curl and wget on Linux: Download Files, Headers, APIs and Scripts

curl wget linux download - custom-curl-featured.png

curl and wget are the standard way to pull a file, probe a URL, or talk to an HTTP API from a server that has no browser.
wget is ideal for mirroring and simple downloads; curl shines when you need headers, methods, or tight control in scripts.

If you are debugging a web stack, combine this with Nginx reverse proxy and
Certbot TLS on the same host.

Pick curl or wget

Both speak HTTP and HTTPS. wget defaults to saving files; curl defaults to printing the body to stdout unless you use -O or -o.

bashquick compare
curl -fsS https://example.com/ | head -c 200
wget -qO- https://example.com/ | head -c 200
curl vs wget
APIs vs simple fetch

Inspect Headers and Timing

A HEAD request (-I) shows status and headers without downloading the body. -v is invaluable for TLS or redirect problems.

bashheaders only
curl -sI https://example.com/
bashtiming breakdown
curl -o /dev/null -s -w 'dns:%{{time_namelookup}} connect:%{{time_connect}} ttfb:%{{time_starttransfer}} total:%{{time_total}}\n' https://example.com/
Headers and verbose
-I and -w

POST JSON to an API

Set Content-Type, send a body with -d, and pass bearer tokens in Authorization when required.

bashexample API call
curl -fsS -X POST https://api.example.com/v1/items \
  -H 'Content-Type: application/json' \
  -H 'Authorization: Bearer TOKEN' \
  -d '{"name":"demo","enabled":true}'
POST JSON
Headers and -d

Download and Resume

Name the local file explicitly in scripts. wget -c continues a partial download.

bashcurl save
curl -fsS -o /tmp/installer.sh https://example.com/install.sh
chmod +x /tmp/installer.sh
bashwget resume
wget -c https://example.com/large.iso
Save to disk
-O, -o, wget -c

Auth, Proxies and TLS

Use -u for basic auth sparingly; prefer tokens. In lab only, -k skips certificate verification — never in production scripts.

bashcustom CA
curl --cacert /etc/ssl/private/my-ca.pem https://internal.example/
WarningDo not use -k in cron jobs that touch production data.
Auth and certs
CA file vs -k

Reliable Script Patterns

curl -fsS fails on HTTP errors and prints errors to stderr. Check exit codes and log responses you care about.

bashhealth check
code=$(curl -fsS -o /tmp/body.txt -w '%{http_code}' https://app.example/health || echo 000)
[ "$code" = 200 ] || { echo "bad health: $code"; exit 1; }
Scripting
-fsS and http_code

Verify Reachability

wget --spider checks existence without keeping the file. Combine with checksums when integrity matters.

bashexists?
wget --spider -S https://example.com/file.zip 2>&1 | head -5
Checks
spider and sha256

Quick Reference

  • curl -fsS for scripts; wget -c to resume
  • -I for headers; -d + JSON for APIs
  • Avoid -k outside lab

Related tutorials

Diagrams are original illustrations by Gnome IT Solutions. Tutorial text © Gnome IT Solutions.