The history of curl from a currency tool to a ubiquitous engine
Daniel Stenberg evolved a 1996 currency exchange tool into curl, a data transfer engine now found on 10 billion installations. The project is maintained through commercial backing from wolfSSL while facing new challenges from AI-generated security reports.
Daniel Stenberg began writing an HTTP downloader in 1996 to automate currency exchange for an IRC bot. He used a tool called httpget released by Rafael Sagula in November 1996 and sent patches to improve its functionality. Stenberg became the maintainer of the tool within weeks. He added Gopher support in 1997, which led to a name change to urlget. Adding FTP upload support in November 1997 led to another name change. The project became curl in March 1998 when version 4.0 released. In 1997, urlget 1.0 added proxy support. By August 1997, urlget 2.0 added support for Windows and Solaris. Version 3.1 added FTP upload support in November 1997, and version 3.5 added HTTP POST support. In 1998, version 5 released and introduced the first curl man page.
The code was small.
The first curl release in 1998 contained 2,400 lines of code and 25 command line options. Stenberg wanted a short, pronounceable name that could be typed easily in command lines. He worked on the code for decades as a spare time project before he finally joined wolfSSL in 2019 to manage the project as his primary full-time job.
The expansion into a ubiquitous engine
The project changed in 2000 when Stenberg released libcurl to provide an API for other applications. PHP adopted the library, and it became a standard component for many users. The first non-beta release, 7.1, arrived in August 2000. Today, the code runs on 10 billion installations, including mobile phones, TVs, and gaming consoles.
| Feature | Details |
|---|---|
| Protocols | DICT, FILE, FTP, FTPS, GOPHER, HTTP, HTTPS, IMAP, LDAP, MQTT, POP3, RTMP, RTSP, SCP, SFTP, SMB, SMTP, TELNET, TFTP |
| HTTP Versions | 0.9, 1.0, 1.1, HTTP/2, HTTP/3 |
| Security | TLS 1.0 to 1.3, SSL, SSH, authentication via Kerberos, Digest, and NTLM |
| OS Support | 82 operating systems and 22 CPU architectures |
It works everywhere.
Stenberg releases new versions every eight weeks. The software handles many protocols including FTP, SFTP, SMB, and SMTP, while it also manages authentication like Kerberos and NTLM for users across many different types of systems. The library provides many authentication mechanisms including Basic, Digest, NTLM, Negotiate, Kerberos, and AWS Sigv4 so that users can perform secure transfers across many different types of internet protocols within their diverse software environments.
The software stays stable.
Most Linux distributors maintain their own stable branches, which can stay alive for over ten years. The code also runs on 47 different car brands. libcurl supports over 50 languages through various bindings. The library handles tasks like cookie handling, proxy support, and DNS-over-HTTPS. It also handles compression via gzip, Brotli, and zstd. You should know that these installations include Windows 10, Android, iOS, and various gaming consoles.
Commercial backing and AI issues
WolfSSL provides commercial backing for the project. Stenberg works for wolfSSL to manage the project. This allows him to handle customization, porting to new platforms, and feature development. They also handle bug fixing and security scanning of curl use. Customers can choose from four levels of support, including 24/7 options.
Does the money matter?
The project faces AI slop. In 2025 and 2026, the frequency of security reports generated by AI increased. These reports often contain fake problems that waste hours of developer work. Stenberg works to prevent these issues while maintaining the project.
I find the volume of these fake reports exhausting. Stenberg noted that these AI generated reports often lack any actual substance. The reports get longer and more complicated because the AI attempts to please the user with incorrect answers. These reports often claim a security problem exists when the function call does not even exist. The project must address these issues.
The tool is vital.