(Dokumentaatio englanniksi)
What it does
Builds an HTTP Authorization: Basic <token> header live from a username and password (
Base64Base64An encoding representing binary data as 64 safe ASCII characters, so it survives transport through text-only channels. It encodes — it does not encrypt.
-encoded, UTF-8 safe), decodes an existing header back into its fields, and flags credential mistakes before they ship.How to use it
- Type a username and password — the header builds live in the output panel.
- Already have a header? Open Paste an Authorization header, paste it, then Parse & load to decode it into the fields.
- Copy the header, download it as
basic-auth-header.txt, or share the URL — your input is encoded in the link.
Examples
user/pass→Basic dXNlcjpwYXNz- Paste
Authorization: Basic dXNlcjpwYXNz→ loadsuser/passinto the fields - Username
a:b→ warns:":" in username — credentials become ambiguous
Good to know
- Private: encoding/decoding is local — credentials never leave your browser.
- Basic Auth is not secure over plain HTTP — pair it with HTTPS. Prefer tokens/OAuth for new APIs.
- A username containing
:is flagged because theuser:passsplit happens at the first colon — conforming parsers silently truncate the username. - Non-ASCII passwords are flagged per RFC 7617: its default charset is UTF-8, but many servers assume ISO-8859-1/US-ASCII and mangle or reject such bytes.
- Passwords containing colons are handled correctly.
- Related tools:
Base64Base64An encoding representing binary data as 64 safe ASCII characters, so it survives transport through text-only channels. It encodes — it does not encrypt.
, HTTP Status Codes.