Thanks for your rating and feedback!
You have already rated.
HTTP client and API tester with cURL import. Diagnose DNS, TCP and TLS.
Your API call just failed on your phone. Was it the request, DNS, TCP, TLS, or the server? Curlew is built to answer that question, on the phone in your hand.
Paste a cURL command or build a request by hand, send it, and inspect the response. When it fails, tap Diagnose host: Curlew runs a DNS lookup, a TCP connect and a TLS handshake against that same host and shows you exactly which stage broke.
Why a request failed — answered, not guessed
Instead of "invalid URL" or "something went wrong", Curlew runs the network path and reports each stage:
• DNS lookup with every resolved address and per-address timing
• TCP connect, per address, with the refusal reason when it fails
• TLS handshake with the negotiated protocol version and cipher suite
• Full certificate details: subject, issuer, validity dates, SAN entries
• Typed errors that name the cause, so a timeout is not filed as a mystery
The same checks run standalone from the Diagnose tab — no request needed. Works against localhost, a private IP and port, a lab board or a staging box that never sees the public internet.
A complete HTTP client — free, forever
• Paste or share any cURL command straight into a ready-to-send request, with honest warnings for anything it cannot reproduce
• Export any request back to cURL, secrets redacted by default
• Import Postman collections (v2.0 and v2.1) with folders, requests and variables
• GET, POST, PUT, PATCH, DELETE, HEAD, OPTIONS with full header, query and auth control
• Bearer, Basic, header API key and query API key authentication
• JSON, raw text, XML and form-encoded request bodies
• Collections with move, copy, rename and send-from-list
• Environments and {variables} with autocomplete, secrets masked on screen
• Response viewer with pretty-printed JSON, a collapsible tree, find-in-body, headers and phase-by-phase timings
• Large responses stream to disk, so a 25 MiB payload is inspectable, not an out-of-memory crash
• History that keeps the request template and never stores response bodies
• Encrypted workspace backup and restore, sealed with a passphrase only you know
• Real two-pane layout on tablets, and a dark theme throughout
No ads. No account. No cloud. No tracking.
Curlew shows no advertising, ever. There is no sign-up, no login and no backend of its own, so nothing to lose access to and nothing to leak. Your requests go only to the endpoints you type. Saved requests, environments and history live in an encrypted database on your device, protected by a key held in the hardware keystore. Curlew asks for two permissions: internet, and network state. No location, no contacts, no storage, no analytics SDK.
Plain http:// is refused until you allow it, per request — and if credentials would travel unencrypted, Curlew asks a second time before sending.
Curlew Pro — one payment, not a subscription
A single unlock that stays unlocked. No recurring charge, no usage caps, no account, and nothing that is free today ever moves behind it:
• WebSocket client with a live session log
• Multipart and file-upload request bodies
• Shared collection headers, so an Authorization header is written once
• Custom request methods such as REPORT or PURGE
• HAR export with credentials stripped
• GraphQL helper with a separate JSON variables pane
Built for the 2 a.m. page
For the on-call engineer with only a phone, the flaky staging API, the IoT board that answers on the LAN and nowhere else. Clear typed errors instead of generic failures. Timings you can screenshot straight into an incident channel. Diagnostics you can trust, from an app that keeps nothing.
Independent software by Areeb Labs. Privacy policy: https://areeblabs.com/privacy/
One-click to install XAPK/APK files on Android!