cURL with API key in Swift

Paste a curl command that uses API key and get Swift code using URLSession. Toolpaper also detects secrets and offers a one-click redaction before sharing.

Quick answer

To convert a cURL command to Swift, paste it into the Toolpaper workbench below. It parses the command in your browser and emits idiomatic Swift code — headers, query string, request body, authentication (Bearer, Basic, API key), and cookies are all wired up automatically. No data is uploaded; conversion is fully client-side.

Prefer a different target? See the full cURL to Swift reference, or jump to the same guide in JavaScript, Node.js, or Python.

InputcURL command
1 secret
MethodGET·Headers1·Body—· Chars 60
OutputApple · URLSession(async/await)
import Foundation

let session = URLSession.shared
var request = URLRequest(url: URL(string: "https://api.example.com/me")!)
request.httpMethod = "GET"
request.setValue("YOUR_KEY", forHTTPHeaderField: "X-API-Key")

let (data, response) = try await session.data(for: request)
print(String(data: data, encoding: .utf8) ?? "")
// Note: to disable redirects, implement URLSessionTaskDelegate.urlSession(_:task:willPerformHTTPRedirection:...) and return nil.
Inspect

Example

A representative curl command for this scenario. Paste your own above to convert an exact match.

curl input
curl https://api.example.com/me \
  -H "X-API-Key: YOUR_KEY"

Implementation notes

  • The X-API-Key (or custom key header) name is preserved exactly as sent; case-sensitive gateways keep working.
  • Secrets are visible in the parsed request. Use the Clean panel's redact-and-diff flow before you paste the command anywhere.
  • Shareable links Base64-encode the input — they never leave your browser, and cleaned versions produce different links.

Common mistakes

  • Duplicating the key header (once via -H, once via a gateway middleware) — the generator warns when the same header appears twice.
  • Not rotating a leaked credential because "it's only in a screenshot" — screenshots get OCR'd, redact first.
  • Trusting HTTPS alone for API keys in query strings — proxies log URLs. Prefer headers, which the converter defaults to.

Common questions

How is API key rendered in Swift?
The X-API-Key header (or any custom API-key header name) passes through unchanged to the generated code.
Can I redact the secret before sharing?
Yes. Open the Clean panel — Toolpaper detects Bearer tokens, Basic credentials, and common API-key patterns and replaces them with <REDACTED> in a diffable view.
Does anything leave my browser?
No. Parsing, redaction, and generation are 100% client-side.

More auth flows in Swift

Swift hub →

The same guide in other languages

All guides →

Full Swift reference on the cURL to Swift hub, or open the main converter for all 18 targets.