๐ Basic Auth Header Generator
Authorization: Basic QWxhZGRpbjpvcGVuIHNlc2FtZQ==Enter a username and password to generate the Authorization header value used for HTTP Basic Authentication (RFC 7617). Drop it straight into a curl command or API client configuration.
How to use
- Enter the username.
- Enter the password.
- Copy the generated Authorization header.
How the calculation works
HTTP Basic authentication (RFC 7617) sends the username and password joined by a colon and Base64-encoded in the Authorization header. This tool builds that header value. Authorization: Basic Base64(username + ":" + password) The username and password are converted to UTF-8 bytes before Base64 encoding, so non-ASCII characters and symbols are encoded correctly (matching the UTF-8 handling RFC 7617 recommends). Base64 is not encryption; anyone can reverse it. Always use Basic authentication over HTTPS.
Worked example
Username: Aladdin, password: open sesame Joined: Aladdin:open sesame Header: Authorization: Basic QWxhZGRpbjpvcGVuIHNlc2FtZQ== RFC 7617 example (username test, password 123ยฃ) Basic dGVzdDoxMjPCow== (ยฃ is two bytes in UTF-8) With curl: curl -H "Authorization: Basic QWxhZGRpbjpvcGVuIHNlc2FtZQ==" https://example.com/
Things to be aware of
- The username cannot contain a colon, because the first colon separates the username from the password. The password can contain colons.
- Anyone who sees the header value can recover the password, so keep it out of logs and screenshots.
- In curl, -u username:password builds the same header for you.
FAQ
What calculation does this do?
It base64-encodes the string "username:password" and prefixes it with "Basic " โ the standard format defined by RFC 7617.
Is Basic Auth secure?
Basic Auth is only base64-encoded, not encrypted, so always use it over HTTPS. Over plain HTTP, the credentials can be trivially read by anyone intercepting the traffic.
How do I use this with curl?
Pass the generated header directly, e.g. `curl -H "Authorization: Basic xxxx" https://example.com`.