How to use the auth header generator
Pick a scheme, fill in the values, and the page builds one Authorization header line plus a curl sample you can run as is. Bearer passes through the token your server issued, while Basic encodes a user id and password as base64. You can also enter your own scheme name, which is validated against the allowed character set. The decode field below lets you confirm how plainly a Basic value gives the credentials back.
How the header is built
The header shape follows RFC 9110 for HTTP authentication, RFC 7617 for Basic and RFC 6750 for Bearer. Scheme names are restricted to the RFC 9110 token characters and anything else is rejected. Basic credentials are turned into bytes as UTF-8; the specification does not fix a character set, so a server expecting a different one will read a different value. Checked October 2026.
Limits worth knowing
base64 is not encryption, only a reversible encoding. Send these headers over HTTPS and treat the result exactly like the password it contains. The page does not issue tokens, send requests or tell you whether a server accepts a given scheme. Everything runs in your browser, but use the clear button to wipe whatever is left on screen when you finish.
Frequently Asked Questions
No. base64 only rewrites bytes as characters, so anyone can reverse it without a key. Use the decode field on this page to see that for yourself. The protection comes from HTTPS on the wire.
The header value is the password or token itself. Pasting it into code, an issue or a chat is a leak, and committing it leaves it in history. Press the clear button once you are done with it.
It does not issue tokens, verify signatures or send any request. It builds one header line and a curl sample from the values you type, and stops there.