🔐

HTTP Basic Auth Generator

Generate a Base64 Authorization header from username and password, with a curl example.
Basic Auth 📂 Network 👤 ToolWorld 🏷️ v1.1.12
Loading...

HTTP Basic Auth Generator

Username:password → Base64 Authorization header + curl example

Combined string user:pass
Base64 value
Authorization header
curl command example

HTTP Basic Auth only applies Base64 encoding, not encryption. Always use it over HTTPS. This tool encodes usernames and passwords as UTF-8, so Chinese text and emoji are supported.

How to Use

📖 Tool Introduction


HTTP Basic Authentication is one of the most common schemes you meet when debugging web APIs: the server expects an Authorization header containing the word Basic followed by a Base64-encoded pair of credentials. This generator automates that whole ceremony. Type in a username and a password and you instantly receive four things at once: the combined string in username-colon-password form, the raw Base64 value, the complete Authorization header line, and a curl command you can paste straight into a terminal. Two mistakes trip up almost everyone the first time they hand-write Basic Auth: forgetting the colon between the two fields, and believing that Base64 is encryption because the output looks like ciphertext. The encoder here works directly on the UTF-8 byte stream, so non-ASCII usernames, Chinese characters and emoji passwords are handled correctly instead of producing garbled sequences. The password field starts out masked and a small toggle reveals it for a quick double-check, and the generated curl command wraps the credentials in single quotes automatically whenever a password contains spaces or shell metacharacters, so the command remains safe to run. Everything happens inside your browser, which means the credentials you type never leave the device and no request of any kind is sent to any server.

Because the encoder uses the browser's built-in UTF-8 routines, non-ASCII user names and passwords such as accented characters or CJK identifiers are encoded correctly rather than mangled into broken bytes, which matches what servers actually expect when they decode the Authorization header. The curl example is ready to run as soon as you fill in a real host, so debugging protected endpoints takes only a copy and a paste, and the whole flow stays offline so credentials never leave the page.

✨ Key Features


  • Four outputs in one click: the combined pair, the Base64 value, the Authorization header and a curl command
  • UTF-8 safe: non-ASCII usernames and emoji passwords are encoded byte-by-byte without garbling
  • Masked password: the field hides the text by default and reveals it on demand
  • Curl quoting: credentials containing spaces or special characters are quoted and escaped automatically
  • Per-block copy: every output block has its own copy button, and the full header is one click away
  • Truly local: credentials live only in your browser memory; no network request is made

📝 How to Use


  1. Type the account name into the username field, for example admin
  2. Type the password, and toggle the show button if you need to double-check it
  3. Optionally fill in the request URL so the curl example targets the right endpoint
  4. Click Generate header and read the four output blocks from top to bottom
  5. Use the small copy button on the block you need, then paste it into your code or API client

⚠️ Notes


  • Not encryption: Base64 is a reversible encoding that anyone can decode in seconds, so never expose it over plain HTTP
  • HTTPS mandatory: Basic Auth credentials must travel inside a TLS tunnel; otherwise they are effectively public
  • Colon matters: the encoded object is the whole username-colon-password string; dropping the colon makes the server reject auth
  • Production alternatives: real systems should prefer Bearer tokens, API keys or OAuth flows instead
  • Graceful validation: an empty username triggers a friendly warning, while an empty password stays allowed for odd API conventions

Related

⏫︎