REST API client. Send GET, POST, PUT, DELETE, PATCH requests with custom headers, body, and auth. Inspect responses with syntax highlighting.
100% browser-based — your data never leaves your device
Send HTTP requests (GET, POST, PUT, DELETE) and inspect responses from your browser.
Send HTTP requests (GET, POST, PUT, DELETE) and inspect responses from your browser.
WebSocket TesterConnect to WebSocket endpoints, send messages, and inspect frames.
HTTP Status Code ReferenceSearchable reference of all HTTP status codes with descriptions and use cases.
Request BuilderBuild HTTP requests interactively and generate code snippets in multiple languages.
curl to Fetch ConverterConvert curl commands to JavaScript fetch, Python requests, and more.
OpenAPI ValidatorValidate OpenAPI 3.x and Swagger 2.0 specifications for correctness.
Mock API GeneratorGenerate mock API responses from JSON schemas for rapid development.
Docker → ComposeConvert docker run commands to docker-compose.yml format instantly.
Fake Data GeneratorGenerate realistic fake data including names, emails, phone numbers, addresses, and more.
This tool turns your browser into a lightweight HTTP testing console, letting you craft requests and read responses without installing a desktop client. It shines for quick debugging sessions where opening Postman or Insomnia feels like overkill. Follow these steps to hit an endpoint and inspect what the server returns:
The main audience is developers testing endpoints during development who want an alternative to heavyweight API clients. It is particularly useful for debugging authentication flows, because you can inspect the request and response headers to see exactly how tokens and credentials are exchanged. The syntax-highlighted response body also makes it easy to validate that returned JSON is well formed and matches expectations.
A second strong use case is saving and replaying. The history feature stores each request locally, so you can revisit a call made hours ago and re-run it with one click. Keep in mind the tool reaches external servers through a CORS proxy, so a few APIs that do not send permissive CORS headers may not respond from the browser — test those against a local server or a CORS-enabled environment.
When you paste a Bearer token or API key into a request field, that credential is effectively the key to your account. If the tool routed your request through a third-party server, the token could be logged, inspected, or reused without your knowledge. This REST client keeps everything local: your request history is stored in your browser only, and nothing you type into the headers or body is transmitted beyond the actual API call you are testing.
That matters for real projects. Production tokens, staging credentials, and internal endpoints are exactly the kind of data you do not want sitting in a service provider's logs. Keeping request construction and history on your device means the only party that ever sees your credentials is the API you are deliberately calling.
Type or paste the full URL of the API endpoint you want to test, including protocol (https://).
Choose the HTTP method — GET, POST, PUT, PATCH, DELETE, HEAD, or OPTIONS — based on what the endpoint expects.
Add custom headers for auth, content type, or caching. For POST/PUT, provide a JSON or form-data body.
Click Send to make the request. Review the response status code, headers, and body with syntax highlighting.
Practical examples to help you get the most out of REST API Client:
GET https://api.example.com/users
Authorization: Bearer eyJhbGciOiJIUzI1NiIs...
Response: 200 OK
[
{ "id": 1, "name": "John Doe" },
{ "id": 2, "name": "Jane Smith" }
]POST https://api.example.com/users
Content-Type: application/json
{
"name": "John Doe",
"email": "john@example.com"
}
Response: 201 CreatedAlways URL-encode query parameter values containing spaces, &, =, %, or other special characters. Use encodeURIComponent() in JavaScript or the tool's query builder.
When sending a POST, PUT, or PATCH request with a body, always include Content-Type: application/json (for JSON) or multipart/form-data (for file uploads).
Yes, via a CORS proxy. Some non-CORS APIs may not work from the browser.
Request history is stored locally in your browser only.
GET, POST, PUT, PATCH, DELETE, HEAD, and OPTIONS requests.
Custom headers, JSON/form-data bodies, and query parameter builder.
View response status, headers, body with syntax highlighting.
Saved request history with the ability to replay.
REST API Client is useful in a variety of scenarios across different workflows:
Test API endpoints during development without installing Postman or Insomnia
Debug authentication flows by inspecting request and response headers
Validate API responses with syntax-highlighted response bodies
Store API base URLs and auth tokens in environment variables so you can quickly switch between dev, staging, and production.
Use the history feature to save and replay frequently used API requests for faster debugging.
Explore more tools in the Developer Workspace workspace:
JSON Formatter
Format, minify, validate, and explore JSON with tree view, JSONPath queries, and multi-format export — the complete JSON workbench.
JSON Validator
Validate JSON data and detect syntax errors with detailed error messages and line numbers.
JSON Compare
Compare two JSON files side by side with real-time diff highlighting.
JSON Path Tester
Test JSONPath expressions against JSON data and see matched results.
JSON Query Tool
Extract values from JSON using dot-notation and bracket-notation paths.
JSON Schema Generator
Generate JSON Schema (draft-07) from sample JSON data automatically.