Base64 Encoder / Decoder
Encodes and decodes Base64 for text and files.
Turn a username and password into an HTTP Basic Authorization header, or decode an existing header back into its username and password.
HTTP Basic authentication (RFC 7617) sends:
Authorization: Basic base64(username + ":" + password)
:. The password may.Aladdin, password open sesame gives Authorization: Basic QWxhZGRpbjpvcGVuIHNlc2FtZQ==, the example from RFC 7617.curl -u 'Aladdin:open sesame' https://api.example.com/private; cURL builds the same header.Basic dXNlcjpwYXNz gives the username user and the password pass.https://user:pass@host) are deprecated; browsers hide or block them and they end up in logs. The form is shown for old tools only.Only over HTTPS. The header is Base64, which anyone can decode, so without TLS the password travels in plain text.
The server splits the decoded text at the first colon. A colon in the username would move part of it into the password.
Basic sends a username and password with every request. Bearer sends a token, such as an OAuth access token or a JWT, which can expire and be revoked.
No. Encoding and decoding happen in your browser.
Often used together with the Basic Auth Header Generator.
Encodes and decodes Base64 for text and files.
Builds copy-ready cURL commands with headers, auth, and a body, quoted for your shell.
Creates .htpasswd lines with bcrypt, APR1-MD5, or SHA-1 hashes for Basic Auth.