Skip to content
empinet.dev
Security & JWT

HTTP Basic Auth Header Generator

Create an Authorization: Basic header from a username and password. Encode credentials locally with UTF-8 and Base64, then copy the complete header for an API client or HTTP request.

Create an Authorization header

Credentials

Username

Password

HTTP header

Enter credentials or load the example.

No request is sent and credentials are not stored by this tool. UTF-8 credentials require compatible server support.

Username and password to Base64

HTTP Basic Auth joins the username and password with a colon, encodes those bytes as Base64, and prefixes the result with Basic. The example uses Aladdin and open sesame. For a client with separate header name and value fields, use Authorization as the name and only Basic plus the token as the value.

Authorization: Basic QWxhZGRpbjpvcGVuIHNlc2FtZQ==

Use HTTPS, not Base64 as protection

Anyone who obtains the header can recover its username and password. Treat it as a secret, send it only to the intended server over HTTPS, and keep it out of public repositories and logs. This tool encodes credentials; it neither authenticates them nor makes network requests.

Unicode and server compatibility

This generator uses UTF-8, including for international usernames and passwords. Servers that advertise charset="UTF-8" support this encoding; older servers may expect something else. ASCII credentials avoid that ambiguity. Input is preserved as entered, without trimming or Unicode normalization, so use the same characters and normalization as your server expects.

Colons and empty credentials

A colon is allowed in a password but not a username, because the first colon separates the two. Tabs, line breaks, and other control characters are rejected. Empty usernames or passwords can be encoded deliberately, but your server decides whether they are acceptable.

Reference: RFC 7617: HTTP Basic Authentication.