cURL with Basic auth in Kotlin

Paste a curl command that uses Basic auth and get Kotlin code using OkHttp. Toolpaper also detects secrets and offers a one-click redaction before sharing.

Quick answer

To convert a cURL command to Kotlin, paste it into the Toolpaper workbench below. It parses the command in your browser and emits idiomatic Kotlin code — headers, query string, request body, authentication (Bearer, Basic, API key), and cookies are all wired up automatically. No data is uploaded; conversion is fully client-side.

Prefer a different target? See the full cURL to Kotlin reference, or jump to the same guide in JavaScript, Node.js, or Python.

InputcURL command
1 secret
MethodGET·Headers0·Body—·Authbasic· Chars 51
OutputJVM · OkHttp / Kotlin(idiomatic)
import okhttp3.*
import okhttp3.MediaType.Companion.toMediaTypeOrNull
import okhttp3.RequestBody.Companion.toRequestBody

val client = OkHttpClient.Builder().followRedirects(false).followSslRedirects(false).build()
val request = Request.Builder()
  .url("https://api.example.com/me")
  .method("GET", null)
  .header("Authorization", Credentials.basic("alice", "s3cret"))
  .build()

client.newCall(request).execute().use { response ->
  println(response.body?.string())
}
Inspect

Example

A representative curl command for this scenario. Paste your own above to convert an exact match.

curl input
curl https://api.example.com/me \
  -u alice:s3cret

Implementation notes

  • -u user:pass is decoded and re-emitted as an idiomatic OkHttp auth primitive rather than a hand-rolled base64 header.
  • Secrets are visible in the parsed request. Use the Clean panel's redact-and-diff flow before you paste the command anywhere.
  • Shareable links Base64-encode the input — they never leave your browser, and cleaned versions produce different links.

Common mistakes

  • Hard-coding user:pass into source instead of reading from env vars — the generated snippet marks credentials so you notice.
  • Not rotating a leaked credential because "it's only in a screenshot" — screenshots get OCR'd, redact first.
  • Trusting HTTPS alone for API keys in query strings — proxies log URLs. Prefer headers, which the converter defaults to.

Common questions

How is Basic auth rendered in Kotlin?
-u user:pass becomes an idiomatic Basic auth call — auth=(user, pass) in Python, SetBasicAuth in Go, .setBasicAuth in Java.
Can I redact the secret before sharing?
Yes. Open the Clean panel — Toolpaper detects Bearer tokens, Basic credentials, and common API-key patterns and replaces them with <REDACTED> in a diffable view.
Does anything leave my browser?
No. Parsing, redaction, and generation are 100% client-side.

More auth flows in Kotlin

Kotlin hub →

The same guide in other languages

All guides →

Full Kotlin reference on the cURL to Kotlin hub, or open the main converter for all 18 targets.