HTTP Basic Auth Header Generator — Free
Runs 100% in your browser — your files never leave your device.
Testing a protected endpoint often requires the exact Authorization: Basic header rather than separate credentials. Enter a username and password to produce the UTF-8-safe base64 header, then copy it into curl, Postman, or an API client.
How it works
- 1
Enter the username
- 2
Enter the password
- 3
Copy the Authorization header
About this tool
What the tool produces
The tool takes a username and password and builds the complete Authorization header: the word Basic followed by the base64 encoding of username:password. Copy the whole header into curl, Postman, or any HTTP client and the request authenticates.
Encoding that handles Unicode
The base64 in Basic auth must encode the UTF-8 bytes of the credentials, not raw characters — non-ASCII passwords break naive implementations. This tool handles the UTF-8 step correctly, which is exactly where copy-pasted base64 usually goes wrong.
Use it over HTTPS, always
Basic auth is plaintext encoding, not encryption — anyone who sees the header can decode it. Over HTTPS the header travels inside the encrypted tunnel and is safe in transit; over plain HTTP it is a password handed to every hop. Also note: every request carries the credential, so log redaction matters.
Frequently asked questions
Is base64 encoding the same as encrypting my password?
No — base64 is reversible by design and anyone can decode it instantly. Its role here is transport formatting. The security comes entirely from the HTTPS layer around the request.
Why does my server reject the header for a Unicode password?
The server expects base64 of the UTF-8 bytes, but some clients encode raw characters instead. This tool produces the UTF-8-correct form servers actually expect.
Can I use the header in a browser fetch call?
Yes — set it as the Authorization header value. Browsers also support it natively via credentials in the URL, but explicit headers keep the credential out of URL logs.