How to use
- Enter the username and the password.
- Copy the generated Authorization header into your client, or use the curl command to test the request.
- To read an existing header, paste it into the decode section and the username and password are shown.
How HTTP Basic authentication works
Basic authentication is defined in RFC 7617. When a resource is protected, the server replies with 401 Unauthorized and a WWW-Authenticate: Basic realm="..." header. The client then joins the username and password with a colon, encodes the result as Base64 and sends it with every request:
Authorization: Basic base64(username ":" password)
# Example from RFC 7617: user "Aladdin", password "open sesame"
Authorization: Basic QWxhZGRpbjpvcGVuIHNlc2FtZQ==
Browsers handle this exchange themselves and show a login dialog, while scripts and API clients usually send the header with the first request without waiting for the challenge. Because the colon separates the two values, the username must not contain one; the password may. A server can add charset="UTF-8" to its challenge to announce that non-ASCII credentials are expected in UTF-8.
Base64 is not encryption
The header looks scrambled, but anyone who sees it can recover the password in seconds, with the decoder on this page or any Base64 decoder. Basic authentication is only acceptable over HTTPS, where TLS encrypts the header in transit. Also keep in mind that:
- the credentials travel with every request, so a single plain HTTP request exposes them;
- proxies, load balancers and debugging tools may log the
Authorizationheader unless told not to; - browsers remember entered credentials until they are closed, and there is no standard way to log out.
For public APIs, revocable API tokens or OAuth are a better fit. Basic authentication remains a reasonable choice for internal tools, staging sites and server-to-server calls over TLS.
Sending the header from code
# curl builds the header itself
curl -u 'user:password' https://api.example.com/
// JavaScript fetch (btoa handles only Latin-1 characters)
fetch(url, { headers: { Authorization: 'Basic ' + btoa('user:password') } })
# Python requests
requests.get(url, auth=('user', 'password'))
Avoid embedding credentials in the URL, as in https://user:password@host/. RFC 3986 deprecates that form, it ends up in browser history and server logs, and modern browsers restrict it.
Frequently asked questions
How do I decode a Basic auth header?
Paste the header into the decode section and the username and password appear at once. Any Base64 decoder gives the same result, which is exactly why the header must only travel over HTTPS.
Can the password contain a colon?
Yes. The server splits the decoded value at the first colon, so everything after it belongs to the password. The username, however, must not contain a colon.
Is HTTP Basic authentication secure?
Over HTTPS with a strong, unique password it protects the credentials in transit, but they are sent with every request and cannot expire like a token. Never use it over plain HTTP.
Why does login fail for passwords with accented or non-Latin characters?
charset="UTF-8"; without it, older servers may assume ISO-8859-1 and compare different bytes.Is my password sent anywhere?
No. The header is built by JavaScript in your browser and nothing is transmitted. Still, use test credentials when you share a generated curl command with others.