Basic Auth Header Generator
Turn a username and password into the Authorization: Basic header that HTTP Basic Authentication expects, encoded as UTF-8 and Base64 as RFC 7617 describes, and get ready code for curl, JavaScript fetch, Python requests, PHP cURL and PowerShell. A second tab decodes an existing header back into its username and password. Everything happens in your browser.
- Runs in your browser
- No sign-up
- Free to use
How to use Basic Auth Header Generator
- Enter the username and password (test credentials where possible).
- Choose the header or a programming language.
- Copy the result into your request.
- To inspect an existing header, switch to “Decode header”.
Basic Auth Header Generator features
Correct encoding
UTF-8 then Base64, per RFC 7617.
Six outputs
Header, curl, fetch, Python requests, PHP cURL and PowerShell.
Decoder
Turns Authorization: Basic … back into username and password.
Input checks
Rejects colons in usernames and control characters.
HTTPS warning
Flags plain-http URLs that would expose the password.
Local only
Nothing is sent, logged or stored.
When to use Basic Auth Header Generator
- Calling an API or webhook that uses Basic authentication.
- Testing a password-protected staging site with curl.
- Checking which user an Authorization header in a log belongs to.
- Configuring a monitoring tool that needs the raw header.
Basic Auth Header Generator FAQ
How is the Basic header built?
The username and password are joined with a colon, encoded as UTF-8 bytes and then Base64-encoded. The result follows the word “Basic” in the Authorization header.
Is Basic authentication secure?
Only over HTTPS. The encoding is reversible by anyone, so on plain HTTP the password is effectively sent in clear text. It also sends the password with every request, so tokens are preferred for most APIs.
Why can the username not contain a colon?
The first colon separates the username from the password. A colon in the password is fine.
Is my password sent anywhere?
No. Encoding and decoding run in your browser. Still, prefer test credentials when using any online tool.
What about non-English characters?
They are encoded as UTF-8, which modern servers expect. Some old servers assumed Latin-1, which can make such passwords fail.
How do I protect a website directory with a password?
Create the password file with the htpasswd command and protect the folder with the .htaccess Generator; this tool creates the header a client sends.
HTTP Basic Authentication explained
Basic authentication is the oldest and simplest way for an HTTP client to prove who it is. When a server requires it, it answers 401 Unauthorized with a WWW-Authenticate: Basic header, and the browser shows a sign-in dialog. The client then repeats the request with an Authorization header that contains the username and password in encoded form, and sends it with every later request to the same area.
The encoding is deliberately simple: username, a colon and password, converted to bytes and written in Base64. Base64 only makes binary data safe to put in a header; it is not encryption, and any Base64 decoder, including the one on this page, reverses it instantly. Basic authentication therefore depends entirely on HTTPS to keep the password secret in transit.
Because the password travels with every request and cannot easily be revoked without changing it, Basic authentication suits limited cases: internal tools, staging sites, webhooks and machine-to-machine calls with dedicated credentials. Public APIs generally prefer tokens, such as OAuth access tokens or API keys sent as bearer tokens, which can be scoped, expired and revoked individually.
In code, most HTTP libraries build the header for you from a username and password, as the samples show. Writing credentials directly into source code is a common way for them to leak through repositories and logs, so read them from environment variables or a secret store, and avoid logging request headers. If credentials have appeared in a log or chat, change them.
The decoder helps when you find an Authorization header in a request dump or log and need to know which account it belongs to. Remember that decoding reveals the password: handle the result with the same care as the credentials themselves, and rotate any real password that has been exposed.