Online REST API & Webhook Request Tester
Developers, QA engineers, and system integrators frequently need to inspect external APIs, trigger webhooks, verify authentication tokens, and debug HTTP response payloads. Installing heavy desktop suites like Postman or Insomnia is often overkill when you simply need to test a quick endpoint, reproduce a bug, or inspect response headers.
The DwellixTools Online REST API & Webhook Request Tester is a lightweight, zero-install, 100% in-browser HTTP client. It allows you to build and execute GET, POST, PUT, PATCH, DELETE, HEAD, and OPTIONS requests directly from your web browser. With support for real-time cURL command import and export, query parameters synchronization, custom request headers, Bearer/Basic authentication, JSON body beautification, and round-trip latency metrics, it provides an instant debugging laboratory without tracking or cloud proxy routing.
Why Use an In-Browser API Client?
Most web-based API testing services route your traffic through an intermediary proxy server in their cloud. While this circumvents browser CORS limitations, it poses severe security liabilities:
- Zero Secret Leakage: When you test authenticated APIs containing private
Bearertokens, API keys, or proprietary database payloads, cloud proxies can log, inspect, or cache your credentials. DwellixTools executes all requests directly from your browser’s nativewindow.fetchruntime, ensuring that your keys never touch external servers. - True Client-Side Inspection: Test how your production endpoints actually respond to standard browser Fetch requests, including inspecting exact CORS response headers (
Access-Control-Allow-Origin,Access-Control-Allow-Methods). - Instant cURL Portability: Easily paste a cURL command copied from Google Chrome DevTools, GitHub documentation, or terminal logs. The tool parses methods, query strings, headers, and bodies into their respective form fields in one click.
Supported Authentication Modes
Our request builder supports all standard enterprise API authentication mechanisms:
- Bearer Token (JWT / OAuth 2.0): Injects standard
Authorization: Bearer <token>headers used by modern REST APIs, Supabase, Firebase, and Auth0. - Basic Auth: Takes your plain username and password and automatically compiles them into an RFC 7617 compliant base64-encoded string:
Authorization: Basic <credentials>. - Custom API Key: Flexible injection allowing you to attach proprietary header keys (such as
X-API-Key,api-key) or query parameters (?api_key=secret). - No Auth: For public endpoints, open data APIs, and unauthenticated webhooks.
Understanding Browser CORS in Web Clients
Because this tool runs 100% inside your browser for complete confidentiality, your requests are governed by the browser’s Same-Origin Policy and CORS (Cross-Origin Resource Sharing) security standards:
- APIs Supporting CORS: Public APIs (such as JSONPlaceholder, GitHub API, Stripe API, Open-Meteo, Httpbin) return an
Access-Control-Allow-Origin: *response header. These endpoints work instantly and display formatted response payloads, status codes, and latency. - APIs Without CORS: If you query a private backend that strictly disallows foreign browser origins, your browser blocks reading the response body (triggering a
TypeError: Failed to fetchnetwork error). In these scenarios, use our Copy cURL button to immediately copy the exact command and run it in your local terminal or shell.
How to Test an API Endpoint Step-by-Step
Step 1: Enter the Method & URL
Select your desired HTTP method from the dropdown (GET, POST, PUT, PATCH, DELETE) and paste your target endpoint URL.
Step 2: Configure Parameters & Headers
- Query Params: Add key-value pairs in the Query Params tab. The URL query string updates dynamically in real time.
- Headers: Add custom headers (such as
Accept,Cache-Control) or click + Add JSON Header to instantly injectContent-Type: application/json.
Step 3: Add Authentication & Request Body
If sending a POST or PUT request:
- Select the Body tab and choose JSON.
- Enter or paste your payload and click Beautify JSON to validate formatting and ensure valid syntax.
- Configure any required Bearer Token or API Key in the Auth tab.
Step 4: Send & Analyze Response
Click Send (or press Ctrl + Enter / Cmd + Enter). The response panel reveals:
- HTTP Status Code (e.g.
200 OK,201 Created,404 Not Found). - Round-trip latency (Time-to-First-Byte in milliseconds).
- Payload size in bytes or kilobytes.
- Formatted, syntax-highlighted response body, raw text, and full headers table.
Frequently Asked Questions (FAQ)
Are my API keys or requests stored on your servers?
No. DwellixTools does not operate a proxy or middleware backend for this tool. Every HTTP call is initiated directly from your browser via the standard Fetch API. Your request history is saved strictly to your local browser storage (localStorage) and can be cleared at any time.
Why do I get a “Failed to fetch / CORS Error” on some endpoints?
Modern web browsers enforce Cross-Origin Resource Sharing (CORS) security. If the server hosting the API does not explicitly permit browser requests via the Access-Control-Allow-Origin header, the browser prevents the webpage from reading the response. You can click Copy cURL to execute the request in your local command line without browser CORS restrictions.
Can I import a cURL command from Chrome DevTools?
Yes. In Chrome DevTools (Network tab), right-click any network request and select Copy > Copy as cURL. Click Import cURL in our tool, paste the command, and the tool will automatically extract the method, URL, headers, and payload into your workspace.
Can I test local APIs running on localhost?
Yes! Because requests originate directly from your browser, you can query local development servers (e.g. http://localhost:3000, http://127.0.0.1:8080) as long as your local server allows CORS from localhost origins.
What is the keyboard shortcut to trigger a request?
You can press Ctrl + Enter (on Windows / Linux) or Cmd + Enter (on macOS) anywhere on the page to dispatch the request instantly.