Basic Auth Generator
Build an HTTP Basic header from UTF-8 credentials
Enter username and password to generate the Authorization header first; encoding details and troubleshooting cases are available in Advanced mode.
The full guide also includes pitfalls, worked examples, snippets, FAQs, and related tools for checking results or troubleshooting.
About this tool
Enter credentials and click Generate to encode username:password as UTF-8 and then standard Base64. The tool provides the credential text, token, complete header line and a cURL example. Password text remains masked until explicitly revealed, but Base64 itself is reversible. Surrounding whitespace is preserved unless you select Trim; username colons and control characters are rejected. This tool does not authenticate a request or validate an htpasswd record. Encoding is local and credential drafts are not saved.
Production Snippets
RFC 7617 example and the first-colon boundary
text
Username: Aladdin
Password: open sesame
Authorization: Basic QWxhZGRpbjpvcGVuIHNlc2FtZQ==
Username a:b: rejected
Username a + password b:c → credential a:b:c
Base64 remains reversible.Frequently Asked Questions
Why is a username colon rejected?
RFC 7617 uses the first colon to separate the username and password. A colon cannot be part of the username; later colons may be part of the password. Both fields must exclude control characters.
Will UTF-8 work with every Basic server?
No. RFC 7617 leaves the legacy default charset undefined. A charset=UTF-8 challenge signals UTF-8 with NFC normalization; this tool preserves text as entered, so confirm the server’s exact convention.
Why is Trim off by default?
Spaces can be meaningful credentials. Enable Trim only when you intend to remove leading and trailing whitespace from both fields.
How do I use the generated header?
The full line is Authorization: Basic TOKEN. In a key/value HTTP client, use Authorization as the key and Basic TOKEN as the value; replace the cURL example endpoint before use.
Does masking or Base64 protect the password?
Masking only reduces casual on-screen exposure. Base64 is reversible and the token is a credential; use HTTPS and do not share the generated header. No input drafts are stored here.
Keep browsing