Basic Auth Header Generator

Turn a username and password into an HTTP Basic Authorization header, or decode an existing header back into its username and password.

Updated
Encoded in your browser. Credentials are never sent or stored.

Authorization header
–
Header value only
–
Base64 credentials
–
cURL
–
URL with credentials (deprecated)
–
Updates as you type.

How to use the Basic Auth Header Generator

  1. On Create header, type the Username and Password.
  2. Copy the Authorization header, the header value, or the ready-made cURL command.
  3. To read a header you already have, open Decode header and paste it.

How it works

HTTP Basic authentication (RFC 7617) sends:

Authorization: Basic base64(username + ":" + password)
  • The username and password are joined with a colon and encoded as UTF-8 bytes, then Base64 encoded.
  • Because the server splits at the first colon, a username may not contain :. The password may.
  • Decoding reverses the Base64 step. There is no secret involved, so anyone who sees the header can read the password.

Examples

  • Username Aladdin, password open sesame gives Authorization: Basic QWxhZGRpbjpvcGVuIHNlc2FtZQ==, the example from RFC 7617.
  • The cURL form is curl -u 'Aladdin:open sesame' https://api.example.com/private; cURL builds the same header.
  • Decoding Basic dXNlcjpwYXNz gives the username user and the password pass.

Limitations

  • Basic auth is only encoded, not encrypted. Use it over HTTPS only.
  • Credentials in URLs (https://user:pass@host) are deprecated; browsers hide or block them and they end up in logs. The form is shown for old tools only.
  • Some old servers expect Latin-1 instead of UTF-8, so non-ASCII characters in passwords may fail there.

Frequently asked questions

Is Basic authentication secure?

Only over HTTPS. The header is Base64, which anyone can decode, so without TLS the password travels in plain text.

Why can't the username contain a colon?

The server splits the decoded text at the first colon. A colon in the username would move part of it into the password.

What is the difference between Basic and Bearer?

Basic sends a username and password with every request. Bearer sends a token, such as an OAuth access token or a JWT, which can expire and be revoked.

Are my credentials sent anywhere?

No. Encoding and decoding happen in your browser.

Often used together with the Basic Auth Header Generator.