects are enabled, whether they can cross hosts or protocols, which credentials are present, and the exact client version. Two curl project advisories published in 2026 describe narrowly conditional issues, not a general claim that all redirects leak credentials.

libcurl netrc password advisory

The curl project’s April 29, 2026 advisory describes a netrc password leak affecting libcurl 7.14.0 through 8.19.0 only under a specific combination: both URLs used clear-text HTTP, the same HTTP proxy was used, a connection was reused, and redirects occurred. The advisory says the curl command-line tool is not affected by this issue; it lists versions at or above 8.20.0 and certain maintained branches as not affected. Check the advisory for the full conditions and version details: curl project advisory.

OAuth bearer-token cross-protocol advisory

A separate curl project advisory published January 7, 2026 describes a bearer-token leak involving a narrow combination of cross-protocol redirects to IMAP, LDAP, POP3, or SMTP with redirects enabled. The advisory identifies curl 8.18.0 as the fix; downstream vendors may backport fixes to packages whose displayed upstream version is older. Review the advisory and your vendor’s security information: curl project advisory for CVE-2025-14524.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For either issue, compare the advisory’s affected conditions with the actual client, build, protocol support, redirect behavior, and package security updates. Avoid allowing unnecessary cross-protocol redirects when credentials are attached.

How do I check which protocols and features my installation supports?

When curl-config is installed, these commands report information about the associated libcurl build:

curl-config --version
curl-config --protocols
curl-config --feature
curl-config --ssl-backends

The outputs respectively identify the libcurl version, supported protocols, compiled features, and TLS backends. The curl manual documents these build-information queries: curl-config manual. Results describe that installed build, not every curl executable on the system. A system package, bundled copy inside an application, or another machine may have different protocol and TLS support.

For command-line diagnostics, curl --version is also useful: it prints the executable’s version and build details, including protocols and features. If an application uses libcurl, establish which library it actually loads; the command found first in your shell’s PATH may not be the one embedded in that program.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How can I understand common curl errors?

Start with the full error text and the exact command. The same symptom can have different causes depending on the URL, network, build, and whether curl or an application using libcurl made the request.

Best Value
  • Could not resolve host: check the spelling of the hostname, DNS configuration, and whether the machine has network access.
  • Connection refused or timed out: check the host and port, service availability, firewall or proxy rules, and whether the endpoint is reachable from that network.
  • Certificate verification failed: check the system clock, hostname, certificate chain, and CA trust as described above; do not treat --insecure as a permanent repair.
  • Unsupported protocol or feature: inspect the installed build’s protocols and features. The requested capability may be absent even if another curl installation supports it.
  • Unexpected response after a redirect: inspect the status and destination of the redirect. For POST requests, determine whether the endpoint expects the method to change or be preserved.

Use -v when you need diagnostic request and connection details, but review output before sharing it: verbose logs can include sensitive URLs, headers, or other request information. Avoid posting access tokens, cookies, passwords, or private data in public support requests.

How do I capture a website screenshot with a URL request?

If what you need is a rendered website image rather than the raw HTTP response body, curl alone does not render the page. A screenshot service can accept a URL and return an image or PDF. ScreenshotNeo is a website screenshot API and MCP server; its endpoint accepts a GET request with a URL and can return PNG, JPEG, WebP, or PDF. API options and response details are documented at ScreenshotNeo documentation.

Or skip the browser setup:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

ScreenshotNeo removes cookie/consent banners, newsletter popups, and chat widgets before capture; bot checks, blank pages, and failed loads are not billed. An MCP server lets AI agents use screenshot tools, and the free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. Sign up free for 1,000 screenshots a month with no card.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Where can I get curl help?

The curl project directs command-line usage questions to the curl-users mailing list and libcurl development or debugging questions to curl-library. It also provides the Everything curl guide and official documentation; the project’s help page lists these routes: curl project help. For a useful question, include the curl or libcurl version, operating system or package source, the exact command or relevant API options, and the error message, while removing credentials and private information.

Frequently Asked Questions

Does curl work on Windows, macOS, and Linux?

curl is available on many operating systems, but the included version and its compiled protocol and TLS features can vary by platform and package.

Is a comment in curl’s 2025 survey evidence of what most users think?

No. The survey includes individual qualitative responses, such as complaints about the unintuitive -k option, but those comments do not establish a representative population estimate: curl 2025 survey.

Where can I find libcurl sample code for HTTPS?

The curl project provides a C example that sets an HTTPS URL, performs the easy request, checks the result, and cleans up: libcurl HTTPS example.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

SaleBestseller No. 2
Curly Girl: The Handbook
Curly Girl: The Handbook
Workman publishing; Binding: paperback; Language: english
$8.19
Bestseller No. 3
Bestseller No. 4
SaleBestseller No. 5
A Practical Guide to Curl (Programming Series)
A Practical Guide to Curl (Programming Series)
Used Book in Good Condition
$24.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.