API Tester

Send GET, POST, PUT, PATCH or DELETE requests to any API and inspect the response, directly in your browser.

Developer ToolsAPIHTTPNetworking

Enter a URL, choose a method, and optionally add headers or a request body, then send the request. This tool makes the request directly from your own browser — not through our server — exactly like typing fetch() into your browser’s own developer console.

We do not log or store the URLs, headers, or bodies you send.

the exact URL you enter below — not a fixed API, and not through our server

One per line, as "Key: Value".
Ignored for GET and HEAD requests.

How This Tool Works

Because the request comes from your own browser, it follows the exact same rules a website’s own JavaScript follows: the target API must explicitly allow cross-origin requests (a security mechanism called CORS) or the browser will block the response from being read, even though the request itself may have succeeded. This is not a limitation of this tool specifically — it is the same restriction you would hit typing the same request into your browser’s own DevTools console, and it cannot be bypassed from client-side JavaScript by design. Every request is sent without cookies or stored login sessions (even for your own site), so pasting a URL here never risks leaking your session to it — an API that needs authentication should have its token added directly in the Headers field.

FAQ

Why do I get a network error / failed to fetch?

This almost always means the target API does not send the CORS headers required to let a browser-based tool read its response — a genuine security restriction, not a bug. It can also mean the URL is unreachable, misspelled, or the host does not exist.

Is my request sent through your server?

No. It goes directly from your browser to the URL you enter, the same way your browser’s own DevTools console would send it.

Can I test an authenticated API?

Yes — add an Authorization header (e.g. “Authorization: Bearer your-token”) in the Headers field. This tool never asks for or stores any credential itself.