Basic Auth Header Generator

Generate and decode HTTP Basic Authentication headers in your browser. Copy Authorization headers, Base64 tokens, cURL examples, and Fetch snippets with no upload.

  • Runs in your browser
  • Your data never leaves your browser
  • Free · No Sign-Up

Generate Basic Auth Header

Create an Authorization header from a username and password.

Generate reads the current username and password and produces a full Authorization header, its Base64 token, and cURL and Fetch snippets. Load Example fills Aladdin and open sesame and generates them.
The username cannot contain a colon. Generation joins username and password with a colon and encodes the pair as UTF-8 before Base64.
Passwords may contain colons and may be empty when a username is present. Enter at least one of username or password to generate a header.
Show and Hide change whether this input displays the password as text. The generated header and decoded password contain the same credentials.

Decode Basic Auth Header

Paste a full Authorization header, a Basic token, or a raw token.

Decode splits the decoded value at its first colon, preserving any later colons in the password. Load Example decodes user with the password p:a:ss.
Accepts a full Authorization header, Basic plus a token, or a token alone. Only Basic and standard Base64 are accepted. Invalid UTF-8 bytes are displayed as ISO-8859-1 with a notice; check the result.

Basic auth is Base64 encoding, not encryption. Use HTTPS when sending it.

Examples, details and FAQ Worked examples, how it compares with other tools, and answers to common questions.

Use this Basic Auth Header Generator to create the exact Authorization: Basic <token> value required by many HTTP APIs, reverse proxies, legacy dashboards, and test endpoints.

The token is the Base64 form of username:password. The tool joins the username and password with a colon, encodes that pair as UTF-8, then converts the bytes to Base64. ASCII credentials are safest for broad Basic Auth compatibility; if you use non-ASCII credentials, verify that the target server expects UTF-8. It can also decode an existing Basic auth header so you can verify copied credentials before using them in a request.

Basic auth is convenient for API checks, reverse proxy rules, testing dashboards, and quick cURL or Fetch snippets. It is not secret by itself: Base64 is encoding, not encryption, and it is reversible. Treat HTTPS as the transport protection boundary whenever an Authorization header crosses the network.

All generation and decoding run in your browser. Credentials are not uploaded and are not persisted by this page.

Examples

The example from RFC 7617 §2: username Aladdin, password open sesame. The tool outputs:

Authorization: Basic QWxhZGRpbjpvcGVuIHNlc2FtZQ==

It also prints a cURL and a Fetch snippet with the same header. curl -u ‘Aladdin:open sesame’ URL sends exactly this header, so you only need the generated value when a tool asks for a raw header line.

Non-ASCII credentials are encoded as UTF-8. renée / s3cret becomes cmVuw6llOnMzY3JldA==, the same token curl -u sends from a UTF-8 terminal. A server that expects ISO-8859-1 would expect cmVu6WU6czNjcmV0 instead; RFC 7617 leaves the default encoding to the server unless it announces charset=“UTF-8” in its challenge.

Servers announce the encoding in their challenge. When a server answers with WWW-Authenticate: Basic realm=“api”, charset=“UTF-8”, the client should send UTF-8, which is what this tool generates. Without that parameter, check the server documentation before you use non-ASCII characters.

To check a copied header, paste Authorization: Basic ZGVwbG95OnBhOnNz into the decoder. It shows username deploy and password pa:ss: the first colon splits the pair, so passwords may contain colons and usernames may not.

Limits

  • Only the Basic scheme is decoded. Bearer and other schemes produce “Only the Basic authorization scheme is supported.”
  • The decoder accepts the standard Base64 alphabet. URL-safe tokens with - or _ are rejected.
  • Bytes that are not valid UTF-8 are shown as ISO-8859-1 with a notice. cmVu6WU6czNjcmV0 decodes to renée / s3cret this way. The tool cannot tell ISO-8859-1 from Windows-1252 or other single-byte encodings, so check characters outside ASCII yourself.
  • A username that contains a colon is refused, as required by RFC 7617.
  • Anyone who sees the header can decode the password. Send it only over HTTPS, and rotate the password if a real header ends up in a screenshot, ticket or chat log.

FAQ

Is Basic auth encrypted?

No. Basic auth uses Base64 encoding, not encryption. Send Basic auth only over HTTPS.

Can I decode an existing Basic auth header?

Yes. Paste a full Authorization header, a Basic token, or a token-only value to inspect the username and password pair.

Are credentials uploaded?

No. Generation and decoding run in your browser, and this tool does not persist entered credentials.