Test REST and GraphQL APIs in your browser. Direct or proxy send, collections, auth, cURL import, and code generation — free, no download.
By default, collections and drafts stay in your browser. Proxy mode sends the HTTP request you choose through Tool Reign’s relay (not stored or logged). The page says so before first use.
Step-by-step guide to get the most from this tool
Choose GET/POST/…, paste the URL, and pick Direct, Proxy, or Auto.
Use the tabs for query params, headers, raw/form/GraphQL body, and Bearer/Basic/API Key/OAuth client credentials.
Press Ctrl/Cmd+Enter. Review body, headers, cookies, timing, and generate client code.
Save to a collection, import cURL or OpenAPI, and backup your workspace.
What makes this tool stand out
Browser fetch or Tool Reign relay with consent for CORS.
Folders, save/restore, last 100 history entries in IndexedDB.
Bearer, Basic, API Key, OAuth client credentials, {{vars}} and dynamics.
cURL, collection JSON v2.0/v2.1, OpenAPI 3.x; export cURL and collections.
cURL, fetch, Python, PHP, Go, C# with optional variable resolution.
Data stays in your browser unless you choose Proxy and consent.
What happens under the hood — and how to use it well
More free utilities you might find useful
Quick answers to common questions
Browsers enforce CORS. If the API does not allow your origin, Direct mode fails. Switch to Auto (retry via proxy after consent) or Proxy, or ask the API owner to allow browser origins.
Direct sends the request from your browser to the API. Proxy relays the request through Tool Reign’s server so CORS does not apply. Proxy cannot reach localhost or private IPs.
When you use Proxy (or Auto after consent), the URL, headers (including Authorization), and body are sent to Tool Reign’s relay to fetch the target. They are not stored or logged. Prefer non-production credentials.
The proxy blocks loopback and private addresses by design (SSRF protection). Use Direct mode for local APIs.
Proxy limits come from /v1/config (request/response bytes, timeout, redirects). Direct mode is limited by your browser and the API. Oversized responses may be truncated.
Collections, history, environments, and tabs are stored in IndexedDB in your browser (migrated from older localStorage keys). Use Backup/Restore to move data. History redacts secrets by default.
Browsers forbid setting Cookie, Host, Referer, Connection, and similar headers from JavaScript. The tool warns you inline. Proxy mode can send those headers upstream.
In Direct mode, Set-Cookie from cross-origin responses is usually unreadable. In Proxy mode, a session cookie jar can store and replay cookies per domain.