How to Perform Load Testing Using cURL
curl is the universal language of HTTP. Developers copy it from docs, browsers, and gateways. That makes it a natural starting point for API load testing — but curl alone is not a load generator.
Here is how to use curl the right way: debug with it, then scale with a proper load profile.
What curl is good at
- Reproducing a single failing request
- Confirming auth headers and status codes
- Timing one call with
-w/-o - Exporting a canonical request teammates can paste
Example:
curl -sS -X POST 'https://api.example.com/v1/orders' \
-H 'Authorization: Bearer TOKEN' \
-H 'Content-Type: application/json' \
-d '{"sku":"sku_123","qty":1}'
What curl is bad at (for load)
Naive loops like for i in {1..1000}; do curl ...; done are not load tests:
- They are usually sequential, not concurrent
- They do not control RPS precisely
- They skew latency with client overhead
- They rarely produce p95/p99 or throughput reports
- Your laptop becomes the bottleneck quickly
Shell parallelism (xargs -P, background jobs) is still a rough hammer — fine for a smoke blast, weak for capacity claims.
A practical workflow: curl → load test
1. Perfect one request with curl
Make sure the call returns the expected status and body on staging. Fix auth, headers, and JSON first.
2. Capture the curl (or Postman) snippet
Keep it as the source of truth for the request shape.
3. Paste into a load testing dashboard
Tools like Loadcurl accept curl / Postman paste into the composer, then let you set:
- Target RPS
- Ramp-up
- Duration
Cloud generators send the traffic; you are not installing workers. You must verify the domain before runs can target that host.
4. Read percentiles and HTTP outcomes
Judge the run on p95/p99, achieved RPS vs target, and error/timeout rates — not on how fast your shell loop felt.
Timing a single request with curl
For quick local checks:
curl -sS -o /dev/null -w 'time_total=%{time_total}\nhttp_code=%{http_code}\n' \
'https://staging.example.com/health'
Useful for debugging. Not a substitute for a multi-minute RPS hold.
Security and safety
- Prefer staging tokens in curl history and shared snippets
- Do not load test hosts you do not own
- Strip secrets before pasting into tickets; rotate if leaked
- Ramp up; production traffic is real
Curl + Loadcurl in practice
- Register at app.loadcurl.com
- Verify your domain (docs)
- Open New test and paste your curl
- Set RPS, ramp-up, duration
- Start — the run page polls live status about every 3 seconds
- Download the report PDF when finished
This keeps curl as the authoring format while cloud infrastructure handles concurrency and reporting.
When to stay local vs go cloud
Stay local for functional curl debugging. Move to cloud generators when you need sustained RPS, clean percentiles, and isolation from laptop limits — covered in Cloud-Based vs Local Load Testing.
Related guides
Related posts
Browse allHow-to guides · staging
Staging vs Production Load Testing: When Each Is Safe
When to load test staging vs production, how domain verification fits, ramp-up and abort criteria, and how to run a production game day safely.
How-to guides · GraphQL
Load Testing GraphQL over HTTP
How to load test GraphQL APIs over HTTP with POST, headers, and JSON bodies — what works in Loadcurl today, and pitfalls unique to GraphQL.
How-to guides · authentication
How to Load Test Authenticated APIs (Safely)
Load test authenticated HTTP APIs without leaking secrets — staging tokens, header hygiene, rate limits, and how Loadcurl stores request credentials.