← Back to Blog

Developers & Code | Jun 11, 2026 | 7 min read

Browser DevTools Copy Options: Copy as cURL and Beyond

By Deepender Yadav

Browser DevTools Copy Options: Copy as cURL and Beyond — Edge Drop Guide

Browser DevTools — Chrome, Edge, Firefox, Safari — all have a network panel with right-click "Copy" options on network requests. The options have specific names: "Copy as cURL", "Copy as fetch", "Copy as PowerShell", "Copy JS path", "Copy selector", "Copy XHR". Each copies a different representation of the request. Picking the wrong one produces a paste that does not do what the developer expected, and — for "Copy as cURL" in particular — can leak the request's Authorization header to whoever receives the paste.

This guide explains each DevTools copy option, what it produces, and when to use it. It is written for developers and QA engineers who use browser DevTools to inspect network traffic. For neighbouring topics, see copying from man pages and --help without soft wraps, Postman and Insomnia: collections beat clips, and best clipboard habits for developers in 2026.

Copy as cURL (bash)

What it produces: a curl command in bash syntax, with all headers, query parameters, and the request body included as command-line arguments.

Example output:

curl 'https://api.example.com/users' \
  -H 'accept: application/json' \
  -H 'authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...' \
  -H 'user-agent: Mozilla/5.0...' \
  --compressed

When to use it: reproducing a request in a terminal, sharing a request with a colleague for debugging, or capturing a request for a bug report.

The token leak risk: the Authorization header is included verbatim. If the request was authenticated, the bearer token is in the copied command. Pasting this into a chat, a ticket, or a public issue leaks the token. Always redact the Authorization header (and any other credential-bearing headers) before sharing. See stack traces, tokens, and the clipboard for the redaction patterns.

Caveats: the bash syntax uses backslash line continuations, which break if pasted into a non-bash shell (PowerShell, cmd). For PowerShell, use "Copy as PowerShell" instead. For Windows cmd, the bash syntax needs manual conversion.

Copy as cURL (cmd) and Copy as cURL (PowerShell)

Chrome and Edge offer these Windows-specific variants. They produce a curl command with the correct quoting for cmd or PowerShell, respectively. The cmd version uses double quotes; the PowerShell version uses single quotes (which avoid PowerShell's escape-sequence issues with $).

When to use them: when the target is a Windows terminal. The bash variant does not paste cleanly into cmd or PowerShell because of quoting differences.

Same token leak risk as the bash variant.

Copy as fetch

What it produces: a JavaScript fetch() call with the request URL, method, headers, and body.

Example output:

fetch('https://api.example.com/users', {
  headers: {
    'accept': 'application/json',
    'authorization': 'Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...',
    'user-agent': 'Mozilla/5.0...'
  }
});

When to use it: reproducing a request in a browser console, in a Node.js script, or in a frontend code snippet. The output is JavaScript, so it pastes into a .js file or the browser console directly.

Token leak risk: same as cURL. The Authorization header is included verbatim.

Caveats: the fetch call does not include credentials by default (no credentials: 'include'). If the original request relied on cookies, the fetch call will not reproduce the same behaviour without adding credentials: 'include'.

Copy as PowerShell (Invoke-WebRequest)

Some DevTools versions offer this. It produces an Invoke-WebRequest cmdlet call with the request details.

Example output:

Invoke-WebRequest -Uri 'https://api.example.com/users' -Headers @{
  'accept'='application/json'
  'authorization'='Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...'
  'user-agent'='Mozilla/5.0...'
}

When to use it: when the target is a PowerShell session and Invoke-WebRequest is preferred over curl.exe. PowerShell developers often prefer the cmdlet because it returns a structured object (.Content, .Headers, .StatusCode) rather than raw text.

Token leak risk: same as cURL.

Copy as Node.js fetch / Copy as Node.js request

Newer DevTools versions offer Node.js-specific variants. They produce a Node.js snippet using fetch (Node 18+) or the request library (older). Useful for reproducing requests in a Node.js script.

Token leak risk: same as cURL.

Copy as HAR

What it produces: a HAR (HTTP Archive) JSON blob containing the full request and response, including headers, body, timing, and metadata. HAR is a standard format defined by the Web Performance Working Group.

When to use it: capturing a full request/response pair for analysis, or for importing into another tool (Postman, Charles, Fiddler, Burp Suite). HAR files preserve more context than a cURL command.

Token leak risk: high. HAR files include all headers and the response body. Treat a HAR export as a credential-bearing artefact; do not share it without redaction.

Caveats: HAR files can be large (megabytes for requests with large response bodies). See JSON payloads: keep them as files, not clips for why HAR files belong on disk, not on the clipboard.

Copy JS path

What it produces: a JavaScript expression that resolves to the selected DOM node in the Elements panel.

Example output:

document.querySelector('#user-card > div.profile > h2.name')

When to use it: writing a CSS selector or DOM path for use in a script, a test, or a scraping tool. The output is a string that can be pasted into a JavaScript file or a test runner.

Token leak risk: none, unless the page itself embeds tokens in the DOM (rare).

Caveats: the JS path is specific to the page's current DOM structure. If the page changes, the path may break. For tests, prefer data attributes ([data-testid="user-card"]) over structural selectors.

Copy selector

What it produces: a CSS selector that matches the selected DOM node.

Example output:

#user-card > div.profile > h2.name

When to use it: writing CSS, writing a Playwright or Cypress test, or targeting an element for styling. The output is a CSS selector string.

Token leak risk: none.

Caveats: same as JS path — the selector is specific to the current DOM structure and may break if the page changes.

Copy XHR / Copy as fetch (this request)

Some DevTools versions offer a "Copy XHR" option that produces a XMLHttpRequest snippet. This is the older JavaScript API for HTTP requests, largely superseded by fetch. Use only if the target codebase explicitly uses XMLHttpRequest.

Copy URL / Copy URL with parameters

What it produces: the request URL, either as-is or with query parameters expanded.

When to use it: sharing a link, reproducing a GET request, or pasting into a browser. For GET requests without authentication, this is the simplest copy option.

Token leak risk: low for GET requests. For requests with credentials in the URL (rare but possible — e.g. a presigned S3 URL), the URL itself is the credential.

Which to use when

Use caseCopy option
Reproduce a request in a terminal (bash)Copy as cURL (bash)
Reproduce a request in PowerShellCopy as PowerShell
Reproduce a request in a browser consoleCopy as fetch
Reproduce a request in Node.jsCopy as Node.js fetch
Capture a full request/response for analysisCopy as HAR (save to file)
Write a CSS selector for an elementCopy selector
Write a JS path for an elementCopy JS path
Share a GET request linkCopy URL
Rebuild the request in PostmanCopy as cURL, then Postman → Import → Raw text

For rebuilding requests in Postman or Insomnia, "Copy as cURL" is the right source. Both tools can import a cURL command and convert it to their native request format. See Postman and Insomnia: collections beat clips for why the collection (not the clipboard) should be the persistent store.

Redaction before sharing

For any copy option that includes headers (cURL, fetch, PowerShell, HAR), redact the credential-bearing headers before sharing:

  • Authorization: Bearer ... → Authorization: Bearer <redacted>
  • Cookie: session=... → Cookie: <redacted>
  • X-API-Key: ... → X-API-Key: <redacted>
  • Set-Cookie (in HAR response headers) → <redacted>

A 30-second find-and-replace pass before pasting prevents the credential exposure. For repeated workflows, a small CLI script (see stack traces, tokens, and the clipboard for an example) automates the redaction.

A note on DevTools version differences

The exact menu names and copy options vary across Chrome, Edge, and Firefox versions, and across DevTools releases. The options described above are accurate as of Chrome 120+ and Edge 120+ in mid-2026. Firefox's DevTools (the Network Monitor) offer a similar set of options but with slightly different naming — for example, "Copy as cURL" in Firefox produces both bash and Windows variants in some versions, while Chrome splits them into separate menu items. Safari's Web Inspector has a more limited set, typically just "Copy as cURL".

The general principle holds across browsers: the network panel's right-click menu offers multiple copy formats, each producing a different representation of the request. The developer's job is to pick the format that matches the target tool and to redact credentials before sharing. The specific menu labels may shift, but the categories — cURL variants, fetch variants, HAR, selector, JS path — are stable across browsers and versions.

When a menu option is missing, check the browser version and the DevTools release notes. New options are added periodically (Node.js fetch variants were added relatively recently), and old options are occasionally renamed or reorganised. The browser's official DevTools documentation is the canonical reference for the current state.

Related reading

Sources

Deepender Yadav
Written by Deepender Yadav · Author & Developer

Deepender Yadav is a B.Tech Computer Science Engineering student and software developer interested in building practical software and open-source projects.

GitHub · LinkedIn

Copy. Stack. Drop.

Transform your clipboard into an interactive edge shelf. Stack, pin, and drag assets into any app with zero friction.

Download for Windows Get from Microsoft Store

How to Install Guide · First 10 Minutes Guide · Drag & Drop Guide · Edge-Drop vs Win+V · Support

Free · Lightweight · Privacy First
Find us on CodeHype