Basic auth header generator
Build an HTTP Basic Authorization header, a .htpasswd line or a curl command from a username and password.
What Basic auth actually is
The username and password, joined with a colon, encoded as base64, put in an Authorization header. That is the entire mechanism.
Which means: it is not encryption. Base64 is an encoding, reversible by anyone in one step with no key and no effort. A Basic auth header is the password written in a slightly less readable alphabet.
That is fine over HTTPS, where the whole request including the header is encrypted in transit. It is completely exposed over plain HTTP, and it is exposed to anything that can see the header — a logging proxy, an error tracker capturing request headers, a screenshot of a browser's network tab.
Never put it in a URL
The https://user:password@host form is legal and still works, and it is the single worst place to put a credential. It gets written to browser history, to server access logs, to every proxy log along the way, and it is sent in the Referer header to whatever site you visit next.
The form is shown here because people ask for it and because you will meet it in old scripts, with the warning attached. If you are choosing, use the header.
What you get
The raw header, a curl command in both the -u and explicit-header forms, a JavaScript fetch snippet, and the nginx configuration lines. The realm is the text a browser shows in its sign-in box, and it only appears in the server configuration.
The colon rule
A username cannot contain a colon. The standard forbids it, and the reason is mechanical: the username and password are joined with one, so a colon in the name makes the split ambiguous and the server has no way to know where the name ends. A password may contain as many as it likes, because only the first is a separator.
Non-ASCII passwords
Handled correctly here, which is worth mentioning because it is a common bug. Base64 works on bytes, not characters, so a password containing an accented or non-Latin character has to be encoded to bytes first — and the browser's own btoa throws an exception rather than doing it for you. The standard says UTF-8, so that is what is used.
Be aware that not every server agrees. Some older ones assume Latin-1, and a password with a character outside it will authenticate from one client and fail from another. If you have a choice, an ASCII password avoids a genuinely miserable class of bug.
When to use something else
Basic auth has no logout, no expiry, no revocation and no second factor. The credentials are sent on every single request. For a person signing in to an application, a session or a token is the right answer.
Where it is still genuinely reasonable: a staging site behind an nginx password, a machine-to-machine call over HTTPS, a health check endpoint, or an internal tool where the alternative is no authentication at all.
Nothing is uploaded
The field above is a live password. It is encoded in this page and no request is made.
Common questions
Is Basic auth encrypted?
No. It is base64, which is an encoding anyone can reverse in one step. It is only safe over HTTPS, where the whole request is encrypted in transit.
Can I put the credentials in the URL?
You can and you should not. It ends up in browser history, server logs, proxy logs and the Referer header sent to the next site you visit.
Why can my username not contain a colon?
Because the username and password are joined with one, so a colon in the name makes the split ambiguous. The password may contain as many as it likes.
Does it handle non-ASCII passwords?
Yes, encoded as UTF-8 per the standard. Worth knowing that some older servers assume Latin-1, so such a password can work from one client and fail from another.
When should I use something else?
For a person signing in to an application. Basic auth has no logout, no expiry, no revocation and no second factor, and sends the credentials on every request.
Is my password sent anywhere?
No. It is encoded in this page and no request is made. That field is a live password, which is why that matters.