httpbin at https://httpbin.org echoes back what you send and can return any status code, delay, or auth challenge — handy for testing an HTTP client.
None. The /basic-auth and /bearer endpoints exist to test auth: they accept whatever credentials the URL says they should.
Full reference: https://httpbin.org/
Returns your method, headers, query, and body.
curl -X POST "https://httpbin.org/anything?source=posttaco" \
-H "Content-Type: application/json" \
-d '{"hello": "world"}'
{
"args": {
"source": "posttaco"
},
"data": "{\"hello\": \"world\"}",
"files": {},
"form": {},
"headers": {
"Accept": "*/*",
"Accept-Encoding": "br, gzip, deflate",
"Accept-Language": "*",
"Content-Length": "18",
"Content-Type": "application/json",
"Host": "httpbin.org",
"Origin": "https://posttaco.dev",
"Sec-Fetch-Mode": "cors",
"User-Agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140 Safari/537.36",
"X-Amzn-Trace-Id": "Root=1-6ab44267-7c758ba20164dd1365cff2e3"
},
"json": {
"hello": "world"
},
"method": "POST",
"origin": "73.217.6.239",
"url": "https://httpbin.org/anything?source=posttaco"
}
curl https://httpbin.org/headers
{
"headers": {
"Accept": "*/*",
"Accept-Encoding": "br, gzip, deflate",
"Accept-Language": "*",
"Host": "httpbin.org",
"Origin": "https://posttaco.dev",
"Sec-Fetch-Mode": "cors",
"User-Agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140 Safari/537.36",
"X-Amzn-Trace-Id": "Root=1-6ab44268-21f14f206478af232552f568"
}
}
The URL sets the expected username and password; -u sends them.
curl -u taco:s3cret https://httpbin.org/basic-auth/taco/s3cret
{
"authenticated": true,
"user": "taco"
}
curl https://httpbin.org/uuid
{
"uuid": "b59782a4-07b3-4b5c-b4ed-5822f7161baf"
}