HTTP Basic auth header generator
Turn a username and password into an Authorization: Basic header, with UTF-8 credentials, reverse parsing of existing headers, and curl / fetch snippets.
Runs in your browserEvery computation happens in your browser — your data never leaves this device.
Result
What this tool does
- Fill in the `Authorization: Basic` header for an API client, Swagger or Postman without hand-rolling the Base64 string.
- Paste an existing auth header from a packet capture or log to decode the username and password and check whether the test account is misconfigured.
- Grab a ready-made curl or fetch snippet and reproduce the request in a terminal.
- Check that credentials containing non-ASCII characters are encoded as UTF-8, and remember to tell the server to decode them the same way.
Example
Input
user:pa$$w0rd
Output
Authorization: Basic dXNlcjpwYSQkdzByZA==
The colon separates username from password, so a username cannot contain one. These credentials are pure ASCII and work with every server; with non-ASCII characters the tool encodes UTF-8 and warns you.
Frequently asked questions
Is Basic auth secure?
The credentials are only Base64 encoded, not encrypted — anyone can decode them. All of the security comes from the transport: it must run over HTTPS, otherwise an eavesdropper reads the username and password directly. Basic auth is for server-to-server, intranet or TLS-wrapped use; public products should prefer tokens or OAuth.
What if the username contains a colon?
RFC 7617 defines everything before the first colon as the username and everything after it as the password, so `a:b:c` parses as username a and password b:c. A colon inside the username simply cannot be expressed; the tool will still generate a value, but the server will never read it back the way you intended.
Do non-ASCII passwords cause problems?
They can. The tool encodes credentials as UTF-8 and warns you when it sees non-ASCII characters, but RFC 7617 originally specified ISO-8859-1 and some older servers decode with a different charset, which breaks authentication. Have the server declare `charset="UTF-8"`, or keep credentials ASCII-only.
Which input forms does the decoder accept?
Three: a full `Authorization: Basic xxx` header (case-insensitive), a bare `Basic xxx`, or a raw Base64 string. If the decoded value has no username:password shape you get “Not a valid Basic auth header”, and invalid Base64 or bytes that are not valid UTF-8 each have their own message.
Does my password get sent anywhere?
No. Encoding, decoding and snippet generation all run in your browser with no network requests, and credentials are never written to a URL or a log. Note that the generated curl snippet contains the Base64 value in clear — think twice before pasting it into a chat or a ticket.
Keywords:basic authauthorizationhttp 认证base64curlfetch认证头basic 认证生成