Basic Auth Decoder
Decode Basic credentials with an explicit UTF-8 interpretation
Basic Auth is reversible encoding, not encryption. Avoid pasting active production credentials.
The username, password, and colon boundary will appear here.
About this tool
Paste a complete Authorization: Basic header, Basic TOKEN, or a bare Base64 token. Decoding interprets bytes as strict UTF-8 and preserves an initial BOM character. The first colon separates username from password; later colons stay in the password. Missing-colon text is displayed with a warning, not certified as valid credentials. The parser tolerates URL-safe symbols and omitted padding for inspection, although those are not the standard Basic wire format. It does not contact a server, prove authentication, or support every legacy charset. Input edits clear the previous result and reveal state; nothing is saved as a draft.
Scenario Recipes
Inspect a Basic header from an API trace
Goal: Confirm the credential boundary without sending another request
- Paste the captured Authorization header.
- Decode it and verify the username before revealing the password.
- Rotate the credential if the trace came from an uncontrolled environment.
Result: A locally decoded username and password boundary for troubleshooting.
Frequently Asked Questions
Which input forms are accepted?
A complete Authorization: Basic header, Basic followed by a token, or the bare token. Bearer and other explicitly named schemes are rejected.
Can a password contain a colon?
Yes. Only the first colon is the separator. Missing-colon output is decoded text rather than a valid Basic username/password pair.
Does a successful decode prove RFC compliance?
No. The inspection parser accepts URL-safe symbols and missing padding, and it does not validate every credential rule or server charset. A readable value is not proof of successful authentication.
Why can a valid legacy credential fail here?
The tool requires UTF-8, while the historical Basic default charset is not universally defined. Confirm the server’s charset before interpreting invalid UTF-8 as damaged data.
Are credentials stored or uploaded?
The tool processes them locally without input drafts. Password display starts masked; copied credential text and Base64 tokens must still be handled as secrets.
Keep browsing