BAS

Basic Auth Generator

Build an HTTP Basic header from UTF-8 credentials

Security & Auth
🔒 100% client-side — your data never leaves this page
Maintained by Evan•Updated: September 30, 2026
Options
Credentials

Enter username and password to generate the Authorization header first; encoding details and troubleshooting cases are available in Advanced mode.

Basic Base64 is reversible. Send it over HTTPS. This tool uses UTF-8 as entered; confirm server charset and normalization for non-ASCII credentials.
Output
Enter username and password to generate Basic auth header
Local processing; credentials are not saved
Page reading mode

The full guide also includes pitfalls, worked examples, snippets, FAQs, and related tools for checking results or troubleshooting.

About this tool

Enter credentials and click Generate to encode username:password as UTF-8 and then standard Base64. The tool provides the credential text, token, complete header line and a cURL example. Password text remains masked until explicitly revealed, but Base64 itself is reversible. Surrounding whitespace is preserved unless you select Trim; username colons and control characters are rejected. This tool does not authenticate a request or validate an htpasswd record. Encoding is local and credential drafts are not saved.

Production Snippets

RFC 7617 example and the first-colon boundary

text

Username: Aladdin
Password: open sesame
Authorization: Basic QWxhZGRpbjpvcGVuIHNlc2FtZQ==
Username a:b: rejected
Username a + password b:c → credential a:b:c
Base64 remains reversible.

Frequently Asked Questions

Why is a username colon rejected?

RFC 7617 uses the first colon to separate the username and password. A colon cannot be part of the username; later colons may be part of the password. Both fields must exclude control characters.

Will UTF-8 work with every Basic server?

No. RFC 7617 leaves the legacy default charset undefined. A charset=UTF-8 challenge signals UTF-8 with NFC normalization; this tool preserves text as entered, so confirm the server’s exact convention.

Why is Trim off by default?

Spaces can be meaningful credentials. Enable Trim only when you intend to remove leading and trailing whitespace from both fields.

How do I use the generated header?

The full line is Authorization: Basic TOKEN. In a key/value HTTP client, use Authorization as the key and Basic TOKEN as the value; replace the cURL example endpoint before use.

Does masking or Base64 protect the password?

Masking only reduces casual on-screen exposure. Base64 is reversible and the token is a credential; use HTTPS and do not share the generated header. No input drafts are stored here.

Keep browsing