API Tester
Send HTTP requests and inspect the response — a full-featured API client, right in your browser.
Send a request to see the response here.
No collections yet. Click Save to create one.
Sent requests will appear here.
Usage examples
Testing an API endpoint before writing code
Quickly check what a GET or POST endpoint returns, including headers and status code, before wiring it up in your application.
Debugging authentication headers
Add a Bearer token or Basic auth credentials and confirm the server accepts them, without installing a separate app.
Reviewing request history during development
Keep an automatic history of the requests you've sent, so you can resend or compare them with one click instead of retyping everything.
Organizing requests into a collection
Save related requests — like all the endpoints for one API — into a named collection you can come back to and reload with one click.
Frequently asked questions
Is my data sent to a server?
Not to ours. This tool sends requests directly from your browser to the URL you enter — nothing passes through our servers. Request history and saved values are also kept only in your browser's local storage.
Why do some requests fail with a network error?
Browsers block cross-origin requests unless the target server explicitly allows them (CORS). If a request fails here but works in a desktop API client, the server likely isn't sending the CORS headers browsers require — that's a browser security restriction, not a bug in this tool.
Is it safe to test requests with real API tokens?
Your tokens are only used to make the request directly to the API you specify, and are kept in your browser's local storage for convenience (so you can resend requests later) — never sent anywhere else. Still, avoid testing with sensitive production credentials on a shared or public computer.
What HTTP methods are supported?
GET, POST, PUT, PATCH, DELETE, HEAD, and OPTIONS.
Can I organize my requests into saved collections?
Yes — click Save next to the Send button to save the current request into a new or existing collection. Saved collections and requests are kept in your browser's local storage, separate from the automatic history list.
Is there a setting to ignore SSL certificate errors, like self-signed certificates?
No — certificate validation happens inside the browser itself, before any page's JavaScript (including this tool) ever sees the request, so there's no setting this tool could offer to bypass it. If you're testing a local server with a self-signed certificate, open its HTTPS URL directly in a new browser tab once and accept the certificate through the 'not private' warning. Your browser will remember that exception, and requests from this tool to the same URL will then go through normally.
Can I manually enter a cookie value, like a custom session ID?
Not as a typed-in value — browsers block JavaScript from setting the Cookie header directly (it's one of a handful of 'forbidden' headers), for the same kind of security reason covered in the certificate question above. What you can do instead is check 'Include browser cookies for this domain' in the Auth tab, which sends whatever cookies your browser already has for that domain — for example, if you're logged into the target site in another tab. If you need a very specific cookie value, set it for that domain using your browser's developer tools (its Application or Storage panel) by visiting the site once, then enable the checkbox here.