AUTH

Basic Auth Decoder

Decode Basic credentials with an explicit UTF-8 interpretation

Security & Auth
🔒 100% client-side — your data never leaves this page
Maintained by Evan•Updated: September 30, 2026
Authorization: Basic

Basic Auth is reversible encoding, not encryption. Avoid pasting active production credentials.

Decoded credentials

The username, password, and colon boundary will appear here.

About this tool

Paste a complete Authorization: Basic header, Basic TOKEN, or a bare Base64 token. Decoding interprets bytes as strict UTF-8 and preserves an initial BOM character. The first colon separates username from password; later colons stay in the password. Missing-colon text is displayed with a warning, not certified as valid credentials. The parser tolerates URL-safe symbols and omitted padding for inspection, although those are not the standard Basic wire format. It does not contact a server, prove authentication, or support every legacy charset. Input edits clear the previous result and reveal state; nothing is saved as a draft.

Scenario Recipes

01

Inspect a Basic header from an API trace

Goal: Confirm the credential boundary without sending another request

  1. Paste the captured Authorization header.
  2. Decode it and verify the username before revealing the password.
  3. Rotate the credential if the trace came from an uncontrolled environment.

Result: A locally decoded username and password boundary for troubleshooting.

Frequently Asked Questions

Which input forms are accepted?

A complete Authorization: Basic header, Basic followed by a token, or the bare token. Bearer and other explicitly named schemes are rejected.

Can a password contain a colon?

Yes. Only the first colon is the separator. Missing-colon output is decoded text rather than a valid Basic username/password pair.

Does a successful decode prove RFC compliance?

No. The inspection parser accepts URL-safe symbols and missing padding, and it does not validate every credential rule or server charset. A readable value is not proof of successful authentication.

Why can a valid legacy credential fail here?

The tool requires UTF-8, while the historical Basic default charset is not universally defined. Confirm the server’s charset before interpreting invalid UTF-8 as damaged data.

Are credentials stored or uploaded?

The tool processes them locally without input drafts. Password display starts masked; copied credential text and Base64 tokens must still be handled as secrets.

Keep browsing