100% Free Forever — No signup, no paywalls, no limits.
DevKit
Utilities 5 min read July 7, 2026

The cURL Command Reference: Every Flag You Need for API Testing

A practical cURL cheat sheet — headers, body, auth, cookies, proxies, and the flags developers use most for API testing.

DK

DevKit Team

Engineering

Share:

cURL is the most widely used command-line tool for testing APIs. Every developer encounters cURL commands in API documentation, browser DevTools "Copy as cURL" features, and debugging sessions. Understanding the essential flags makes API testing much faster.

The Essential Flags

-X: HTTP method (GET, POST, PUT, DELETE). -H: request header (e.g., -H "Content-Type: application/json"). -d: request body (e.g., -d '{"key":"value"}' ). -u: basic auth (e.g., -u user:pass). -b: send cookies. -c: save cookies. -L: follow redirects. -k: skip SSL verification. -o: output to file. -w: custom output format. -s: silent mode. -v: verbose. Use a cURL to code converter to turn these commands into production code in your language of choice.

Why This Matters in 2026

Utility tools — timestamp converters, UUID generators, cron expression builders, number base converters — are the unsung heroes of development. They handle the small but critical tasks that every developer encounters daily. In 2026, these tools have evolved with new standards like UUID v7, the TC39 Temporal API proposal, and modern cron scheduling platforms. Understanding these utilities deeply saves time and prevents subtle bugs that can take hours to trace.

Key Takeaways

  • Use UUID v7 instead of v4 for database primary keys — it is timestamp-sortable
  • Store timestamps in UTC, convert to local time only at the presentation layer
  • Use crypto.randomUUID() for hardware-accelerated UUID generation in browsers
  • Always confirm the timezone when working with cron expressions
  • JavaScript Date.now() returns milliseconds, not seconds — divide by 1000 for APIs
  • Use ISO 8601 strings for API communication — they are sortable and timezone-explicit

Common Mistakes to Avoid

  • Using UUID v4 for database primary keys, causing B-tree index fragmentation
  • Confusing seconds and milliseconds when converting timestamps across languages
  • Not specifying the timezone in cron jobs, causing jobs to run at wrong times
  • Using getHours() for server-side logic — it uses local time, not UTC
  • Generating UUIDs with Math.random() instead of crypto.randomUUID()
  • Storing timestamps in local time instead of UTC, causing timezone bugs

Warning

The Year 2038 problem is real for 32-bit systems. If you maintain legacy C/C++ code, embedded firmware, or older database schemas, audit your timestamp handling now. Use 64-bit time_t or switch to a custom epoch with smaller values.

Best Practices

  • Default to UUID v7 for new systems — sortable, index-friendly, RFC standard
  • Store all timestamps in UTC (Unix epoch or ISO 8601 with Z suffix)
  • Use toISOString() for storage and API calls, toLocaleString() for display
  • Specify timezone explicitly in cron job definitions wherever supported
  • Use crypto.randomUUID() in browsers, uuid v4 library in Node.js if needed
  • Test timezone edge cases: midnight UTC, DST transitions, 30-minute offset zones

Tip

When converting timestamps between languages, always check the unit first. JavaScript uses milliseconds, Python uses seconds, Go uses both, and PostgreSQL stores microseconds. A simple unit mismatch causes bugs that are incredibly hard to trace.

Quick Reference

Here are quick reference snippets for the most common utility operations across JavaScript and other languages:

javascript
// UUID v7 (sortable, index-friendly)
const uuid = crypto.randomUUID(); // v4 in browsers
// For v7, use the uuid library: import { v7 } from "uuid";

// Timestamp conversions
const now = Date.now(); // milliseconds
const unixSeconds = Math.floor(Date.now() / 1000);
const isoString = new Date().toISOString(); // "2026-08-06T00:00:00.000Z"

// Number base conversion
const hex = (255).toString(16); // "ff"
const binary = (10).toString(2); // "1010"
const decimal = parseInt("ff", 16); // 255

// Cron expression: every 15 minutes
const cron = "*/15 * * * *";

Real-World Example

A practical scenario: generating sortable IDs for a database insert and converting timestamps for a multi-timezone scheduling system. This pattern works across JavaScript backends and browser clients:

javascript
// Generate sortable UUIDs for bulk database insert
function generateIds(count) {
  return Array.from({ length: count }, () => crypto.randomUUID());
}

// Convert UTC timestamp to user's local time
function formatForUser(utcTimestamp, timezone) {
  return new Date(utcTimestamp * 1000).toLocaleString("en-US", {
    timeZone: timezone,
    year: "numeric",
    month: "short",
    day: "numeric",
    hour: "2-digit",
    minute: "2-digit",
  });
}

// Usage
const ids = generateIds(1000); // Bulk generate
const localTime = formatForUser(1722883200, "America/New_York");

Tools and Resources

"The best utility is the one you do not have to think about. It just works, every time, without surprises."

Utility tools handle the small but critical tasks that every developer faces daily. Use UUID v7 for sortable database keys, store timestamps in UTC, specify timezones in cron jobs, and always check units when converting between languages. These small choices prevent the subtle bugs that waste hours of debugging time.

Advertisement
32 tools ready to use

Ready to boost your workflow?

No accounts. No uploads. No limits. Just open a tool and start working.

Browse All Tools
Free forever
No signup
100% private