cURL with API key in Java
Paste a curl command that uses API key and get Java code using OkHttp. Toolpaper also detects secrets and offers a one-click redaction before sharing.
Quick answer
To convert a cURL command to Java, paste it into the Toolpaper workbench below. It parses the command in your browser and emits idiomatic Java code — headers, query string, request body, authentication (Bearer, Basic, API key), and cookies are all wired up automatically. No data is uploaded; conversion is fully client-side.
Prefer a different target? See the full cURL to Java reference, or jump to the same guide in JavaScript, Node.js, or Python.
import okhttp3.OkHttpClient;
import okhttp3.Request;
import okhttp3.Response;
public class Main {
public static void main(String[] args) throws Exception {
OkHttpClient.Builder clientBuilder = new OkHttpClient.Builder();
clientBuilder.followRedirects(false).followSslRedirects(false);
OkHttpClient client = clientBuilder.build();
Request.Builder rb = new Request.Builder().url("https://api.example.com/me");
rb.method("GET", null);
rb.header("X-API-Key", "YOUR_KEY");
try (Response response = client.newCall(rb.build()).execute()) {
System.out.println(response.body().string());
}
}
}Example
A representative curl command for this scenario. Paste your own above to convert an exact match.
curl https://api.example.com/me \
-H "X-API-Key: YOUR_KEY"Implementation notes
- The X-API-Key (or custom key header) name is preserved exactly as sent; case-sensitive gateways keep working.
- Secrets are visible in the parsed request. Use the Clean panel's redact-and-diff flow before you paste the command anywhere.
- Shareable links Base64-encode the input — they never leave your browser, and cleaned versions produce different links.
Common mistakes
- Duplicating the key header (once via -H, once via a gateway middleware) — the generator warns when the same header appears twice.
- Not rotating a leaked credential because "it's only in a screenshot" — screenshots get OCR'd, redact first.
- Trusting HTTPS alone for API keys in query strings — proxies log URLs. Prefer headers, which the converter defaults to.
Common questions
- How is API key rendered in Java?
- The X-API-Key header (or any custom API-key header name) passes through unchanged to the generated code.
- Can I redact the secret before sharing?
- Yes. Open the Clean panel — Toolpaper detects Bearer tokens, Basic credentials, and common API-key patterns and replaces them with <REDACTED> in a diffable view.
- Does anything leave my browser?
- No. Parsing, redaction, and generation are 100% client-side.
More auth flows in Java
Java hub →The same guide in other languages
All guides →In JavaScript
/how-to/curl-api-key-auth-in-javascript
In Node.js
/how-to/curl-api-key-auth-in-node
In Python
/how-to/curl-api-key-auth-in-python
In Go
/how-to/curl-api-key-auth-in-go
In PHP
/how-to/curl-api-key-auth-in-php
In Ruby
/how-to/curl-api-key-auth-in-ruby
In Rust
/how-to/curl-api-key-auth-in-rust
In Kotlin
/how-to/curl-api-key-auth-in-kotlin
Full Java reference on the cURL to Java hub, or open the main converter for all 18 targets.